diff --git a/signer/hsm-sign.sh b/signer/hsm-sign.sh index 5c69961..c1ad07a 100755 --- a/signer/hsm-sign.sh +++ b/signer/hsm-sign.sh @@ -64,6 +64,19 @@ describe_cert() { echo "sha256 (apk_cert_sha256): $(sha256sum "$1" | cut -d' ' -f1)" } +# The label of the token in slot PKCS11_SLOT_INDEX, as pkcs11-tool numbers slots for +# --slot-index. +token_label() { + pkcs11-tool --module "$module" --list-slots 2>/dev/null | awk -v n="$slot_index" ' + /^Slot [0-9]+ / { s = $2 } + s == n && /^[[:space:]]*token label[[:space:]]*:/ { sub(/^[^:]*:[[:space:]]*/, ""); print; exit }' +} + +# $1 percent-encoded, every byte, for a pkcs11: URI (RFC 7512). +uri_encode() { + printf '%s' "$1" | od -An -v -tx1 | tr -d ' \n' | tr 'a-f' 'A-F' | sed 's/../%&/g' +} + # SunPKCS11's configuration: which library, which slot. cat > "$work/pkcs11.cfg" <&2 # Thirty years: the certificate's dates are not checked for APK signatures, and # replacing it would mean a new app identity on every device. Also long enough for # Google Play, which wants validity past 2033-10-22. OPENSSL_CONF="$work/openssl.cnf" openssl req -new -x509 -sha256 -days 10950 \ -subj "$subject" -engine pkcs11 -keyform engine \ - -key "pkcs11:id=${uri_id};type=private" -out "$work/cert.pem" + -key "$uri" -out "$work/cert.pem" openssl x509 -in "$work/cert.pem" -outform DER -out "$work/cert.der" if [ "$replacing" = 1 ]; then # Removed first, so tokens that keep several objects with one id do not end up diff --git a/signer/test.sh b/signer/test.sh index 66be591..fe0a6ac 100755 --- a/signer/test.sh +++ b/signer/test.sh @@ -51,6 +51,9 @@ fi export PKCS11_MODULE="$(find /usr/lib -name libsofthsm2.so | head -n 1)" export PKCS11_PIN=123456 KEY_ID=03 softhsm2-util --init-token --free --label hsm-sign-test --pin "$PKCS11_PIN" --so-pin 87654321 >/dev/null + # A second token, as the OpenPGP card shows two (User PIN and User PIN (sig)): the + # slot the key is on has to be named, not left to whichever token matches its id. + softhsm2-util --init-token --free --label "hsm-sign-test (sig)" --pin "$PKCS11_PIN" --so-pin 87654321 >/dev/null # A key and nothing else, as on the real HSM before make-cert. pkcs11-tool --module "$PKCS11_MODULE" --login --pin env:PKCS11_PIN \ --keypairgen --key-type rsa:4096 --id "$KEY_ID" --label test-key >/dev/null