-
Notifications
You must be signed in to change notification settings - Fork 135
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Nitrokey HSM 2 with Dogtag PKI #4400
Comments
Found this similiar bug and this for the ipa-advice |
Just for further information that
|
I could disable p11-kit for modutil so it doesn't activate twice via
but for that I'm getting following error
Token is inserted for in pki-tomcat
Any idea how to move forward in debugging? |
Hello guys,
I'm trying to initialize FreeIPA with Dogtag PKI including a Nitrokey HSM 2 which is my cheap option to experiment with a HSM instead of the expensive Enterprise variants. The Dogtag wiki lists the HSM so I thought to give it try on CentOS 8 Stream!
It uses OpenSC
dnf install opensc
and supports PKCS#11. After a quick example HSM initialization this one is ready for usage:$ sc-hsm-tool --initialize --so-pin 3537363231383830 --pin 648219
or
$ pkcs11-tool --module /usr/lib64/opensc-pkcs11.so --init-token --init-pin --so-pin=3537363231383830 --new-pin=648219 --label="test" --pin=648219
New certs can be put in like in example:
$ pkcs11-tool --module /usr/lib64/opensc-pkcs11.so -l --pin 648219 --keypairgen --key-type rsa:1024 --id 10
Under modules it will be listed and is ready for usage
$ p11-kit list-modules
The only documentation I found is Installing CA with HSM which needs a directory service in place
dscreate interactive
Afterwards the PKI could not be spawned as it fails
$ pkispawn -f /opt/ca.cfg -s CA
Following configuration file with HSM options were used and the correct
pki_ds_password
from prior initialization given.It stops at executing following command
modutil -dbdir /etc/pki/pki-tomcat/alias -nocertdb -add 'SmartCard-HSM (UserPIN)' -libfile /usr/lib64/opensc-pkcs11.so -force
Cannot resolve it and through the p11-kit the module is available. Please elaborate how to continue on.
The text was updated successfully, but these errors were encountered: