allan icon

SmartCards - Generate X.509 Certificate with OpenSSL

allan | PRO | 07/18/17 06:04:27 PM UTC | 0 ⭐ | 526 👁️ | Never ⏰ | []
Bash |

7.83 KB

|

None

|

0 👍

/

0 👎

# The following was performed on Debian Stretch
# Adapted from:
#    https://ubuntuforums.org/showthread.php?t=1557180&p=9743605
#    http://blog.fkraiem.org/2013/03/13/linux-smart-card-authentication-openssl/
#
# Note: A Public/Private Key on the card is required. See:
#    https://pastebin.com/D0geT5Ne
# =====================================================================
#
# document OpenSSL version
# ---------------------------------------------------------------------
$ openssl version
OpenSSL 1.1.0f  25 May 2017
 
# install the OpenSSL PKSC11 engine from the Debian repo
# ---------------------------------------------------------------------
$ sudo apt-get install libengine-pkcs11-openssl1.1
 
# start OpenSSL and load the modules
# ---------------------------------------------------------------------
$ openssl
OpenSSL> engine dynamic -pre SO_PATH:/usr/lib/x86_64-linux-gnu/engines-1.1/pkcs11.so -pre ID:pkcs11 -pre LIST_ADD:1 -pre LOAD -pre MODULE_PATH:opensc-pkcs11.so
(dynamic) Dynamic engine loading support
[Success]: SO_PATH:/usr/lib/x86_64-linux-gnu/engines-1.1/pkcs11.so
[Success]: ID:pkcs11
[Success]: LIST_ADD:1
[Success]: LOAD
[Success]: MODULE_PATH:opensc-pkcs11.so
Loaded: (pkcs11) pkcs11 engine
OpenSSL>
 
# generate a certificate based on the Smart Card's Private Key
# Note: slot-0 = Reader 0
#       id_xxx = Private Key ID from "pkcs15-tool --dump"
#
# Note: Common Name must match the full name exactly as defined in /etc/passwd
#       This includes the commas used by the legacy
#           GECOS fields (http://en.wikipedia.org/wiki/Gecos_field)
#
# Example /etc/passwd:
# jdoe:x:1000:1000:John Doe,,,:/home/jdoe:/bin/bash
#
# ---------------------------------------------------------------------
OpenSSL> req -new -x509 -days 365 -keyform engine -engine pkcs11 -key slot_0-id_707db33cfbd0712e0d5cfc4238fa85be44da990d -out smartcard.cert.pem
engine "pkcs11" set.
No private keys found.
PKCS#11 token PIN: <User PIN>
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [AU]:
State or Province Name (full name) [Some-State]:
Locality Name (eg, city) []:
Organization Name (eg, company) [Internet Widgits Pty Ltd]:
Organizational Unit Name (eg, section) []:
Common Name (e.g. server FQDN or YOUR name) []: John Doe,,,
Email Address []:
 
<Ctrl-D to Exit OpenSSL prompt>
 
# Verify generated certificate using OpenSSL
# ---------------------------------------------------------------------
$ openssl x509 -in smartcard.cert.pem -noout -text
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            d4:fa:71:c4:a6:cf:7d:88
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C = AU, ST = Some-State, O = Internet Widgits Pty Ltd, CN = "John Doe,,,"
        Validity
            Not Before: Jul 18 17:56:24 2017 GMT
            Not After : Jul 18 17:56:24 2018 GMT
        Subject: C = AU, ST = Some-State, O = Internet Widgits Pty Ltd, CN = "John Doe,,,"
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:a3:bb:95:41:bc:10:63:a9:1f:ef:e7:cd:0c:ce:
                    d0:61:e6:96:83:71:a1:08:c9:de:c6:9c:05:27:bc:
                    a4:3b:37:de:55:36:cd:89:ab:24:08:b1:eb:9b:1c:
                    36:22:a4:eb:8b:48:ed:79:b8:e8:b9:0c:4a:00:e6:
                    0b:73:33:29:b7:79:c8:f0:ac:a3:62:44:cc:30:1e:
                    c7:71:89:48:59:c0:45:59:65:97:76:cd:8e:41:ff:
                    aa:1a:59:0e:6b:82:20:62:a1:46:dd:c0:b1:2f:45:
                    84:b6:2a:87:bb:c4:5e:e0:82:7f:9b:28:8c:8b:e2:
                    f5:02:4d:7e:bc:d5:5c:86:ed:bb:7d:e9:fd:58:c0:
                    da:40:90:7e:ce:e2:9c:22:dc:08:1a:80:31:d5:b6:
                    65:4b:80:30:9c:6b:5b:d0:e4:55:76:7b:f4:3f:81:
                    18:4d:b6:a9:8e:35:15:fe:c1:c7:5a:6c:77:dd:a0:
                    ab:be:80:a1:81:93:18:11:de:27:0c:97:1f:ec:17:
                    ac:e1:f8:eb:ff:fd:1b:58:d1:ff:ba:47:ed:92:50:
                    4e:6e:21:48:ea:fd:fb:c8:7c:b2:3c:97:e7:5e:c4:
                    1e:4a:8c:40:1e:af:1b:f1:f9:81:fe:1d:62:90:30:
                    20:c5:98:ae:c5:2c:d3:af:d6:20:37:2d:f0:ca:cd:
                    12:65
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                59:F5:80:CA:67:0A:C1:4A:62:3D:16:EA:D8:52:E0:7F:D4:34:B0:41
            X509v3 Authority Key Identifier: 
                keyid:59:F5:80:CA:67:0A:C1:4A:62:3D:16:EA:D8:52:E0:7F:D4:34:B0:41
 
            X509v3 Basic Constraints: critical
                CA:TRUE
    Signature Algorithm: sha256WithRSAEncryption
         7b:f2:22:b5:1d:d9:1e:84:7d:15:01:df:20:9f:a4:58:a3:a9:
         f6:82:3b:55:17:8d:9e:2c:90:1b:5d:84:37:4e:fe:2a:a9:38:
         cd:f1:71:e5:91:bc:27:16:6b:bf:b5:dc:3b:9c:12:05:d8:fd:
         19:26:9a:4b:6e:c3:15:ed:1b:8a:e1:39:c4:7b:24:ff:39:95:
         46:ee:ba:77:0e:2a:e1:fd:ee:bd:2c:ba:15:ed:c3:7d:52:ae:
         8f:e7:50:20:56:58:27:92:e7:8f:fd:82:8e:dd:14:84:ce:9a:
         bd:64:fd:d6:be:a1:70:5d:1a:a1:88:89:76:d7:1d:f6:13:d9:
         9e:77:b2:27:04:2c:c2:c9:ec:56:be:36:03:a3:77:7a:22:87:
         2b:da:e8:4d:7b:79:83:2f:7b:ba:e1:6c:44:1b:4f:56:14:3c:
         89:fc:9a:cc:66:5b:97:d2:74:6e:00:cd:81:a9:16:dd:31:9c:
         e3:8c:ae:4d:db:62:cb:a7:7d:96:eb:43:d3:45:45:ae:d4:fe:
         eb:7a:8b:e4:f0:42:4c:9f:ee:5a:f5:f6:4d:d2:aa:55:08:d6:
         e6:ea:e7:58:44:d6:96:dd:a6:c8:d6:29:8e:08:c4:45:2f:a0:
         e9:7a:df:e9:53:5b:17:85:71:b1:7d:1f:e0:28:84:0d:7b:3a:
         2b:07:e2:e3
 
 
# Verify certificate is self-signed
# ---------------------------------------------------------------------
$ openssl verify -CAfile smartcard.cert.pem smartcard.cert.pem 
smartcard.cert.pem: OK
 
# Store the generated cert in the card
# ---------------------------------------------------------------------
$ pkcs15-init --store-certificate smartcard.cert.pem --auth-id 01 --id 707db33cfbd0712e0d5cfc4238fa85be44da990d --format pem
Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00
Security officer PIN [Security Officer PIN] required.
Please enter Security officer PIN [Security Officer PIN]: <SO PIN>
User PIN [John Doe] required.
Please enter User PIN [John Doe]: <User PIN>
 
# Verify stored certificate
# Note: "Encoded serial" must match openssl output
# ---------------------------------------------------------------------
$ pkcs15-tool --list-certificates
Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00
X.509 Certificate [Certificate]
    Object Flags   : [0x2], modifiable
    Authority      : no
    Path           : 3f0050153104
    ID             : 707db33cfbd0712e0d5cfc4238fa85be44da990d
    Encoded serial : 02 09 00D4FA71C4A6CF7D88
 
# Decode Certificate through OpenSSL
# ---------------------------------------------------------------------
$ pkcs15-tool --read-certificate 707db33cfbd0712e0d5cfc4238fa85be44da990d | openssl x509 -noout -text
Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00
Certificate:
    Data:
[...]
 
# Delete stored certificate
# ---------------------------------------------------------------------
$ pkcs15-init --delete-objects cert --id 707db33cfbd0712e0d5cfc4238fa85be44da990d
Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00
Security officer PIN [Security Officer PIN] required.
Please enter Security officer PIN [Security Officer PIN]: <SO PIN>
Deleted 1 objects

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎