# The following was performed on Debian Stretch # Adapted from: # https://ubuntuforums.org/showthread.php?t=1557180&p=9743605 # http://blog.fkraiem.org/2013/03/13/linux-smart-card-authentication-openssl/ # # Note: A Public/Private Key on the card is required. See: # https://pastebin.com/D0geT5Ne # ===================================================================== # # document OpenSSL version # --------------------------------------------------------------------- $ openssl version OpenSSL 1.1.0f 25 May 2017 # install the OpenSSL PKSC11 engine from the Debian repo # --------------------------------------------------------------------- $ sudo apt-get install libengine-pkcs11-openssl1.1 # start OpenSSL and load the modules # --------------------------------------------------------------------- $ openssl OpenSSL> engine dynamic -pre SO_PATH:/usr/lib/x86_64-linux-gnu/engines-1.1/pkcs11.so -pre ID:pkcs11 -pre LIST_ADD:1 -pre LOAD -pre MODULE_PATH:opensc-pkcs11.so (dynamic) Dynamic engine loading support [Success]: SO_PATH:/usr/lib/x86_64-linux-gnu/engines-1.1/pkcs11.so [Success]: ID:pkcs11 [Success]: LIST_ADD:1 [Success]: LOAD [Success]: MODULE_PATH:opensc-pkcs11.so Loaded: (pkcs11) pkcs11 engine OpenSSL> # generate a certificate based on the Smart Card's Private Key # Note: slot-0 = Reader 0 # id_xxx = Private Key ID from "pkcs15-tool --dump" # # Note: Common Name must match the full name exactly as defined in /etc/passwd # This includes the commas used by the legacy # GECOS fields (http://en.wikipedia.org/wiki/Gecos_field) # # Example /etc/passwd: # jdoe:x:1000:1000:John Doe,,,:/home/jdoe:/bin/bash # # --------------------------------------------------------------------- OpenSSL> req -new -x509 -days 365 -keyform engine -engine pkcs11 -key slot_0-id_707db33cfbd0712e0d5cfc4238fa85be44da990d -out smartcard.cert.pem engine "pkcs11" set. No private keys found. PKCS#11 token PIN: You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank. ----- Country Name (2 letter code) [AU]: State or Province Name (full name) [Some-State]: Locality Name (eg, city) []: Organization Name (eg, company) [Internet Widgits Pty Ltd]: Organizational Unit Name (eg, section) []: Common Name (e.g. server FQDN or YOUR name) []: John Doe,,, Email Address []: # Verify generated certificate using OpenSSL # --------------------------------------------------------------------- $ openssl x509 -in smartcard.cert.pem -noout -text Certificate: Data: Version: 3 (0x2) Serial Number: d4:fa:71:c4:a6:cf:7d:88 Signature Algorithm: sha256WithRSAEncryption Issuer: C = AU, ST = Some-State, O = Internet Widgits Pty Ltd, CN = "John Doe,,," Validity Not Before: Jul 18 17:56:24 2017 GMT Not After : Jul 18 17:56:24 2018 GMT Subject: C = AU, ST = Some-State, O = Internet Widgits Pty Ltd, CN = "John Doe,,," Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:a3:bb:95:41:bc:10:63:a9:1f:ef:e7:cd:0c:ce: d0:61:e6:96:83:71:a1:08:c9:de:c6:9c:05:27:bc: a4:3b:37:de:55:36:cd:89:ab:24:08:b1:eb:9b:1c: 36:22:a4:eb:8b:48:ed:79:b8:e8:b9:0c:4a:00:e6: 0b:73:33:29:b7:79:c8:f0:ac:a3:62:44:cc:30:1e: c7:71:89:48:59:c0:45:59:65:97:76:cd:8e:41:ff: aa:1a:59:0e:6b:82:20:62:a1:46:dd:c0:b1:2f:45: 84:b6:2a:87:bb:c4:5e:e0:82:7f:9b:28:8c:8b:e2: f5:02:4d:7e:bc:d5:5c:86:ed:bb:7d:e9:fd:58:c0: da:40:90:7e:ce:e2:9c:22:dc:08:1a:80:31:d5:b6: 65:4b:80:30:9c:6b:5b:d0:e4:55:76:7b:f4:3f:81: 18:4d:b6:a9:8e:35:15:fe:c1:c7:5a:6c:77:dd:a0: ab:be:80:a1:81:93:18:11:de:27:0c:97:1f:ec:17: ac:e1:f8:eb:ff:fd:1b:58:d1:ff:ba:47:ed:92:50: 4e:6e:21:48:ea:fd:fb:c8:7c:b2:3c:97:e7:5e:c4: 1e:4a:8c:40:1e:af:1b:f1:f9:81:fe:1d:62:90:30: 20:c5:98:ae:c5:2c:d3:af:d6:20:37:2d:f0:ca:cd: 12:65 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 59:F5:80:CA:67:0A:C1:4A:62:3D:16:EA:D8:52:E0:7F:D4:34:B0:41 X509v3 Authority Key Identifier: keyid:59:F5:80:CA:67:0A:C1:4A:62:3D:16:EA:D8:52:E0:7F:D4:34:B0:41 X509v3 Basic Constraints: critical CA:TRUE Signature Algorithm: sha256WithRSAEncryption 7b:f2:22:b5:1d:d9:1e:84:7d:15:01:df:20:9f:a4:58:a3:a9: f6:82:3b:55:17:8d:9e:2c:90:1b:5d:84:37:4e:fe:2a:a9:38: cd:f1:71:e5:91:bc:27:16:6b:bf:b5:dc:3b:9c:12:05:d8:fd: 19:26:9a:4b:6e:c3:15:ed:1b:8a:e1:39:c4:7b:24:ff:39:95: 46:ee:ba:77:0e:2a:e1:fd:ee:bd:2c:ba:15:ed:c3:7d:52:ae: 8f:e7:50:20:56:58:27:92:e7:8f:fd:82:8e:dd:14:84:ce:9a: bd:64:fd:d6:be:a1:70:5d:1a:a1:88:89:76:d7:1d:f6:13:d9: 9e:77:b2:27:04:2c:c2:c9:ec:56:be:36:03:a3:77:7a:22:87: 2b:da:e8:4d:7b:79:83:2f:7b:ba:e1:6c:44:1b:4f:56:14:3c: 89:fc:9a:cc:66:5b:97:d2:74:6e:00:cd:81:a9:16:dd:31:9c: e3:8c:ae:4d:db:62:cb:a7:7d:96:eb:43:d3:45:45:ae:d4:fe: eb:7a:8b:e4:f0:42:4c:9f:ee:5a:f5:f6:4d:d2:aa:55:08:d6: e6:ea:e7:58:44:d6:96:dd:a6:c8:d6:29:8e:08:c4:45:2f:a0: e9:7a:df:e9:53:5b:17:85:71:b1:7d:1f:e0:28:84:0d:7b:3a: 2b:07:e2:e3 # Verify certificate is self-signed # --------------------------------------------------------------------- $ openssl verify -CAfile smartcard.cert.pem smartcard.cert.pem smartcard.cert.pem: OK # Store the generated cert in the card # --------------------------------------------------------------------- $ pkcs15-init --store-certificate smartcard.cert.pem --auth-id 01 --id 707db33cfbd0712e0d5cfc4238fa85be44da990d --format pem Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00 Security officer PIN [Security Officer PIN] required. Please enter Security officer PIN [Security Officer PIN]: User PIN [John Doe] required. Please enter User PIN [John Doe]: # Verify stored certificate # Note: "Encoded serial" must match openssl output # --------------------------------------------------------------------- $ pkcs15-tool --list-certificates Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00 X.509 Certificate [Certificate] Object Flags : [0x2], modifiable Authority : no Path : 3f0050153104 ID : 707db33cfbd0712e0d5cfc4238fa85be44da990d Encoded serial : 02 09 00D4FA71C4A6CF7D88 # Decode Certificate through OpenSSL # --------------------------------------------------------------------- $ pkcs15-tool --read-certificate 707db33cfbd0712e0d5cfc4238fa85be44da990d | openssl x509 -noout -text Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00 Certificate: Data: [...] # Delete stored certificate # --------------------------------------------------------------------- $ pkcs15-init --delete-objects cert --id 707db33cfbd0712e0d5cfc4238fa85be44da990d Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00 Security officer PIN [Security Officer PIN] required. Please enter Security officer PIN [Security Officer PIN]: Deleted 1 objects