opencryptoki-users Mailing List for openCryptoki (Page 10)
Brought to you by:
ebarretto
You can subscribe to this list here.
2005 |
Jan
|
Feb
|
Mar
|
Apr
(3) |
May
|
Jun
(8) |
Jul
(5) |
Aug
(5) |
Sep
(2) |
Oct
|
Nov
(3) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2006 |
Jan
(7) |
Feb
(5) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
(7) |
Aug
|
Sep
|
Oct
|
Nov
(8) |
Dec
(3) |
2007 |
Jan
(14) |
Feb
|
Mar
|
Apr
(14) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(2) |
Nov
(10) |
Dec
(6) |
2008 |
Jan
(2) |
Feb
|
Mar
(5) |
Apr
(6) |
May
(3) |
Jun
(6) |
Jul
(10) |
Aug
(4) |
Sep
(17) |
Oct
(13) |
Nov
(43) |
Dec
(72) |
2009 |
Jan
(4) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(9) |
Sep
(5) |
Oct
(2) |
Nov
|
Dec
|
2010 |
Jan
|
Feb
|
Mar
|
Apr
|
May
(1) |
Jun
|
Jul
(23) |
Aug
|
Sep
|
Oct
|
Nov
(9) |
Dec
|
2011 |
Jan
(2) |
Feb
|
Mar
|
Apr
|
May
(1) |
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2012 |
Jan
|
Feb
(15) |
Mar
|
Apr
(1) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(6) |
Oct
|
Nov
(1) |
Dec
|
2013 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(6) |
Sep
|
Oct
|
Nov
|
Dec
|
2016 |
Jan
(1) |
Feb
|
Mar
(1) |
Apr
|
May
(5) |
Jun
(1) |
Jul
|
Aug
|
Sep
(4) |
Oct
(2) |
Nov
|
Dec
|
2017 |
Jan
|
Feb
|
Mar
(2) |
Apr
(1) |
May
(2) |
Jun
(1) |
Jul
|
Aug
|
Sep
(1) |
Oct
(2) |
Nov
(1) |
Dec
|
2018 |
Jan
|
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
|
2019 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2021 |
Jan
|
Feb
(4) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: <bur...@ya...> - 2006-11-01 15:58:10
|
I have problems using cryptoki using with TPM. My TPM is working fine I am = sure about it.=0AI have applied the method mentioned in trousers faq. SRK i= s NULL. =0A=0A[root@dungeon opencryptoki]# tpmtoken_init=0AA new TPM securi= ty officer password is needed. The password must be between 6 and 127 chara= cters in length.=0AEnter new password:=0AConfirm password:=0ASegmentation f= ault=0A[root@dungeon opencryptoki]# tpmtoken_init=0AWarning: The TPM token = has already been initialized. Reinitializing the TPM token will cause all T= PM token data to be lost.=0AClear the TPM token data? [y/N]: y=0AEnter the = TPM security officer password:=0AC_InitToken failed: 0x000000a0 (160)=0A=0A= I have entered SO PIN as 87654321.=0A=0A[root@dungeon opencryptoki]# pkcsco= nf -P -c 0=0AEnter the SO PIN: ********=0AEnter the new SO PIN: ********=0A= Re-enter the new SO PIN: ********=0AError setting PIN: 0x6=0A=0ABut Cryptok= i has seen my TPM.=0A[root@dungeon opencryptoki]# pkcsconf -s -t=0AToken #0= Info:=0A Label: IBM PKCS#11 TPM Token=0A Manufacturer: IBM C= orp.=0A Model: TPM v1.1 Token=0A Serial Number: 123=0A = Flags: 0x980445 (RNG|LOGIN_REQUIRED|CLOCK_ON_TOKEN|TOKEN_INITIALIZED|USER_= PIN_TO_BE_CHANGED|SO_PIN_COUNT_LOW|SO_PIN_TO_BE_CHANGED)=0A Sessions= : -1/-1=0A R/W Sessions: -1/-1=0A PIN Length: 6-127=0A = Public Memory: 0xFFFFFFFF/0xFFFFFFFF=0A Private Memory: 0xFFFFFFFF/= 0xFFFFFFFF=0A Hardware Version: 1.0=0A Firmware Version: 1.0= =0A Time: 05:52:06 PM=0AToken #1 Info:=0A Label: IBM OS PKCS#= 11=0A Manufacturer: IBM Corp.=0A Model: IBM SoftTok=0A = Serial Number: 123=0A Flags: 0x880045 (RNG|LOGIN_REQUIRED|CLOCK_ON_= TOKEN|USER_PIN_TO_BE_CHANGED|SO_PIN_TO_BE_CHANGED)=0A Sessions: -1/-= 1=0A R/W Sessions: -1/-1=0A PIN Length: 4-8=0A Public = Memory: 0xFFFFFFFF/0xFFFFFFFF=0A Private Memory: 0xFFFFFFFF/0xFFFFFF= FF=0A Hardware Version: 1.0=0A Firmware Version: 1.0=0A = Time: 05:52:06 PM=0ASlot #0 Info=0A Description: Linux 2.6.18 Linu= x (TPM)=0A Manufacturer: Linux 2.6.18=0A Flags: 0x5 (TOKEN_PR= ESENT|HW_SLOT)=0A Hardware Version: 0.0=0A Firmware Version: = 1.1=0ASlot #1 Info=0A Description: Linux 2.6.18 Linux (Soft)=0A = Manufacturer: Linux 2.6.18=0A Flags: 0x1 (TOKEN_PRESENT)=0A = Hardware Version: 0.0=0A Firmware Version: 1.1=0A=0ADo you have an= y idea what is going on? What should I do?=0A=0AThanx in advance.=0A =0A-- = burak()=0A(ps: bf)=0AMETU CENG '06=0A=0A=0A=0A |
From: Kent Y. <shp...@gm...> - 2006-07-13 15:39:39
|
Forwarding this on to the list.... ---------- Forwarded message ---------- From: sit...@li... <sit...@li...> Date: Jul 13, 2006 10:07 AM Subject: Uncaught bounce notification To: ope...@li... The attached message was received as a bounce, but either the bounce format was not recognized, or no member addresses could be extracted from it. This mailing list has been configured to send all unrecognized bounce messages to the list administrator(s). For more information see: https://lists.sourceforge.net/lists/admin/opencryptoki-users/bounce ---------- Forwarded message ---------- From: Daniel H Jones <dan...@us...> To: "King G.Great" <kin...@gm...> Date: Thu, 13 Jul 2006 10:07:19 -0500 Subject: Re: [opencryptoki-users] opencryptoki-users Digest, Vol 2, Issue 3 Gev, I can't explain why the copy of ltmain.sh in /usr/share/libtool/libltdl was overwritten. That is not done by "libtoolize -c" or the bootstrap.sh script in the tarball. I just repeated the process I described and confirmed that it works and /usr/share/libtool/libltdl/ltmain.sh is not corrupted. Thanks, Dan Jones IBM Linux Technology Center, Security 512-838-1794 (T/L 678-1794) dan...@us... "King G.Great" <kin...@gm...> Sent by: ope...@li... 07/13/2006 01:59 AM To ope...@li... cc Subject Re: [opencryptoki-users] opencryptoki-users Digest, Vol 2, Issue 3 Hi Daniel Thank you for your helpfull response. But here is what I had found two days ago. It turned out that SOMEHOW.. I don't know how.. the ltmain.sh script form openCryptoki folder replaced the ltmain.sh in /usr/share/libtool/ folder during build. After coping the ltmain.sh from /usr/share/libtool/libltdl/ back to /usr/share/libtool/ this problem never appear again. BTW we have 3 machines running RedHat Enterprise Linux 4 and on one of them we had the same issue (but never on 2 others). To reproduce the issue on Fedora 5 I tried to reinstall it (I started with hard drive formatting) but the problem had disappeared and now I don't know what to do :) Did you have the same situation or yours was slightly different from mine? Now I can't reproduce the problem to check your solution. I don't know at which point during build the ltmain.sh from my folder got into /usr/share/libtool/. If it happenes during bootstrap then I'm not sure if 'libtoolize -c ' will help :( Thank you Gev On 7/12/06, ope...@li... < ope...@li...> wrote: Send opencryptoki-users mailing list submissions to ope...@li... To subscribe or unsubscribe via the World Wide Web, visit https://lists.sourceforge.net/lists/listinfo/opencryptoki-users or, via email, send a message with subject or body 'help' to ope...@li... You can reach the person managing the list at ope...@li... When replying, please edit your Subject line so it is more specific than "Re: Contents of opencryptoki-users digest..." Today's Topics: 1. Fw: build fail on Fedora 5 (Daniel H Jones) ---------------------------------------------------------------------- Message: 1 Date: Mon, 10 Jul 2006 15:01:15 -0500 From: Daniel H Jones < dan...@us...> Subject: [opencryptoki-users] Fw: build fail on Fedora 5 To: ope...@li... Message-ID: < OF4...@us...> Content-Type: text/plain; charset="us-ascii" It looks like the tarball contains an ltmain.sh that is incompatible with FC5. Try this ... rm ltmain.sh run libtoolize -c run ./configure then try running make again. I was able to reproduce the problem on my FC 5 machine and fixed it using the steps above. ============================================================== Hi all I'm trying to build the openCryptoki 2.1.5-6 on Fedora 5 (kernel 2.6.15-1) and it fails saying: libtool: unrecognized option `--tag=CC' I used to have the same problem on RedHat Enterprise Linux 4 but there running "libtoolize -f" fixed the problem. On Fedora 5 it doesn't help. Here are the version infos on my build system: [gev@Fedora5 ~]$ gcc --version gcc (GCC) 4.1.0 20060304 (Red Hat 4.1.0-3 ) Copyright (C) 2006 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ automake --version automake (GNU automake) 1.9.6 Written by Tom Tromey < tr...@re...>. Copyright 2005 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ autoconf --version autoconf (GNU Autoconf) 2.59 Written by David J. MacKenzie and Akim Demaille. Copyright (C) 2003 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ libtool --version ltmain.sh (GNU libtool) 1.5.22 (1.1220.2.365 2005/12/18 22:14:06) Copyright (C) 2005 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. What is strange is that running libtool from openCryptoki's folder reports: [gev@Fedora5 cryptoki]$ ./libtool --version ltmain.sh (GNU libtool) 1.4 (1.920 2001/04/24 23:26:18) Had anyone built openCryptoki on Fedora 5 and can help me to resolve this issue with libtool? Any help is appreciated Thanks in advance Gev Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ opencryptoki-users mailing list ope...@li... https://lists.sourceforge.net/lists/listinfo/opencryptoki-users Thanks, Dan Jones IBM Linux Technology Center, Security 512-838-1794 (T/L 678-1794) dan...@us... -------------- next part -------------- An HTML attachment was scrubbed... URL: http://sourceforge.net/mailarchive/forum.php?forum=opencryptoki-users/attachments/20060710/9a21e2df/attachment.html ------------------------------ ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 ------------------------------ _______________________________________________ opencryptoki-users mailing list ope...@li... https://lists.sourceforge.net/lists/listinfo/opencryptoki-users End of opencryptoki-users Digest, Vol 2, Issue 3 ************************************************ ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ opencryptoki-users mailing list ope...@li... https://lists.sourceforge.net/lists/listinfo/opencryptoki-users -- Kent Yoder IBM LTC Security Dev. |
From: Daniel H J. <dan...@us...> - 2006-07-13 15:07:29
|
Gev, I can't explain why the copy of ltmain.sh in /usr/share/libtool/libltdl was overwritten. That is not done by "libtoolize -c" or the bootstrap.sh script in the tarball. I just repeated the process I described and confirmed that it works and /usr/share/libtool/libltdl/ltmain.sh is not corrupted. Thanks, Dan Jones IBM Linux Technology Center, Security 512-838-1794 (T/L 678-1794) dan...@us... "King G.Great" <kin...@gm...> Sent by: ope...@li... 07/13/2006 01:59 AM To ope...@li... cc Subject Re: [opencryptoki-users] opencryptoki-users Digest, Vol 2, Issue 3 Hi Daniel Thank you for your helpfull response. But here is what I had found two days ago. It turned out that SOMEHOW.. I don't know how.. the ltmain.sh script form openCryptoki folder replaced the ltmain.sh in /usr/share/libtool/ folder during build. After coping the ltmain.sh from /usr/share/libtool/libltdl/ back to /usr/share/libtool/ this problem never appear again. BTW we have 3 machines running RedHat Enterprise Linux 4 and on one of them we had the same issue (but never on 2 others). To reproduce the issue on Fedora 5 I tried to reinstall it (I started with hard drive formatting) but the problem had disappeared and now I don't know what to do :) Did you have the same situation or yours was slightly different from mine? Now I can't reproduce the problem to check your solution. I don't know at which point during build the ltmain.sh from my folder got into /usr/share/libtool/. If it happenes during bootstrap then I'm not sure if 'libtoolize -c ' will help :( Thank you Gev On 7/12/06, ope...@li... < ope...@li...> wrote: Send opencryptoki-users mailing list submissions to ope...@li... To subscribe or unsubscribe via the World Wide Web, visit https://lists.sourceforge.net/lists/listinfo/opencryptoki-users or, via email, send a message with subject or body 'help' to ope...@li... You can reach the person managing the list at ope...@li... When replying, please edit your Subject line so it is more specific than "Re: Contents of opencryptoki-users digest..." Today's Topics: 1. Fw: build fail on Fedora 5 (Daniel H Jones) ---------------------------------------------------------------------- Message: 1 Date: Mon, 10 Jul 2006 15:01:15 -0500 From: Daniel H Jones < dan...@us...> Subject: [opencryptoki-users] Fw: build fail on Fedora 5 To: ope...@li... Message-ID: < OF4...@us...> Content-Type: text/plain; charset="us-ascii" It looks like the tarball contains an ltmain.sh that is incompatible with FC5. Try this ... rm ltmain.sh run libtoolize -c run ./configure then try running make again. I was able to reproduce the problem on my FC 5 machine and fixed it using the steps above. ============================================================== Hi all I'm trying to build the openCryptoki 2.1.5-6 on Fedora 5 (kernel 2.6.15-1) and it fails saying: libtool: unrecognized option `--tag=CC' I used to have the same problem on RedHat Enterprise Linux 4 but there running "libtoolize -f" fixed the problem. On Fedora 5 it doesn't help. Here are the version infos on my build system: [gev@Fedora5 ~]$ gcc --version gcc (GCC) 4.1.0 20060304 (Red Hat 4.1.0-3 ) Copyright (C) 2006 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ automake --version automake (GNU automake) 1.9.6 Written by Tom Tromey < tr...@re...>. Copyright 2005 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ autoconf --version autoconf (GNU Autoconf) 2.59 Written by David J. MacKenzie and Akim Demaille. Copyright (C) 2003 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ libtool --version ltmain.sh (GNU libtool) 1.5.22 (1.1220.2.365 2005/12/18 22:14:06) Copyright (C) 2005 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. What is strange is that running libtool from openCryptoki's folder reports: [gev@Fedora5 cryptoki]$ ./libtool --version ltmain.sh (GNU libtool) 1.4 (1.920 2001/04/24 23:26:18) Had anyone built openCryptoki on Fedora 5 and can help me to resolve this issue with libtool? Any help is appreciated Thanks in advance Gev Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ opencryptoki-users mailing list ope...@li... https://lists.sourceforge.net/lists/listinfo/opencryptoki-users Thanks, Dan Jones IBM Linux Technology Center, Security 512-838-1794 (T/L 678-1794) dan...@us... -------------- next part -------------- An HTML attachment was scrubbed... URL: http://sourceforge.net/mailarchive/forum.php?forum=opencryptoki-users/attachments/20060710/9a21e2df/attachment.html ------------------------------ ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 ------------------------------ _______________________________________________ opencryptoki-users mailing list ope...@li... https://lists.sourceforge.net/lists/listinfo/opencryptoki-users End of opencryptoki-users Digest, Vol 2, Issue 3 ************************************************ ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ opencryptoki-users mailing list ope...@li... https://lists.sourceforge.net/lists/listinfo/opencryptoki-users |
From: King G.G. <kin...@gm...> - 2006-07-13 06:59:47
|
Hi Daniel Thank you for your helpfull response. But here is what I had found two days ago. It turned out that SOMEHOW.. I don't know how.. the ltmain.sh script form openCryptoki folder replaced the ltmain.sh in /usr/share/libtool/ folder during build. After coping the ltmain.sh from /usr/share/libtool/libltdl/ back to /usr/share/libtool/ this problem never appear again. BTW we have 3 machines running RedHat Enterprise Linux 4 and on one of them we had the same issue (but never on 2 others). To reproduce the issue on Fedora 5 I tried to reinstall it (I started with hard drive formatting) but the problem had disappeared and now I don't know what to do :) Did you have the same situation or yours was slightly different from mine? Now I can't reproduce the problem to check your solution. I don't know at which point during build the ltmain.sh from my folder got into /usr/share/libtool/. If it happenes during bootstrap then I'm not sure if 'libtoolize -c ' will help :( Thank you Gev On 7/12/06, ope...@li... <ope...@li...> wrote: > > Send opencryptoki-users mailing list submissions to > ope...@li... > > To subscribe or unsubscribe via the World Wide Web, visit > https://lists.sourceforge.net/lists/listinfo/opencryptoki-users > or, via email, send a message with subject or body 'help' to > ope...@li... > > You can reach the person managing the list at > ope...@li... > > When replying, please edit your Subject line so it is more specific > than "Re: Contents of opencryptoki-users digest..." > > > Today's Topics: > > 1. Fw: build fail on Fedora 5 (Daniel H Jones) > > > ---------------------------------------------------------------------- > > Message: 1 > Date: Mon, 10 Jul 2006 15:01:15 -0500 > From: Daniel H Jones <dan...@us...> > Subject: [opencryptoki-users] Fw: build fail on Fedora 5 > To: ope...@li... > Message-ID: > < > OF4...@us...> > Content-Type: text/plain; charset="us-ascii" > > It looks like the tarball contains an ltmain.sh that is incompatible with > FC5. Try this ... > > rm ltmain.sh > run libtoolize -c > run ./configure > then try running make again. > > I was able to reproduce the problem on my FC 5 machine and fixed it using > the steps above. > > ============================================================== > > Hi all > > I'm trying to build the openCryptoki 2.1.5-6 on Fedora 5 (kernel 2.6.15-1) > and it fails saying: > > libtool: unrecognized option `--tag=CC' > > I used to have the same problem on RedHat Enterprise Linux 4 but there > running "libtoolize -f" fixed the problem. > On Fedora 5 it doesn't help. > > Here are the version infos on my build system: > > [gev@Fedora5 ~]$ gcc --version > gcc (GCC) 4.1.0 20060304 (Red Hat 4.1.0-3) > Copyright (C) 2006 Free Software Foundation, Inc. > This is free software; see the source for copying conditions. There is NO > warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR > PURPOSE. > [gev@Fedora5 ~]$ automake --version > automake (GNU automake) 1.9.6 > Written by Tom Tromey <tr...@re...>. > Copyright 2005 Free Software Foundation, Inc. > This is free software; see the source for copying conditions. There is NO > warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR > PURPOSE. > [gev@Fedora5 ~]$ autoconf --version > autoconf (GNU Autoconf) 2.59 > Written by David J. MacKenzie and Akim Demaille. > Copyright (C) 2003 Free Software Foundation, Inc. > This is free software; see the source for copying conditions. There is NO > warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR > PURPOSE. > [gev@Fedora5 ~]$ libtool --version > ltmain.sh (GNU libtool) 1.5.22 (1.1220.2.365 2005/12/18 22:14:06) > Copyright (C) 2005 Free Software Foundation, Inc. > This is free software; see the source for copying conditions. There is NO > > warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR > PURPOSE. > What is strange is that running libtool from openCryptoki's folder > reports: > [gev@Fedora5 cryptoki]$ ./libtool --version > ltmain.sh (GNU libtool) 1.4 (1.920 2001/04/24 23:26:18) > Had anyone built openCryptoki on Fedora 5 and can help me to resolve this > issue with libtool? > Any help is appreciated > Thanks in advance > Gev > Using Tomcat but need to do more? Need to support web services, security? > Get stuff done quickly with pre-integrated technology to make your job > easier > Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 > _______________________________________________ > opencryptoki-users mailing list > ope...@li... > https://lists.sourceforge.net/lists/listinfo/opencryptoki-users > > Thanks, > Dan Jones > IBM Linux Technology Center, Security > 512-838-1794 (T/L 678-1794) > dan...@us... > -------------- next part -------------- > An HTML attachment was scrubbed... > URL: http://sourceforge.net/mailarchive/forum.php?forum=opencryptoki-users/attachments/20060710/9a21e2df/attachment.html > > > ------------------------------ > > > ------------------------------------------------------------------------- > Using Tomcat but need to do more? Need to support web services, security? > Get stuff done quickly with pre-integrated technology to make your job > easier > Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 > > > ------------------------------ > > _______________________________________________ > opencryptoki-users mailing list > ope...@li... > https://lists.sourceforge.net/lists/listinfo/opencryptoki-users > > > End of opencryptoki-users Digest, Vol 2, Issue 3 > ************************************************ > |
From: Kent Y. <shp...@gm...> - 2006-07-13 03:54:49
|
Hi Tanvi, It sounds like you need to add /usr/local/lib to your /etc/ld.so.conf file, then re-run ldconfig to get the library added to the linker cache. Can you try this and tell me if that has any effect? Kent On 7/12/06, Vyas, Tanvi <Tan...@cd...> wrote: > > > > > Hello, > > > > I have installed opencryptoki-2.2.4 on my Virtual Linux Machine (kernel > version 2.6.17-1.2139_FC5.stk16smp) using VMPlayer. I have also installe= d a > tpm_emulator, TrouSerS, and tpm_tools. I am trying to follow the > instructions here: > > http://trousers.sourceforge.net/pkcs11.html and am stuck on > trying to login as the Security Officer. > > > > After following the instructions on the opencryptoki README, I have all t= he > files listed in the README in the correct directories (except for the ICA > files). Now I'm trying to follow these instructions for configuration: > > http://www-128.ibm.com/developerworks/library/s-pkcs/ > > > > I do the following: > > groupadd pkcs11 > > output: groupadd: group pkcs11 exists > /usr/local/lib/pkcs11/methods/pkcs11_startup > /usr/local/sbin/pkcsslotd > > > [/usr/lib/pkcs11/methods/4758_status file not there, so I > skipped this step] > > > > /usr/local/lib/pkcs11/methods/pkcsconf =96I =96c 0 > > > > And I get an error: > > Error loading PKCS#11 library: 0xBF8FF964 > > dlopen error: libopencryptoki.so: cannot open shared object file: No such > file or directory. > > > > However, libopencryptoki.so is where it should be: both in > /usr/local/lib/libopencryptoki.so and > /usr/local/lib/opencryptoki/libopencryptoki.so. They are > symbolic links that ultimately link to > /usr/local/lib/opencryptoki/libopencryptoki.so.0.0.0. > > > > Do you have any ideas as to why I'm getting this error? > > > > Thank you for your help! > > > > Sincerely, > > Tanvi Vyas > > > > > > ------------------------------------------------------------------------- > Using Tomcat but need to do more? Need to support web services, security? > Get stuff done quickly with pre-integrated technology to make your job > easier > Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronim= o > http://sel.as-us.falkag.net/sel?cmd=3Dlnk&kid=3D120709&bid=3D263057&dat= =3D121642 > > > _______________________________________________ > opencryptoki-users mailing list > ope...@li... > https://lists.sourceforge.net/lists/listinfo/opencryptoki-users > > > --=20 Kent Yoder IBM LTC Security Dev. |
From: Vyas, T. <Tan...@cd...> - 2006-07-13 00:56:47
|
Hello, =20 I have installed opencryptoki-2.2.4 on my Virtual Linux Machine (kernel version 2.6.17-1.2139_FC5.stk16smp) using VMPlayer. I have also installed a tpm_emulator, TrouSerS, and tpm_tools. I am trying to follow the instructions here: http://trousers.sourceforge.net/pkcs11.html and am stuck on trying to login as the Security Officer. =20 After following the instructions on the opencryptoki README, I have all the files listed in the README in the correct directories (except for the ICA files). Now I'm trying to follow these instructions for configuration: http://www-128.ibm.com/developerworks/library/s-pkcs/ =20 I do the following: groupadd pkcs11 output: groupadd: group pkcs11 exists /usr/local/lib/pkcs11/methods/pkcs11_startup /usr/local/sbin/pkcsslotd [/usr/lib/pkcs11/methods/4758_status file not there, so I skipped this step] =20 /usr/local/lib/pkcs11/methods/pkcsconf -I -c 0 =20 And I get an error: Error loading PKCS#11 library: 0xBF8FF964 dlopen error: libopencryptoki.so: cannot open shared object file: No such file or directory. =20 However, libopencryptoki.so is where it should be: both in /usr/local/lib/libopencryptoki.so and /usr/local/lib/opencryptoki/libopencryptoki.so. They are symbolic links that ultimately link to /usr/local/lib/opencryptoki/libopencryptoki.so.0.0.0. =20 Do you have any ideas as to why I'm getting this error? =20 Thank you for your help! =20 Sincerely, Tanvi Vyas =20 =20 |
From: Daniel H J. <dan...@us...> - 2006-07-10 19:56:00
|
It looks like the tarball contains an ltmain.sh that is incompatible with FC5. Try this ... rm ltmain.sh run libtoolize -c run ./configure then try running make again. I was able to reproduce the problem on my FC 5 machine and fixed it using the steps above. ============================================================== Hi all I'm trying to build the openCryptoki 2.1.5-6 on Fedora 5 (kernel 2.6.15-1) and it fails saying: libtool: unrecognized option `--tag=CC' I used to have the same problem on RedHat Enterprise Linux 4 but there running "libtoolize -f" fixed the problem. On Fedora 5 it doesn't help. Here are the version infos on my build system: [gev@Fedora5 ~]$ gcc --version gcc (GCC) 4.1.0 20060304 (Red Hat 4.1.0-3) Copyright (C) 2006 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ automake --version automake (GNU automake) 1.9.6 Written by Tom Tromey <tr...@re...>. Copyright 2005 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ autoconf --version autoconf (GNU Autoconf) 2.59 Written by David J. MacKenzie and Akim Demaille. Copyright (C) 2003 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ libtool --version ltmain.sh (GNU libtool) 1.5.22 (1.1220.2.365 2005/12/18 22:14:06) Copyright (C) 2005 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. What is strange is that running libtool from openCryptoki's folder reports: [gev@Fedora5 cryptoki]$ ./libtool --version ltmain.sh (GNU libtool) 1.4 (1.920 2001/04/24 23:26:18) Had anyone built openCryptoki on Fedora 5 and can help me to resolve this issue with libtool? Any help is appreciated Thanks in advance Gev Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ opencryptoki-users mailing list ope...@li... https://lists.sourceforge.net/lists/listinfo/opencryptoki-users Thanks, Dan Jones IBM Linux Technology Center, Security 512-838-1794 (T/L 678-1794) dan...@us... |
From: King G.G. <kin...@gm...> - 2006-07-06 07:20:27
|
Hi all I'm trying to build the openCryptoki 2.1.5-6 on Fedora 5 (kernel 2.6.15-1) and it fails saying: libtool: unrecognized option `--tag=CC' I used to have the same problem on RedHat Enterprise Linux 4 but there running "libtoolize -f" fixed the problem. On Fedora 5 it doesn't help. Here are the version infos on my build system: [gev@Fedora5 ~]$ gcc --version gcc (GCC) 4.1.0 20060304 (Red Hat 4.1.0-3) Copyright (C) 2006 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ automake --version automake (GNU automake) 1.9.6 Written by Tom Tromey <tr...@re...>. Copyright 2005 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ autoconf --version autoconf (GNU Autoconf) 2.59 Written by David J. MacKenzie and Akim Demaille. Copyright (C) 2003 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. [gev@Fedora5 ~]$ libtool --version ltmain.sh (GNU libtool) 1.5.22 (1.1220.2.365 2005/12/18 22:14:06) Copyright (C) 2005 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. What is strange is that running libtool from openCryptoki's folder reports: [gev@Fedora5 cryptoki]$ ./libtool --version ltmain.sh (GNU libtool) 1.4 (1.920 2001/04/24 23:26:18) Had anyone built openCryptoki on Fedora 5 and can help me to resolve this issue with libtool? Any help is appreciated Thanks in advance Gev |
From: Michael H. <mi...@ha...> - 2006-06-30 16:16:52
|
----- Forwarded message from ope...@li... ----- Subject: tpm_takeownership From: Claudia Leonarda <04...@st...> hi we bought an hp compaq dc7600 ultra-slim desktop business pc we try to use the truosers tpm_tools when we want to take the ownership of the chip we have this problem: [root@localhost tpm_mgmt]# LD_LIBRARY_PATH=../../../oricla ./tpm_takeownership -l debug Enter owner password: Confirm password: Enter SRK password: Confirm password: Tspi_Context_Create success Tspi_Context_Connect success Tspi_Context_GetTpmObject success Tspi_GetPolicyObject success Tspi_Policy_SetSecret success Tspi_Context_CreateObject success Tspi_GetPolicyObject success Tspi_Policy_SetSecret success Tspi_TPM_TakeOwnership failed: 0x00000021 - layer=tpm, code=0021 (33), Decryption error Tspi_Context_CloseObject success Tspi_Context_FreeMemory success Tspi_Context_Close success we looked at the codes and also try with all te testsuite and verify the same problem(Tspi_TPM_TakeOwnership returned (33) TCPA_E_DECRYPT_ERROR) what have we to do?please help us..we have to do a project with this chip have a good day, thanks a lot Dalla Valle Oriana and Claudia Leonarda ----- End forwarded message ----- |
From: Claudia L. <04...@st...> - 2006-06-30 16:07:12
|
hi we bought an hp compaq dc7600 ultra-slim desktop business pc we try to use the truosers tpm_tools when we want to take the ownership of the chip we have this problem: [root@localhost tpm_mgmt]# LD_LIBRARY_PATH=3D../../../oricla = ./tpm_takeownership -l debug Enter owner password: Confirm password: Enter SRK password: Confirm password: Tspi_Context_Create success Tspi_Context_Connect success Tspi_Context_GetTpmObject success Tspi_GetPolicyObject success Tspi_Policy_SetSecret success Tspi_Context_CreateObject success Tspi_GetPolicyObject success Tspi_Policy_SetSecret success Tspi_TPM_TakeOwnership failed: 0x00000021 - layer=3Dtpm, code=3D0021 = (33), Decryption error Tspi_Context_CloseObject success Tspi_Context_FreeMemory success Tspi_Context_Close success we looked at the codes and also try with all te testsuite and verify the = same problem(Tspi_TPM_TakeOwnership returned (33) TCPA_E_DECRYPT_ERROR) what have we to do?please help us..we have to do a project with this = chip have a good day, thanks a lot Dalla Valle Oriana and Claudia Leonarda |
From: Qiyan S. <Qiy...@Su...> - 2006-02-22 00:29:07
|
Hi, In 2.2.0 and before, openCryptoki dlopens 32 bit stdll if sizeof(long) == 4. Otherwise it dlopens the 64 bit stdll, as shown below (from apiutil.c): if ( sizeof(long) == 4 ) { dllload[i].dlop_p = dlopen(sinfp->dll_location,RTLD_NOW); } else { // 64 bit env sprintf(buffer,"%s64",sinfp->dll_location); dllload[i].dlop_p = dlopen(buffer,RTLD_NOW); } In 2.2.2 release, this has been changed to just dllload[i].dlop_p = dlopen(sinfp->dll_location,RTLD_NOW); This works for 32 bit apps. For 64 bit apps, however, it still tries to dlopen the 32 bit stdll and fails. How to run 64 bit apps using 2.2.2 release? Thanks, Qiyan |
From: Jochen S. <sch...@oc...> - 2006-02-20 16:22:28
|
Hi Kent, yes, it works when I create the directory. Thanks! Cheers, Jochen On Mon, 2006-02-20 at 10:13 -0600, Kent Yoder wrote: > Hi Jochen, > > This may be the problem that someone else was seeing awhile back... > Does the /var/lib/opencryptoki/tpm/schneider directory exist? If > not, can you create it and try again? > > Kent |
From: Tom L. <to...@us...> - 2006-02-20 16:20:00
|
ope...@li... wrote on 02/20/2006 04:47:52 AM: > Hi, > > I am trying to getting Opencryptoki (2.2.2-rc4) going with Trousers and > the tpm_emulator. Unfortunately, I can't get passed tpm_takeownership, > pkcsconf doesn't work (though it did a while ago). I am a member of the > pkcs11 group. When is NVTOK.DAT supposed to be created? > One thing you can check is to see that your TPM SRK does not have a password associated with it. If you supplied an SRK password when you took ownership then you'll need to perform a tpm_changeownerauth command using the "-s" option to change/remove the SRK password. When prompted to enter the new SRK password just hit enter. See if that helps. > schneider@piquod:~$ /usr/sbin/pkcsconf -s > LOG_DEBUG TSPI ../tcsd_api/clntside.c:58 Sending TSP packet to host > localhost. > LOG_DEBUG TSPI ../tcsd_api/clntside.c:74 Connecting to 127.0.0.1 > LOG_DEBUG TSPI ../tcsd_api/tcstp.c:388 TCS_OpenContext_RPC_TP: Received > TCS Context: 0xa0c1b30b > ST MSG TPM_STDLL loadsave.c:477 whammy > ST MSG TPM_STDLL utility.c:788 whammy > LOG_ERR TPM_STDLL loadsave.c:396 ERROR: failed > opening /var/lib/opencryptoki/tpm/schneider/NVTOK.DAT for read: No such > file or directory > ST MSG TPM_STDLL new_host.c:488 whammy > ST MSG TPM_STDLL new_host.c:506 whammy > C_GetSlotCount returned 0 slots. Check that your tokens are installed > correctly. > > > /var/lib/opencryptoki/pk_config_data contains: > > TRUE|0|Linux 2.6.14-1-686 Linux (TPM)|Linux 2.6.14-1-686|TRUE|FALSE| > TRUE|0|0|1|1|NONE|/usr/lib/opencryptoki/stdll/libpkcs11_tpm.so| > ST_Initialize > > /var/log/debug contains: > > Feb 20 10:45:33 piquod openCryptokiModule[17850]: Logging enabled 1 > enabled > Feb 20 10:45:33 piquod openCryptokiModule[17850]: C_GetFunctionList > Feb 20 10:45:33 piquod openCryptokiModule[17850]: C_Initialize > Feb 20 10:45:33 piquod openCryptokiModule[17850]: Anchor allocated at > 804d380 > Feb 20 10:45:33 piquod openCryptokiModule[17850]: Shared memory b7cc6000 > Feb 20 10:45:33 piquod openCryptokiModule[17850]: API_Register > MgrProcIndc 17850 pid 0 > Feb 20 10:45:33 piquod openCryptokiModule[17850]: DL_Load_and_Init > dll_location /usr/lib/opencryptoki/stdll/libpkcs11_tpm.so > Feb 20 10:45:33 piquod openCryptokiModule[17850]: DL_LOAD > Feb 20 10:45:33 piquod openCryptokiModule[17850]: Empty slot at 0 > Feb 20 10:45:33 piquod TCSD[6063]: svrside.c:267 accepted socket 7 > Feb 20 10:45:33 piquod TCSD[6063]: tcsd_threads.c:193 Rx'd packet > Feb 20 10:45:33 piquod TCSD[6063]: tcsd_wrap.c:3949 Dispatching ordinal > 1 > Feb 20 10:45:33 piquod TCSD[6063]: tcsd_wrap.c:314 thread b7e37bb0 > servicing a tcs_wrap_OpenContext request > Feb 20 10:45:33 piquod TCSD[6063]: tcsd_threads.c:241 Sending 0x4E bytes > back > Feb 20 10:45:33 piquod openCryptokiModule[17850]: return from STDDLL > Init = 6 > Feb 20 10:45:33 piquod openCryptokiModule[17850]: C_GetSlotList > Feb 20 10:45:33 piquod openCryptokiModule[17850]: Pres 1 Count 0 > Feb 20 10:45:33 piquod TCSD[6063]: tcsd_threads.c:269 The TSP has closed > the socket's connection. Thread exiting. > Feb 20 10:45:33 piquod TCS[6063]: tcscm.c:43 Closing context A0C1A509 > Feb 20 10:45:33 piquod TCS[6063]: tcscm.c:55 Context A0C1A509 closed > > I can get the TPM to work by using Trousers directly. > > Any help appreciated, > > Jochen > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through log files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642 > _______________________________________________ > opencryptoki-users mailing list > ope...@li... > https://lists.sourceforge.net/lists/listinfo/opencryptoki-users |
From: Jochen S. <sch...@oc...> - 2006-02-20 10:48:13
|
Hi, I am trying to getting Opencryptoki (2.2.2-rc4) going with Trousers and the tpm_emulator. Unfortunately, I can't get passed tpm_takeownership, pkcsconf doesn't work (though it did a while ago). I am a member of the pkcs11 group. When is NVTOK.DAT supposed to be created? schneider@piquod:~$ /usr/sbin/pkcsconf -s LOG_DEBUG TSPI ../tcsd_api/clntside.c:58 Sending TSP packet to host localhost. LOG_DEBUG TSPI ../tcsd_api/clntside.c:74 Connecting to 127.0.0.1 LOG_DEBUG TSPI ../tcsd_api/tcstp.c:388 TCS_OpenContext_RPC_TP: Received TCS Context: 0xa0c1b30b ST MSG TPM_STDLL loadsave.c:477 whammy ST MSG TPM_STDLL utility.c:788 whammy LOG_ERR TPM_STDLL loadsave.c:396 ERROR: failed opening /var/lib/opencryptoki/tpm/schneider/NVTOK.DAT for read: No such file or directory ST MSG TPM_STDLL new_host.c:488 whammy ST MSG TPM_STDLL new_host.c:506 whammy C_GetSlotCount returned 0 slots. Check that your tokens are installed correctly. /var/lib/opencryptoki/pk_config_data contains: TRUE|0|Linux 2.6.14-1-686 Linux (TPM)|Linux 2.6.14-1-686|TRUE|FALSE| TRUE|0|0|1|1|NONE|/usr/lib/opencryptoki/stdll/libpkcs11_tpm.so| ST_Initialize /var/log/debug contains: Feb 20 10:45:33 piquod openCryptokiModule[17850]: Logging enabled 1 enabled Feb 20 10:45:33 piquod openCryptokiModule[17850]: C_GetFunctionList Feb 20 10:45:33 piquod openCryptokiModule[17850]: C_Initialize Feb 20 10:45:33 piquod openCryptokiModule[17850]: Anchor allocated at 804d380 Feb 20 10:45:33 piquod openCryptokiModule[17850]: Shared memory b7cc6000 Feb 20 10:45:33 piquod openCryptokiModule[17850]: API_Register MgrProcIndc 17850 pid 0 Feb 20 10:45:33 piquod openCryptokiModule[17850]: DL_Load_and_Init dll_location /usr/lib/opencryptoki/stdll/libpkcs11_tpm.so Feb 20 10:45:33 piquod openCryptokiModule[17850]: DL_LOAD Feb 20 10:45:33 piquod openCryptokiModule[17850]: Empty slot at 0 Feb 20 10:45:33 piquod TCSD[6063]: svrside.c:267 accepted socket 7 Feb 20 10:45:33 piquod TCSD[6063]: tcsd_threads.c:193 Rx'd packet Feb 20 10:45:33 piquod TCSD[6063]: tcsd_wrap.c:3949 Dispatching ordinal 1 Feb 20 10:45:33 piquod TCSD[6063]: tcsd_wrap.c:314 thread b7e37bb0 servicing a tcs_wrap_OpenContext request Feb 20 10:45:33 piquod TCSD[6063]: tcsd_threads.c:241 Sending 0x4E bytes back Feb 20 10:45:33 piquod openCryptokiModule[17850]: return from STDDLL Init = 6 Feb 20 10:45:33 piquod openCryptokiModule[17850]: C_GetSlotList Feb 20 10:45:33 piquod openCryptokiModule[17850]: Pres 1 Count 0 Feb 20 10:45:33 piquod TCSD[6063]: tcsd_threads.c:269 The TSP has closed the socket's connection. Thread exiting. Feb 20 10:45:33 piquod TCS[6063]: tcscm.c:43 Closing context A0C1A509 Feb 20 10:45:33 piquod TCS[6063]: tcscm.c:55 Context A0C1A509 closed I can get the TPM to work by using Trousers directly. Any help appreciated, Jochen |
From: Steven B. <sb...@au...> - 2006-01-27 12:49:55
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 YH Cheng wrote: | Thanks for your pointers. | | I am using old version (seems not MMAP). | | $ pwd | /usr/lib/pkcs11/methods | $ pkcsconf -c 0 -iM | PKCS#11 Info | Version 2.1 | Manufacuter: IBM AIX Software PKCS11 | Flags: 0x0 | Library Description: Meta PKCS11 LIBRARY | Library Version 0.d | | | I tried C_CloseAllSessions also to ensure all sessions are closed. | It shows global sessions = 0 also... CloseAllSessions only closes the sessions for that application.. it won't affect the value in shared memory if a prior process died... you need to find the shared memory segment (ipcs command can be used to list them) and remove it (alternativly, what happens if you reboot the system? New shared memory should be created) | | $ pkcsconf -c 0 -M | Shared Memory Data | Number of Slots: 1 | | Slot Number: 0 | Present: 1 | DLL Location: /usr/lib/pkcs11/stdll/PKCS11_4758.so | Init Function: SC_Initialize | Coorelator: 0 | Global Sessions: 0x0 | $ pkcsconf -c 0 -I | Enter the SO PIN: ******** | Enter a unique token label: testtoken | Error Initializing Token: 0xB6 | | | | | | On 1/26/06, *Steven Bade* <sb...@au... | <mailto:sb...@au...>> wrote: | | Michael Halcrow wrote: | | On Wed, Jan 25, 2006 at 09:48:46AM +0800, YH Cheng wrote: | | | |>I am using openCryptoki to access IBM crypto card 4758 for my | |>project. | | | | | | What version of openCryptoki are you running? | | | | Mike | | Recomendation.. Stop pkcsslotd.. If you look for the shared memory | region and delete it.. if you are running newer, look in the directory | with the cnfig information and find the .apimap file and delete it (i | doubt you are getting this because slotd will not start if that exists) | | Somehow the system thinks that a session remains open on the device, so | it won't let you initialize... deleting the shm (which should | automatically occur when slotd is terminated (old model). I expect that | you killed a process that was using the token, and that the garbage | collection did not clean out the state. - ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642 <http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642> _______________________________________________ opencryptoki-users mailing list ope...@li... <mailto:ope...@li...> https://lists.sourceforge.net/lists/listinfo/opencryptoki-users <https://lists.sourceforge.net/lists/listinfo/opencryptoki-users> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFD2hbpBKHgXq2RAKcRAqlvAKCQ51qFDeHbv7SJJY8tNhjurAlUtQCdFnQY 79Ohp3tkRszNtmcVlZT5gwE= =QFR9 -----END PGP SIGNATURE----- |
From: YH C. <hue...@gm...> - 2006-01-26 02:27:11
|
Thanks for your pointers. I am using old version (seems not MMAP). $ pwd /usr/lib/pkcs11/methods $ pkcsconf -c 0 -iM PKCS#11 Info Version 2.1 Manufacuter: IBM AIX Software PKCS11 Flags: 0x0 Library Description: Meta PKCS11 LIBRARY Library Version 0.d I tried C_CloseAllSessions also to ensure all sessions are closed. It shows global sessions =3D 0 also... $ pkcsconf -c 0 -M Shared Memory Data Number of Slots: 1 Slot Number: 0 Present: 1 DLL Location: /usr/lib/pkcs11/stdll/PKCS11_4758.so Init Function: SC_Initialize Coorelator: 0 Global Sessions: 0x0 $ pkcsconf -c 0 -I Enter the SO PIN: ******** Enter a unique token label: testtoken Error Initializing Token: 0xB6 On 1/26/06, Steven Bade <sb...@au...> wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Michael Halcrow wrote: > | On Wed, Jan 25, 2006 at 09:48:46AM +0800, YH Cheng wrote: > | > |>I am using openCryptoki to access IBM crypto card 4758 for my > |>project. > | > | > | What version of openCryptoki are you running? > | > | Mike > > Recomendation.. Stop pkcsslotd.. If you look for the shared memory > region and delete it.. if you are running newer, look in the directory > with the cnfig information and find the .apimap file and delete it (i > doubt you are getting this because slotd will not start if that exists) > > Somehow the system thinks that a session remains open on the device, so > it won't let you initialize... deleting the shm (which should > automatically occur when slotd is terminated (old model). I expect that > you killed a process that was using the token, and that the garbage > collection did not clean out the state. > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.2.4 (MingW32) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iD8DBQFD16kqBKHgXq2RAKcRAn3BAJ4pLGBJSXibmShU8WIBycxiWge2SQCeOGXq > szfEfu8OQjn97YZIzVthVJ8=3D > =3DpfFz > -----END PGP SIGNATURE----- > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through log > files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=3Dlnk&kid=3D103432&bid=3D230486&dat= =3D121642 > _______________________________________________ > opencryptoki-users mailing list > ope...@li... > https://lists.sourceforge.net/lists/listinfo/opencryptoki-users > |
From: Steven B. <sb...@au...> - 2006-01-25 16:37:18
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Michael Halcrow wrote: | On Wed, Jan 25, 2006 at 09:48:46AM +0800, YH Cheng wrote: | |>I am using openCryptoki to access IBM crypto card 4758 for my |>project. | | | What version of openCryptoki are you running? | | Mike Recomendation.. Stop pkcsslotd.. If you look for the shared memory region and delete it.. if you are running newer, look in the directory with the cnfig information and find the .apimap file and delete it (i doubt you are getting this because slotd will not start if that exists) Somehow the system thinks that a session remains open on the device, so it won't let you initialize... deleting the shm (which should automatically occur when slotd is terminated (old model). I expect that you killed a process that was using the token, and that the garbage collection did not clean out the state. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFD16kqBKHgXq2RAKcRAn3BAJ4pLGBJSXibmShU8WIBycxiWge2SQCeOGXq szfEfu8OQjn97YZIzVthVJ8= =pfFz -----END PGP SIGNATURE----- |
From: Michael H. <mha...@us...> - 2006-01-25 16:17:31
|
On Wed, Jan 25, 2006 at 09:48:46AM +0800, YH Cheng wrote: > I am using openCryptoki to access IBM crypto card 4758 for my > project. What version of openCryptoki are you running? Mike |
From: YH C. <hue...@gm...> - 2006-01-25 01:56:10
|
Hi all, I am using openCryptoki to access IBM crypto card 4758 for my project. And when I try to initialize the HSM via PKCS11 C_InitToken, it always fail with return code 0xB6 (CKR_SESSION_EXIST). I tried both 1) make direct API call to C_InitToken, and 2) use pkcsconf -I -c 0 (which in turns call PKCS11 API as well). But the result is just the same. I tried pkcsconf -M to show the shared memory; the global session count is 0. What's is the problem? Is it sth about user permission? The application running user is not in group "pkcs11", is it related? (I searched code and the problem seems to be in function "session_exists", which check global_session_count in shared memory. ) Would anyone please help me ? Thanks , Hue |
From: Kent Y. <shp...@gm...> - 2006-01-19 23:30:24
|
Dear users, At long last, documentation is now available for setting up the PKCS#11 interface to the TPM. Please see http://trousers.sourceforge.net/pkcs11.html. Info there includes a quick start guide, as well as a detailed overview of the design of the TPM specific functionality inside openCryptoki. Thanks, Kent -- Kent Yoder IBM LTC Security Dev. |
From: Michael H. <mha...@us...> - 2006-01-11 00:03:44
|
On Tue, Nov 15, 2005 at 01:00:07PM +0400, King G.Great wrote: > memset(&p->cmd, 0, sizeof(p->cmd)); > sscanf(buf, "%d (%15c", &p->pid, p->cmd); // comm[16] in kernel >=20 > where cmd is an unallocated char*. Yup; that looks like a problem. Kent, here is a patch to address this. Please look it over and let me know if it is ok to merge. King Great, thanks for tracking this down and providing your recommendation for fixing it. Mike --- Index: ./usr/sbin/pkcsslotd/garbage_linux.c =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D RCS file: /cvsroot/opencryptoki/opencryptoki/usr/sbin/pkcsslotd/garbage_lin= ux.c,v retrieving revision 1.1.1.1 diff -a -u -r1.1.1.1 garbage_linux.c --- ./usr/sbin/pkcsslotd/garbage_linux.c 18 Jan 2005 16:09:03 -0000 1.1.1.1 +++ ./usr/sbin/pkcsslotd/garbage_linux.c 10 Jan 2006 23:42:53 -0000 @@ -841,7 +841,7 @@ p->processor =3D 0; =20 /* now parse the two strings, tmp & buf, separately, skipping the leadin= g "(" */ - memset(&p->cmd, 0, sizeof(p->cmd)); + memset(p->cmd, 0, sizeof(p->cmd)); sscanf(buf, "%d (%15c", &p->pid, p->cmd); // comm[16] in kernel num =3D sscanf(tmp + 2, // skip space after ')' = as well "%c " Index: ./usr/sbin/pkcsslotd/garbage_linux.h =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D RCS file: /cvsroot/opencryptoki/opencryptoki/usr/sbin/pkcsslotd/garbage_lin= ux.h,v retrieving revision 1.1.1.1 diff -a -u -r1.1.1.1 garbage_linux.h --- ./usr/sbin/pkcsslotd/garbage_linux.h 18 Jan 2005 16:09:03 -0000 1.1.1.1 +++ ./usr/sbin/pkcsslotd/garbage_linux.h 10 Jan 2006 23:42:53 -0000 @@ -308,7 +308,7 @@ pid; /* process id */ =20 char - *cmd, /* command line string vector for /proc/<pid>/cmdline = */ + cmd[16], /* command line string vector for /proc/<pid>/cmdline = */ state; /* single-char code for process state [R, S, D, Z, or = T] */ =20 int |
From: King G.G. <kin...@gm...> - 2005-11-15 09:00:14
|
Hi all here is the description of problems I have: System configuration: Linux 2.6.10 uclibc, BusyBox v1.00-rc3, openCryptoki 2.1.5-6 built with i386 uclibc gcc 3.3.4 Any application which calls C_Initialize and stays in the memory for a few seconds causes pkcsslotd to 'disappear' from memory without freeing shared memory. Most likely pkcsslotd crashes and shared memory stays until next reboot since despite pkcsslotd i= s no longer running any call to C_XXX functions succeed and applications work fine. After spending days I found that even there is no need to call C_XXX functions from PKCS11_API.so. To make pkcsslotd crash it's enough to attach to shared memory and write into 2 fields: Slot_Mgr_Proc_t::inuse and Slot_Mgr_Proc_t::proc_id, and stay in memory for a few seconds: key_t tok; int shmid =3D 0; void* shmp =3D NULL; Slot_Mgr_Shr_t *shm; Slot_Mgr_Proc_t *procp; tok =3D ftok("/usr/sbin/pkcsslotd",'b'); shmid =3D shmget(tok, sizeof(Slot_Mgr_Shr_t),S_IWUSR|S_IWGRP|S_IRGRP|S_IRUS= R); printf("shmid =3D %d\n",shmid); shmp =3D shmat(shmid,NULL,0); shm =3D shmp; procp =3D shm->proc_table; procp->inuse =3D TRUE; procp->proc_id =3D getpid(); while(1); Couple of days later I found the following code in garbage_linux.c, line 846: memset(&p->cmd, 0, sizeof(p->cmd)); sscanf(buf, "%d (%15c", &p->pid, p->cmd); // comm[16] in kernel where cmd is an unallocated char*. After changing definition of cmd in proc_t structure from char* to char[16] this issue was solved. To me it seems this is the only place where cmd is used. But since pkcsslot= d is very important part I'm afraid of breaking something in it's functionality by this change. Could you please tell me is this a bug or this is how it supposed to be? What is the meaning of that memset? Is it supposed to zeroise string pointed by cmd or make cmd NULL-pointer? I= f zeroise, how many bytes? Are my changes correct or not? May they affect some other parts of openCryptoki or somehow cause malfunctioning? Or if that cmd is not used at all then may be it's better to skip it? Gev |
From: Kent Y. <shp...@gm...> - 2005-11-05 01:52:19
|
Hi Thomas, Yes, the Linux 4758 drivers and libs were recently (past 6 months) taken down from IBM's external pages. I believe you will need to contact IBM through whatever 4758 support channels are there from buying your card to see if they're still available. The openCryptoki maintainers don't have access to or control of that code. Kent On 11/4/05, Thomas Inskip <ti...@wi...> wrote: > I need to develop a product to take advantage of the IBM 4758's > capabilities by yesterday. Of course I'd rather do it on some flavor > of unix, and it looks like openCryptoki is the way to go. > > I don't know which firmware is on the card (deep or shallow). I guess > whatever comes from factory. I built openCryptoki as described in the > README and INSTALL files, but for some reason the libs for the 4758 > token do not get built. I even tried explicitly specifying > --enable-icctok when configuring to no avail. > > Could someone tell me what I am doing wrong? I am not that familiar > with the card, much less with the software needed to talk to it, yet I > have to get a bunch of stuff done in a pretty short time. > > I am using Red Hat EL ES 4, gcc 3.4.3, glibc 2.3.4 > > Thanks. > > > > ------------------------------------------------------- > SF.Net email is sponsored by: > Tame your development challenges with Apache's Geronimo App Server. Downl= oad > it for free - -and be entered to win a 42" plasma tv or your very own > Sony(tm)PSP. Click here to play: http://sourceforge.net/geronimo.php > _______________________________________________ > opencryptoki-users mailing list > ope...@li... > https://lists.sourceforge.net/lists/listinfo/opencryptoki-users > -- Kent Yoder IBM LTC Security Dev. |
From: Thomas I. <ti...@wi...> - 2005-11-04 20:02:02
|
I need to develop a product to take advantage of the IBM 4758's capabilities by yesterday. Of course I'd rather do it on some flavor of unix, and it looks like openCryptoki is the way to go. I don't know which firmware is on the card (deep or shallow). I guess whatever comes from factory. I built openCryptoki as described in the README and INSTALL files, but for some reason the libs for the 4758 token do not get built. I even tried explicitly specifying --enable-icctok when configuring to no avail. Could someone tell me what I am doing wrong? I am not that familiar with the card, much less with the software needed to talk to it, yet I have to get a bunch of stuff done in a pretty short time. I am using Red Hat EL ES 4, gcc 3.4.3, glibc 2.3.4 Thanks. |
From: Kent Y. <shp...@gm...> - 2005-09-13 04:08:54
|
Hmm, no idea. Works for me... Kent On 9/12/05, Qiyan Sun <Qiy...@su...> wrote: > Hi, >=20 > I tried to download this engine and got the following error: >=20 > Could not read file. >=20 > Go back. > /home/ftp/pub/sourceforge//s/so/sourceforge/opencryptoki/openssl-0.9.7c-P= KCS11_engine-aug152005.patch >=20 > Sep 12, 2005 14:51 >=20 > I tried to use different download sites and got the same error. Any ideas= ? >=20 > Thanks, > Qiyan >=20 >=20 >=20 > ------------------------------------------------------- > SF.Net email is Sponsored by the Better Software Conference & EXPO > September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practic= es > Agile & Plan-Driven Development * Managing Projects & Teams * Testing & Q= A > Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf > _______________________________________________ > opencryptoki-users mailing list > ope...@li... > https://lists.sourceforge.net/lists/listinfo/opencryptoki-users > |