Bug 1710899
| Summary: | opensc failure for ssh with myeid card | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Scott Poore <spoore> | ||||
| Component: | opensc | Assignee: | Jakub Jelen <jjelen> | ||||
| Status: | CLOSED NOTABUG | QA Contact: | Scott Poore <spoore> | ||||
| Severity: | unspecified | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | 7.7 | ||||||
| Target Milestone: | rc | ||||||
| Target Release: | --- | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2019-05-17 07:10:47 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
|
Description
Scott Poore
2019-05-16 14:26:44 UTC
Created attachment 1569531 [details]
opensc debug log
FYI, I realized the key was only 1024bit. Having seen similar issues with weaker keys elsewhere, I tried regenerating my certificate with the key length set to 2048. Now it's working as expected. So, I'm not sure if we want to pursue this any further. If so, I can give access to my card and system. Otherwise, I think we can close this as NOTABUG. Given that the problem is caused by the very small key size on a card we really do not officially support, I do not think we should spend more time on this. I think this is a limitation of the RSA_PKCS mechanism (the card needs to add the PKCS#1.5 padding), but this error comes from inside of the card (the data size is fine for the PKCS#11 specification). |