Fedora Account System
Red Hat Associate
Red Hat Customer
engine_pkcs11 should use p11-kit-proxy.so as its PKCS#11 provider if no other module is specified. Then it will pick up the modules which are present in the system's p11-kit configuration. Also, the text format in which it is instructed which object to use is non-standard. It should accept PKCS#11 URIs. Proof-of-concept patch at http://sourceforge.net/p/opensc/mailman/message/33132605/
Cleaned up fixes at https://github.com/OpenSC/engine_pkcs11/pull/9
David, would you like to comaintain engine_pkcs11?
I'd actually like to kill it off entirely as a separate package and get the functionality merged into OpenSSL proper (cf. http://sourceforge.net/p/opensc/mailman/message/33136083/ ) But yeah, in the meantime I'm happy enough to help with the separate package. Thanks.
Note: once these patches are merged, we should also make the engine reside at %{_libdir}/openssl/engines/libpkcs11.so so that it is loaded automatically by a call to ENGINE_by_id("pkcs11").
engine_pkcs11-0.1.8-10.fc22 has been submitted as an update for Fedora 22. https://admin.fedoraproject.org/updates/engine_pkcs11-0.1.8-10.fc22
Package engine_pkcs11-0.1.8-10.fc22: * should fix your issue, * was pushed to the Fedora 22 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing engine_pkcs11-0.1.8-10.fc22' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2015-7723/engine_pkcs11-0.1.8-10.fc22 then log in and leave karma (feedback).
engine_pkcs11-0.1.8-10.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.