Bug 1562277
| Summary: | RFE: add support to OpenSC for CardOS 5.3 cards | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Josip Vilicic <jvilicic> | ||||
| Component: | opensc | Assignee: | Jakub Jelen <jjelen> | ||||
| Status: | CLOSED ERRATA | QA Contact: | Asha Akkiangady <aakkiang> | ||||
| Severity: | urgent | Docs Contact: | Marc Muehlfeld <mmuehlfe> | ||||
| Priority: | urgent | ||||||
| Version: | 7.4 | CC: | ekeck, jjelen, jvilicic, kperrier, mthacker, nmavrogi, richard.ryder, rpattath, wayne.johnson | ||||
| Target Milestone: | rc | Keywords: | FutureFeature, HardwareEnablement | ||||
| Target Release: | --- | ||||||
| Hardware: | x86_64 | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | opensc-0.19.0-1.el7 | Doc Type: | Bug Fix | ||||
| Doc Text: |
CardOS 5.3 smart cards with ECDSA support work correctly in OpenSC
Previously, OpenSC did not correctly parse the ECDSA algorithm in the *TokenInfo* information provided by CardOS 5.3 smart cards. As a consequence, OpenSC did not detect these cards. The *TokenInfo* parser has been updated and now complies with the PKCS #15 specification. As a result, CardOS 5.3 smart cards with ECDSA support work correctly in OpenSC.
|
Story Points: | --- | ||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2018-10-30 11:24:51 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | |||||||
| Bug Blocks: | 1563596 | ||||||
| Attachments: |
|
||||||
|
Description
Josip Vilicic
2018-03-30 00:49:18 UTC
The ATR of the listed card is already in the card driver in RHEL7 and cardos-tool looks like recognizing the card correctly. Though the error will be probably later. Can you run the OpenSC in debug mode to gather more information what went wrong?
OPENSC_DEBUG=9 pkcs11-tool -L
I suspect these new cards have EC keys on them and it will be solved by the following change in upstream:
https://github.com/OpenSC/OpenSC/issues/1134
Can you try if the following build resolves the issues (it is latest RHEL7.5 with the above patch)?
https://brewweb.engineering.redhat.com/brew/taskinfo?taskID=15699214
Customer confirmed that the latest OpenSC package from RHEL 7.5 fixed the issue. We are quoting the customer below: --------------------------------------- After upgrading to opensc-0.16.0-8.2.20170227git777e2a3.el7.x86_64.rpm, all card versions tested work correctly (v5.3, v4.2). The person who has this card did not turn on debug as requested when running pkcs11-tool, but here is the output he sent us. Let us know if you still need the debug knowing that the above RPM fixes the issue. Available slots: Slot 0 (0x0): HP RGS Remote Smart Card Reader 00 00 (empty) Slot 1 (0x4): OMNIKEY AG CardMan 3021 00 00 token label : Siemens Corporate ID Card (V8) token manufacturer : www.atos.net/cardos token model : PKCS#15 token flags : login required, token initialized, PIN initialized hardware version : 0.0 firmware version : 0.0 serial num : 324952464D355556 Slot 2 (0x5): OMNIKEY AG CardMan 3021 00 00 token label : Extra PIN #1 (Siemens Corporate token manufacturer : www.atos.net/cardos token model : PKCS#15 token flags : login required, token initialized, PIN initialized hardware version : 0.0 firmware version : 0.0 serial num : 324952464D355556 Slot 3 (0x6): OMNIKEY AG CardMan 3021 00 00 token label : Extra PIN #0 (Siemens Corporate token manufacturer : www.atos.net/cardos token model : PKCS#15 token flags : login required, token initialized, PIN initialized hardware version : 0.0 firmware version : 0.0 serial num : 324952464D355556 Thank you for verification. Can you also clarify if the tested package was the one provided in the comment #2 or from standard RHEL7.5 update? I assume the first, but your comment does not make it clear. Hi Jakub,
1) My apologies -- the customer only installed the package you provided, described as being the same as RHEL 7.5 packages:
"Can you try if the following build resolves the issues (it is latest RHEL7.5 with the above patch)? https://brewweb.engineering.redhat.com/brew/taskinfo?taskID=15699214"
2) So no, they haven't fully updated to 7.5, which they mention here:
"FYI only: debug info originally requested is attached, but as we mentioned the test package resolved the issue.
We haven't tried If RHEL 7.5 yet, but if contains the same fix, you can close this case."
Since it does, I'll be closing that case.
3) Attaching "pkcs11-tool -L in debug mode with CardOS 5.3 inserted" debug info as a final follow-up.
Created attachment 1421438 [details]
pkcs11-tool -L in debug mode with CardOS 5.3 inserted.
Thank you for clarification. No, the RHEL7.5 does not contain this fix. It was fixed. I will make sure this will get fixed in RHEL7.6. Let me know if you will need an official hotfix earlier, or if this will be needed to be fixed in Z-stream earlier. [root@dhcp129-188 ~]# rpm -qi opensc Name : opensc Version : 0.16.0 Release : 10.20170227git777e2a3.el7 Architecture: x86_64 Install Date: Tue 31 Jul 2018 10:10:39 AM EDT Group : System Environment/Libraries Size : 3260617 License : LGPLv2+ Signature : RSA/SHA256, Tue 03 Jul 2018 04:12:33 AM EDT, Key ID 199e2f91fd431d51 Source RPM : opensc-0.16.0-10.20170227git777e2a3.el7.src.rpm Build Date : Tue 03 Jul 2018 03:59:44 AM EDT Build Host : x86-019.build.eng.bos.redhat.com Relocations : (not relocatable) Packager : Red Hat, Inc. <http://bugzilla.redhat.com/bugzilla> Vendor : Red Hat, Inc. URL : https://github.com/OpenSC/OpenSC/wiki Summary : Smart card library and applications Sanity tests look good. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:3224 |