Bug 1592875
| Summary: | HID OmniKey 3121 reader does not detect DoD Alternate Token | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Roshni <rpattath> | |
| Component: | pcsc-lite-ccid | Assignee: | Bob Relyea <rrelyea> | |
| Status: | CLOSED ERRATA | QA Contact: | Asha Akkiangady <aakkiang> | |
| Severity: | unspecified | Docs Contact: | ||
| Priority: | medium | |||
| Version: | 7.5-Alt | CC: | afarley, jjelen, nmavrogi, rpattath, rrelyea, sveerank | |
| Target Milestone: | rc | Keywords: | Reopened, Triaged | |
| Target Release: | --- | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| Whiteboard: | ||||
| Fixed In Version: | pcsc-lite-ccid-1.4.10-15.el7.src.rpm | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | ||
| Clone Of: | ||||
| : | 1694581 (view as bug list) | Environment: | ||
| Last Closed: | 2019-08-06 13:10:25 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 1694581 | |||
|
Description
Roshni
2018-06-19 13:53:10 UTC
If it works with Coolkey (can you check?), it will probably be some issue in OpenSC. Can you provide a debug log from the failing reader? Can you reproduce it with the pkcs11-tool -L? From the log you say there are two different readers, but they have the same identification? What is the difference between the readers? I am seeing the issue with the reader using both coolkey and opensc [root@dhcp129-28 ~]# pkcs11-tool -L Available slots: Slot 0 (0x0): OMNIKEY AG 3121 USB 00 00 C_GetTokenInfo() failed: rv = CKR_TOKEN_NOT_PRESENT [root@dhcp129-28 ~]# pkcs11-tool -L Available slots: Slot 0 (0x0): OMNIKEY AG 3121 USB 00 00 C_GetTokenInfo() failed: rv = CKR_TOKEN_NOT_PRESENT [root@dhcp129-28 ~]# pkcs11-tool -L Available slots: Slot 0 (0x0): OMNIKEY AG CardMan 3121 00 00 token label : CAC II (alt.Smith.Bernice.123456 token manufacturer : Common Access Card token model : PKCS#15 emulated token flags : login required, rng, token initialized, PIN initialized hardware version : 0.0 firmware version : 0.0 serial num : 00000000 [root@dhcp129-28 ~]# modutil -list -dbdir /etc/pki/nssdb/ Listing of PKCS #11 Modules ----------------------------------------------------------- 1. NSS Internal PKCS #11 Module uri: pkcs11:library-manufacturer=Mozilla%20Foundation;library-description=NSS%20Internal%20Crypto%20Services;library-version=3.36 slots: 2 slots attached status: loaded slot: NSS Internal Cryptographic Services token: NSS Generic Crypto Services uri: pkcs11:token=NSS%20Generic%20Crypto%20Services;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203 slot: NSS User Private Key and Certificate Services token: NSS Certificate DB uri: pkcs11:token=NSS%20Certificate%20DB;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203 2. CoolKey PKCS #11 Module library name: libcoolkeypk11.so uri: pkcs11:library-manufacturer=Mozilla%20Foundation;library-description=CoolKey%20PKCS%20%2311%20Module%20%20%20%20%20;library-version=1.0 slots: 1 slot attached status: loaded slot: OMNIKEY AG CardMan 3121 00 00 token: alt.Smith.Bernice.1234567890 uri: pkcs11:token=alt.Smith.Bernice.1234567890 ----------------------------------------------------------- [root@dhcp129-28 ~]# pkcs11-switch opensc WARNING: Performing this operation while the browser is running could cause corruption of your security databases. If the browser is currently running, you should exit browser before continuing this operation. Type 'q <enter>' to abort, or <enter> to continue: ^C [root@dhcp129-28 ~]# modutil -list -dbdir /etc/pki/nssdb/ Listing of PKCS #11 Modules ----------------------------------------------------------- 1. NSS Internal PKCS #11 Module uri: pkcs11:library-manufacturer=Mozilla%20Foundation;library-description=NSS%20Internal%20Crypto%20Services;library-version=3.36 slots: 2 slots attached status: loaded slot: NSS Internal Cryptographic Services token: NSS Generic Crypto Services uri: pkcs11:token=NSS%20Generic%20Crypto%20Services;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203 slot: NSS User Private Key and Certificate Services token: NSS Certificate DB uri: pkcs11:token=NSS%20Certificate%20DB;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203 2. CoolKey PKCS #11 Module library name: libcoolkeypk11.so uri: pkcs11:library-manufacturer=Mozilla%20Foundation;library-description=CoolKey%20PKCS%20%2311%20Module%20%20%20%20%20;library-version=1.0 slots: 1 slot attached status: loaded slot: OMNIKEY AG 3121 USB 00 00 token: uri: pkcs11: ----------------------------------------------------------- [root@dhcp129-28 ~]# pkcs11-switch opensc WARNING: Performing this operation while the browser is running could cause corruption of your security databases. If the browser is currently running, you should exit browser before continuing this operation. Type 'q <enter>' to abort, or <enter> to continue: Module "OpenSC PKCS #11 Module" added to database. ^[[AModule "CoolKey PKCS #11 Module" deleted from database. [root@dhcp129-28 ~]# modutil -list -dbdir /etc/pki/nssdb/ Listing of PKCS #11 Modules ----------------------------------------------------------- 1. NSS Internal PKCS #11 Module uri: pkcs11:library-manufacturer=Mozilla%20Foundation;library-description=NSS%20Internal%20Crypto%20Services;library-version=3.36 slots: 2 slots attached status: loaded slot: NSS Internal Cryptographic Services token: NSS Generic Crypto Services uri: pkcs11:token=NSS%20Generic%20Crypto%20Services;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203 slot: NSS User Private Key and Certificate Services token: NSS Certificate DB uri: pkcs11:token=NSS%20Certificate%20DB;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203 2. OpenSC PKCS #11 Module library name: opensc-pkcs11.so uri: pkcs11:library-manufacturer=OpenSC%20Project;library-description=OpenSC%20smartcard%20framework;library-version=0.16 slots: 1 slot attached status: loaded slot: OMNIKEY AG 3121 USB 00 00 token: uri: pkcs11: ----------------------------------------------------------- [root@dhcp129-28 ~]# pkcs11-tool -L Available slots: Slot 0 (0x0): OMNIKEY AG 3121 USB 00 00 C_GetTokenInfo() failed: rv = CKR_TOKEN_NOT_PRESENT [root@dhcp129-28 ~]# rpm -q opensc opensc-0.16.0-10.20170227git777e2a3.el7.x86_64 [root@dhcp129-28 ~]# rpm -q coolkey coolkey-1.1.0-40.el7.x86_64 This issue was not selected to be included either in Red Hat Enterprise Linux 7.7 because it is seen either as low or moderate impact to a small amount of use-cases. The next release will be in Maintenance Support 1 Phase, which means that qualified Critical and Important Security errata advisories (RHSAs) and Urgent Priority Bug Fix errata advisories (RHBAs) may be released as they become available. We will now close this issue, but if you believe that it qualifies for the Maintenance Support 1 Phase, please re-open; otherwise we recommend moving the request to Red Hat Enterprise Linux 8 if applicable. *** Bug 1678361 has been marked as a duplicate of this bug. *** Fixed in pcsc-lite-ccid-1.4.10-15.el7.src.rpm Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2019:2248 |