I've been using OpenSC 0.20 to connect from my Mac to various Linux servers at work without any problems. I recently updated to OpenSC 0.21, and I soon discovered ssh would not connect to the same Linux servers using the exact same steps (ssh-add -s /usr/lib/ssh-keychain.dylib then slogin -A servername) as with OpenSC 0.20. I re-installed 0.20 and rebooted, and ssh could connect error-free again. I went back and forth between 0.20 and 0.21 multiple times to confirm that the problem was 0.21 and not something else. It failed with 0.21 every time and worked correctly with 0.20 every time. I'm back on 0.20 until there's a fix for this.
Here's the ssh error message:
Received disconnect from SERVER_IP_ADDRESS: 2: Too many authentication failures for MYUSERID
If I google that error message, I see a lot of advice to add "IdentitiesOnly yes" to my ~/.ssh/config, but that didn't help. Maybe one of the sshd versions involved doesn't support that option or something?
Under 0.20, ssh-add -L shows two keys. Under 0.21, ssh-add -L shows 7 keys.
Maybe output from pkcs15-tool -D can help us. How many keys are really on card ?
Maybe output from pkcs15-tool -D can help us.
OK, see below. I've redacted some information that I didn't feel should be shared. I hope what's left is still helpful.
How many keys are really on card ?
I count 8 private RSA keys and 8 public RSA keys.
Using reader with a card: SCM Microsystems Inc. SCR 3310
PKCS#15 Card [PIV_II]:
Version : 0
Serial number : ...
Manufacturer ID: piv_II
Flags :
PIN [PIN]
Object Flags : [0x01], private
Auth ID : 02
ID : 01
Flags : [0x32], local, initialized, needs-padding
Length : min_len:4, max_len:8, stored_len:8
Pad char : 0xFF
Reference : ... (0x...)
Type : ascii-numeric
PIN [PIV PUK]
Object Flags : [0x01], private
ID : 02
Flags : [0xF2], local, initialized, needs-padding, unblockingPin, soPin
Length : min_len:4, max_len:8, stored_len:8
Pad char : 0xFF
Reference : ... (0x...)
Type : ascii-numeric
Private RSA Key [PIV AUTH key]
Object Flags : [0x01], private
Usage : [0x2E], decrypt, sign, signRecover, unwrap
Access Flags : [0x1D], sensitive, alwaysSensitive, neverExtract, local
ModLength : 2048
Key ref : 154 (0x9A)
Native : yes
Auth ID : 01
ID : 01
MD:guid : 0x'...'
Private RSA Key [SIGN key]
Object Flags : [0x01], private
Usage : [0x20E], decrypt, sign, signRecover, nonRepudiation
Access Flags : [0x1D], sensitive, alwaysSensitive, neverExtract, local
ModLength : 2048
Key ref : 156 (0x9C)
Native : yes
Auth ID : 01
ID : 02
MD:guid : 0x'...'
Private RSA Key [KEY MAN key]
Object Flags : [0x01], private
Usage : [0x22], decrypt, unwrap
Access Flags : [0x1D], sensitive, alwaysSensitive, neverExtract, local
ModLength : 2048
Key ref : 157 (0x9D)
Native : yes
Auth ID : 01
ID : 03
MD:guid : 0x'...'
Private RSA Key [CARD AUTH key]
Object Flags : [0x00]
Usage : [0x0C], sign, signRecover
Access Flags : [0x1D], sensitive, alwaysSensitive, neverExtract, local
ModLength : 2048
Key ref : 158 (0x9E)
Native : yes
ID : 04
MD:guid : 0x'...'
Private RSA Key [Retired KEY MAN 1]
Object Flags : [0x01], private
Usage : [0x22], decrypt, unwrap
Access Flags : [0x1D], sensitive, alwaysSensitive, neverExtract, local
ModLength : 2048
Key ref : 130 (0x82)
Native : yes
Auth ID : 01
ID : 05
MD:guid : 0x'...'
Private RSA Key [Retired KEY MAN 2]
Object Flags : [0x01], private
Usage : [0x22], decrypt, unwrap
Access Flags : [0x1D], sensitive, alwaysSensitive, neverExtract, local
ModLength : 2048
Key ref : 131 (0x83)
Native : yes
Auth ID : 01
ID : 06
MD:guid : 0x'...'
Private RSA Key [Retired KEY MAN 3]
Object Flags : [0x01], private
Usage : [0x22], decrypt, unwrap
Access Flags : [0x1D], sensitive, alwaysSensitive, neverExtract, local
ModLength : 2048
Key ref : 132 (0x84)
Native : yes
Auth ID : 01
ID : 07
MD:guid : 0x'...'
Private RSA Key [Retired KEY MAN 4]
Object Flags : [0x01], private
Usage : [0x22], decrypt, unwrap
Access Flags : [0x1D], sensitive, alwaysSensitive, neverExtract, local
ModLength : 2048
Key ref : 133 (0x85)
Native : yes
Auth ID : 01
ID : 08
MD:guid : 0x'...'
Public RSA Key [PIV AUTH pubkey]
Object Flags : [0x00]
Usage : [0xD1], encrypt, wrap, verify, verifyRecover
Access Flags : [0x02], extract
ModLength : 2048
Key ref : 154 (0x9A)
Native : yes
ID : 01
DirectValue : <absent>
Public RSA Key [SIGN pubkey]
Object Flags : [0x00]
Usage : [0x2C1], encrypt, verify, verifyRecover, nonRepudiation
Access Flags : [0x02], extract
ModLength : 2048
Key ref : 156 (0x9C)
Native : yes
ID : 02
DirectValue : <absent>
Public RSA Key [KEY MAN pubkey]
Object Flags : [0x00]
Usage : [0x11], encrypt, wrap
Access Flags : [0x02], extract
ModLength : 2048
Key ref : 157 (0x9D)
Native : yes
ID : 03
DirectValue : <absent>
Public RSA Key [CARD AUTH pubkey]
Object Flags : [0x00]
Usage : [0xC0], verify, verifyRecover
Access Flags : [0x02], extract
ModLength : 2048
Key ref : 158 (0x9E)
Native : yes
ID : 04
DirectValue : <absent>
Public RSA Key [Retired KEY MAN 1]
Object Flags : [0x00]
Usage : [0x11], encrypt, wrap
Access Flags : [0x02], extract
ModLength : 2048
Key ref : 130 (0x82)
Native : yes
ID : 05
DirectValue : <absent>
Public RSA Key [Retired KEY MAN 2]
Object Flags : [0x00]
Usage : [0x11], encrypt, wrap
Access Flags : [0x02], extract
ModLength : 2048
Key ref : 131 (0x83)
Native : yes
ID : 06
DirectValue : <absent>
Public RSA Key [Retired KEY MAN 3]
Object Flags : [0x00]
Usage : [0x11], encrypt, wrap
Access Flags : [0x02], extract
ModLength : 2048
Key ref : 132 (0x84)
Native : yes
ID : 07
DirectValue : <absent>
Public RSA Key [Retired KEY MAN 4]
Object Flags : [0x00]
Usage : [0x11], encrypt, wrap
Access Flags : [0x02], extract
ModLength : 2048
Key ref : 133 (0x85)
Native : yes
ID : 08
DirectValue : <absent>
X.509 Certificate [Certificate for PIV Authentication]
Object Flags : [0x00]
Authority : no
Path :
ID : 01
Encoded serial : ...
X.509 Certificate [Certificate for Digital Signature]
Object Flags : [0x00]
Authority : no
Path :
ID : 02
Encoded serial : ...
X.509 Certificate [Certificate for Key Management]
Object Flags : [0x00]
Authority : no
Path :
ID : 03
Encoded serial : ...
X.509 Certificate [Certificate for Card Authentication]
Object Flags : [0x00]
Authority : no
Path :
ID : 04
Encoded serial : ...
X.509 Certificate [Retired Certificate for Key Management 1]
Object Flags : [0x00]
Authority : no
Path :
ID : 05
Encoded serial : ...
X.509 Certificate [Retired Certificate for Key Management 2]
Object Flags : [0x00]
Authority : no
Path :
ID : 06
Encoded serial : ...
X.509 Certificate [Retired Certificate for Key Management 3]
Object Flags : [0x00]
Authority : no
Path :
ID : 07
Encoded serial : ...
X.509 Certificate [Retired Certificate for Key Management 4]
Object Flags : [0x00]
Authority : no
Path :
ID : 08
Encoded serial : ...
Data object 'Card Capability Container'
applicationName: Card Capability Container
applicationOID: 2.xxx.yyy....
Path: dxxx
Data (70 bytes): ...
Data object 'Card Holder Unique Identifier'
applicationName: Card Holder Unique Identifier
applicationOID: 2.xxx.yyy....
Path: 3xxx
Data (2xxx bytes): ...
Data object 'Unsigned Card Holder Unique Identifier'
applicationName: Unsigned Card Holder Unique Identifier
applicationOID: 2.16.840.1.101.3.7.2.48.2
Path: 3xxx
Data object read failed: File not found
Data object 'X.509 Certificate for PIV Authentication'
applicationName: X.509 Certificate for PIV Authentication
applicationOID: 2.xxx.yyy....
Path: 0xxx
Data (1xxx bytes): ...
Data object 'Cardholder Fingerprints'
applicationName: Cardholder Fingerprints
applicationOID: 2.xxx.yyy....
Path: 6xxx
Auth ID: 01
Data object 'Printed Information'
applicationName: Printed Information
applicationOID: 2.16.840.1.101.3.7.2.48.1
Path: 3xxx
Auth ID: 01
Data object 'Cardholder Facial Image'
applicationName: Cardholder Facial Image
applicationOID: 2.xxx.yyy....
Path: 6xxx
Auth ID: 01
Data object 'X.509 Certificate for Digital Signature'
applicationName: X.509 Certificate for Digital Signature
applicationOID: 2.16.840.1.101.3.7.2.1.0
Path: 0xxx
Data (1xxx bytes): ...
Data object 'X.509 Certificate for Key Management'
applicationName: X.509 Certificate for Key Management
applicationOID: 2.xxx.yyy....
Path: 0xxx
Data (1xxx bytes): ...
Data object 'X.509 Certificate for Card Authentication'
applicationName: X.509 Certificate for Card Authentication
applicationOID: 2.xxx.yyy....
Path: 0xxx
Data (1xxx bytes): ...
Data object 'Security Object'
applicationName: Security Object
applicationOID: 2.xxx.yyy....
Path: 9xxx
Data (xxx bytes): ...
Data object 'Discovery Object'
applicationName: Discovery Object
applicationOID: 2.xxx.yyy....
Path: 6xxx
Data (xx bytes): ...
Data object 'Key History Object'
applicationName: Key History Object
applicationOID: 2.xxx.yyy....
Path: 6xxx
Data (xx bytes): ...
Data object 'Cardholder Iris Image'
applicationName: Cardholder Iris Image
applicationOID: 2.xxx.yyy....
Path: 1xxx
Data object read failed: File not found
Data object 'Retired X.509 Certificate for Key Management 1'
applicationName: Retired X.509 Certificate for Key Management 1
applicationOID: 2.xxx.yyy....
Path: 1xxx
Data (1xxx bytes): ...
Data object 'Retired X.509 Certificate for Key Management 2'
applicationName: Retired X.509 Certificate for Key Management 2
applicationOID: 2.xxx.yyy....
Path: 1xxx
Data (1xxx bytes): ...
I don't know why opensc 0.20 and 0.21 shows a different number of keys. Maybe @dengert can explain this...
But, seems there is incomplete SSH configuration on your client side. Client tries to authenticate with 1st 3 or 5 keys loaded into ssh-agent (depends on server configuration) without success and server then close connection with too many auth errors. You should explicitly choose the correct key and not test key by key.
.ssh/test at client side (same public key as in .ssh/authorized_keys on server side).ssh -o IdentitiesOnly=Yes -v -i .ssh/test SERVERyou client should offer only one key (corresponding to public key) to your server, example from correct setup:
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: publickey
debug1: Offering public key: /home/xxxxx/.ssh/test RSA SHA256:K6Onw1GvaevV6lhKcvj6Q3v22XVZcI3yGOp+jLnab2g explicit agent
debug1: Server accepts key: /home/xxxxx/.ssh/test RSA SHA256:K6Onw1GvaevV6lhKcvj6Q3v22XVZcI3yGOp+jLnab2g explicit agent
debug1: Authentication succeeded (publickey).
If this works, you can create a specific config for your serer in .ssh/config ... or example:
Host SERVER
IdentitiesOnly yes
IdentityFile ~/.ssh/test
Is this an official PIV issued by gov running on MacOS?
Card has some objects that are signed that are normally only on gov issued cards and you are using
/usr/lib/ssh-keychain.dylib
@mouse07410 do you have any ideas on this?
/usr/lib/ssh-keychain.dylib is not part of OpenSC, so it finds the OpenSC pkcs11 module somehow.
It might be finding the wrong version. ldd /usr/lib/ssh-keychain.dylib or strings /usr/lib/ssh-keychain.dylib | grep pkcs11 (Or MacOS equivalent) might help.
Having 8 keys might hit some SSH limit. 4 of those are retired encryption keys, which are not used for authentication.
Since ssh-add -L shows only 2 keys in 0.20.0 which would probably be the AUTH and SIGN keys, but 7 in 0.21.0 indicates that they may be a problem with selection and all the keys are selected.
Something that might help is to run using OpenSC SPY to see the PKCS11 calls.
https://github.com/OpenSC/OpenSC/wiki/Using-OpenSC has example of how to do this.
Googling for /usr/lib/ssh-keychain.dylib has some interesting info, From NASA, GSA and idmanagement.gov, and man page.
They use a combination of opensc-pkcs11 and ssh-keychain.
on my Ubuntu 20.04, there is a packaged for keychain, which leads to original source https://www.funtoo.org/Keychain
Which leads to https://github.com/funtoo/keychain Don't know if this is also used on MacOS, or has been modified for MacOS.
It could also be that in 0.20.0 the OpenSC pkcs11 module is being called, but for some reason in 0.21.0 it is not, and you are using the build in MacOS PIV drivers. One way to detect this is to to turn on OpenSC debugging in the opensc.conf file See: https://github.com/OpenSC/OpenSC/wiki/Using-OpenSC and try the slogin -A servername
Both implementations (OpenSC / PIV driver in MacOS) should read the same number of keys on PIV card .. or not ?
BTW, I have 10 keys on my card (MyEID/OsEID), on linux, and I have same problem as described - "Too many authentication failures" - no matter if I use ssh-agent or if I use ssh -I /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so HOST. HOST reject my attempts after 5 keys. This is not related to OpenSC. In this case (lot of keys on card) IdentityFile is necessary for ssh.
They may be different. PIV card can have retired encryption keys, which are indicated by the History Object. As certificates and keys are updated, the issuing agency's CMS system will save the retired keys so they can be used to decrypt previously encrypted data. OpenSC will list these, MacOS may not. I don't have a Mac.
"Too many authentication failures" comes from a call to auth_maxtries_exceeded in ./openssh-portable/auth2.c
options->max_authtries = DEFAULT_AUTH_FAIL_MAX; where #define DEFAULT_AUTH_FAIL_MAX 6
This is on the server side, and not likely to be changed. Sounds like IdentityFile on client is better way to avoid this.
It is still not clear why 0.20.0 and 0.21.0 differ A pkcs11 SPY trace could be of help identify if the problem is in OpenSC or not. Maybe the order of the retrieved public keys has changed, or some PKCS11 attribute is not being filtered. Or the /usr/lib/ssh-keychain.dylib is listing them by hash value which could change the order or what is save in the keychain data. So it works if the identity is found in the first 6 attempts.
SSH log of what is sent by client would also help.
Also looking at what is saved in user keychain or profile could give a clue.
https://awesomeopensource.com/project/FiloSottile/yubikey-agent says:
"The ssh-agent that ships with macOS (which is pretty cool, as it starts on demand and is preconfigured in the environment) also has restrictions on where the .so modules can be loaded from. It can see through symlinks, so a Homebrew-installed /usr/local/lib/libykcs11.dylib won't work, while a hard copy at /usr/local/lib/libykcs11.copy.dylib will.
/usr/lib/ssh-keychain.dylib works out of the box, but only with RSA keys. Key generation is undocumented."
The above is talking about pkcs11 modules.
So could the problem be how 0.21.0 is built for the Mac.
@frankmorgner
@popovec commented:
But, seems there is incomplete SSH configuration on your client side. Client tries to authenticate with 1st 3 or 5 keys loaded into ssh-agent (depends on server configuration) without success and server then close connection with too many auth errors. You should explicitly choose the correct key and not test key by key.
I disagree in principle that I should have to do that when I don't have to do that with OpenSC 0.20.
- save your public key into
.ssh/testat client side (same public key as in .ssh/authorized_keys on server side).
I don't believe I'm permitted to extract keys from my card and store them off-card. I believe that's against regulations. I could be mistaken about that.
If I were permitted to do that, how would I go about doing that? Can you point me to instructions?
- try to connect
ssh -o IdentitiesOnly=Yes -v -i .ssh/test SERVER
In my original post, I already stated that I tried using the ssh client option IdentitiesOnly=Yes, and it didn't work for me. Also, a stackoverflow.com article on this topic says that explicitly specifying the key with -i didn't work, at least for some people. There are multiple reports there that at least some versions of ssh apparently try all the keys that are available regardless of -i or specifying IdentityFile in ~/.ssh/config. Maybe that's a bug that was fixed in later ssh versions though, I don't know.
@dengert asked:
Is this an official PIV issued by gov running on MacOS?
Does it really matter? Anyway, my workplace is listed in my GitHub profile. The answer is yes.
Since ssh-add -L shows only 2 keys in 0.20.0 which would probably be the AUTH and SIGN keys, but 7 in 0.21.0 indicates that they may be a problem with selection and all the keys are selected.
YES. THIS.
Also, any theory as to why there are 7 keys with 0.21, but the card has 8 keys?
I'm jumping in late, but my experience on MacOS has been negative.
SSH Agent would indeed start when I load the PKCS#11 library, and would run ok for a few hours. Then, for reasonsi don't know, it would stop accepting requests. Symptoms would be like those of the original poster.
My remedy is to pkill ssh-agent, and restart it manually. Rinse and repeat in a few hours. Now I only start ssh-agent if I really need it - way too inconvenient to deal with these random frequent failures.
The instructions for using OpenSC SPY at https://github.com/OpenSC/OpenSC/wiki/Using-OpenSC do not work on macOS. /usr/lib/pkcs11/opensc-pkcs11.so doesn't exist. Can anyone provide Mac-specific guidance? Thanks.
@mouse07410 commented:
SSH Agent would indeed start when I load the PKCS#11 library, and would run ok for a few hours. Then, for reasonsi don't know, it would stop accepting requests. Symptoms would be like those of the original poster.
My remedy is to
pkill ssh-agent, and restart it manually. Rinse and repeat in a few hours. Now I only start ssh-agent if I really need it - way too inconvenient to deal with these random frequent failures.
This has not been my experience with OpenSC 0.20. I've never had to manually restart ssh-agent. Anyway, that's not really relevant to this issue, I feel.
@popovec commented:
BTW, I have 10 keys on my card (MyEID/OsEID), on linux, and I have same problem as described - "Too many authentication failures" - no matter if I use
ssh-agentor if I usessh -I /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so HOST. HOST reject my attempts after 5 keys. This is not related to OpenSC. In this case (lot of keys on card) _IdentityFile_ is necessary for ssh.
But it wasn't necessary for me with OpenSC 0.20. Only a couple of keys on my card are useful for ssh, and OpenSC 0.20 knew to ignore the keys that aren't useful to ssh. Version 0.21 does not do that. It exposes almost all of the keys to ssh-agent.
Now, was that change intentional or accidental? If it was accidental, I would call that a regression, one I hope the OpenSC team would be open to fixing. If it was intentional, then I'll look into possible workarounds or just stick with OpenSC 0.20 indefinitely. Probably the latter, but I'd like to stay current for security reasons.
Based on @popovec recreating the problem, it does not look like a PIV only problem. So a SPY is even more important to see what is going on. "ignore the keys that aren't useful to ssh" would be by PKCS11 requesting only key that have specific attributes.
The spy routine could replace the /usr/lib/ssh-keychain.dylib something like:
export PKCS11SPY=/usr/lib/ssh-keychain.dylib
export PKCS11SPY_OUTPUT=logfile eval ssh-agent
ssh-add -L /usr/lib/pkcs11-spy.so (need to set this path. look for pkcs11-spy.dylib too)
I don't have a Mac to tell you where the OpenSC pkcs11 module is installed, or how /usr/lib/ssh-keychain.dylib finds it.
But you said you installed 0.21.0. So it has to be there somewhere.
Why there are 7 keys with 0.21.0, but the card has 8 keys? I would suspect that the CARD AUTH key is not counted, because it does not require the PIN. It can be used to show possession of the card to say a physical door reader.
0.20.0 should have also shown 8 public keys. The question is why it only showed 2 keys.
@dengert commented:
The spy routine could replace the
/usr/lib/ssh-keychain.dylibsomething like:export PKCS11SPY=/usr/lib/ssh-keychain.dylib
export PKCS11SPY_OUTPUT=logfileeval ssh-agent
ssh-add -L /usr/lib/pkcs11-spy.so (need to set this path. look for pkcs11-spy.dylib too)I don't have a Mac to tell you where the OpenSC pkcs11 module is installed, or how
/usr/lib/ssh-keychain.dylibfinds it.
But you said you installed 0.21.0. So it has to be there somewhere.
I also said I'm back on 0.20. find /usr/lib/ -name "*spy*" -print on my Mac finds nothing. Can anyone help?
Never mind. I found it in /Library/OpenSC/lib/.
But it didn't work.
> ssh-add -s /Library/OpenSC/lib/pkcs11-spy.so
Enter passphrase for PKCS#11:
Could not add card "/Library/OpenSC/lib/pkcs11-spy.so": agent refused operation
Has anyone successfully used this spy thing on a Mac?
Ah, ha! I found this comment in another issue here:
macOS 10.12.4 includes a new version of OpenSSH...the behavior of
ssh-agenthas changed such that you need to "whitelist" the location of pkcs11 libraries. See the manual page forssh-agentand the-Poption. It's not clear to me that there's anything for the OpenSC project to do about this.
_Originally posted by @bmah888 in https://github.com/OpenSC/OpenSC/issues/1007#issuecomment-289847808_
So ssh-agent -P '/usr/lib/*,/Library/OpenSC/lib/*' worked, and I was able to spy successfully!
Here's the log using OpenSC 0.20:
opensc.0.20.log
*************** OpenSC PKCS#11 spy *****************
Loaded: "/usr/lib/ssh-keychain.dylib"
0: C_GetFunctionList
2020-11-30 18:33:07.989
Returned: 0 CKR_OK
1: C_Initialize
2020-11-30 18:33:07.990
[in] pInitArgs = 0x0
Returned: 0 CKR_OK
2: C_GetInfo
2020-11-30 18:33:08.641
[out] pInfo:
cryptokiVersion: 2.20
manufacturerID: 'Apple, Inc. '
flags: 0
libraryDescription: 'Keychain emulation PKCS#11 API '
libraryVersion: 0.0
Returned: 0 CKR_OK
3: C_GetSlotList
2020-11-30 18:33:08.641
[in] tokenPresent = 0x1
[out] pSlotList:
Count is 2
[out] *pulCount = 0x2
Returned: 0 CKR_OK
4: C_GetSlotList
2020-11-30 18:33:08.641
[in] tokenPresent = 0x1
[out] pSlotList:
Slot 0
Slot 1
[out] *pulCount = 0x2
Returned: 0 CKR_OK
5: C_GetTokenInfo
2020-11-30 18:33:08.641
[in] slotID = 0x0
[out] pInfo:
label: 'Key For PIV Authentication (Edwa'
manufacturerID: 'Apple, Inc. '
model: 'Keychain '
serialNumber: '000000 '
ulMaxSessionCount: 0
ulSessionCount: 0
ulMaxRwSessionCount: 0
ulRwSessionCount: 0
ulMaxPinLen: 0
ulMinPinLen: 0
ulTotalPublicMemory: 0
ulFreePublicMemory: 0
ulTotalPrivateMemory: 0
ulFreePrivateMemory: 0
hardwareVersion: 0.0
firmwareVersion: 0.0
time: ' '
flags: 404
CKF_LOGIN_REQUIRED
CKF_TOKEN_INITIALIZED
Returned: 0 CKR_OK
6: C_OpenSession
2020-11-30 18:33:08.641
[in] slotID = 0x0
[in] flags = 0x6
pApplication=0x0
Notify=0x0
[out] *phSession = 0x1
Returned: 0 CKR_OK
7: C_Login
2020-11-30 18:33:08.641
[in] hSession = 0x1
[in] userType = CKU_USER
[in] pPin[ulPinLen] 00007f9e7d402780 / 8
00000000 [redacted]
Returned: 0 CKR_OK
8: C_FindObjectsInit
2020-11-30 18:33:08.717
[in] hSession = 0x1
[in] pTemplate[1]:
CKA_CLASS CKO_PUBLIC_KEY
Returned: 0 CKR_OK
9: C_FindObjects
2020-11-30 18:33:08.717
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x0 matches
Returned: 0 CKR_OK
10: C_GetAttributeValue
2020-11-30 18:33:08.717
[in] hSession = 0x1
[in] hObject = 0x0
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_MODULUS 0000000000000000 / 0
CKA_PUBLIC_EXPONENT 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_MODULUS 0000000000000000 / 257
CKA_PUBLIC_EXPONENT 0000000000000000 / 3
Returned: 0 CKR_OK
11: C_GetAttributeValue
2020-11-30 18:33:08.717
[in] hSession = 0x1
[in] hObject = 0x0
[in] pTemplate[3]:
CKA_ID 00007f9e7d6334b0 / 270
CKA_MODULUS 00007f9e7d61fdc0 / 257
CKA_PUBLIC_EXPONENT 00007f9e7d6301a0 / 3
[out] pTemplate[3]:
CKA_ID 00007f9e7d6334b0 / 270
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_MODULUS 00007f9e7d61fdc0 / 257
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_PUBLIC_EXPONENT 00007f9e7d6301a0 / 3
00000000 [redacted]
Returned: 0 CKR_OK
12: C_FindObjects
2020-11-30 18:33:08.717
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x0
Returned: 0 CKR_OK
13: C_FindObjectsFinal
2020-11-30 18:33:08.717
[in] hSession = 0x1
Returned: 0 CKR_OK
14: C_FindObjectsInit
2020-11-30 18:33:08.717
[in] hSession = 0x1
[in] pTemplate[1]:
CKA_CLASS CKO_CERTIFICATE
Returned: 0 CKR_OK
15: C_FindObjects
2020-11-30 18:33:08.717
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x0 matches
Returned: 0 CKR_OK
16: C_GetAttributeValue
2020-11-30 18:33:08.717
[in] hSession = 0x1
[in] hObject = 0x0
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
Returned: 0 CKR_OK
17: C_FindObjects
2020-11-30 18:33:08.717
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x0
Returned: 0 CKR_OK
18: C_FindObjectsFinal
2020-11-30 18:33:08.717
[in] hSession = 0x1
Returned: 0 CKR_OK
19: C_GetTokenInfo
2020-11-30 18:33:08.717
[in] slotID = 0x1
[out] pInfo:
label: 'Key For Digital Signature (Edwar'
manufacturerID: 'Apple, Inc. '
model: 'Keychain '
serialNumber: '000000 '
ulMaxSessionCount: 0
ulSessionCount: 0
ulMaxRwSessionCount: 0
ulRwSessionCount: 0
ulMaxPinLen: 0
ulMinPinLen: 0
ulTotalPublicMemory: 0
ulFreePublicMemory: 0
ulTotalPrivateMemory: 0
ulFreePrivateMemory: 0
hardwareVersion: 0.0
firmwareVersion: 0.0
time: ' '
flags: 404
CKF_LOGIN_REQUIRED
CKF_TOKEN_INITIALIZED
Returned: 0 CKR_OK
20: C_OpenSession
2020-11-30 18:33:08.718
[in] slotID = 0x1
[in] flags = 0x6
pApplication=0x0
Notify=0x0
[out] *phSession = 0x2
Returned: 0 CKR_OK
21: C_Login
2020-11-30 18:33:08.718
[in] hSession = 0x2
[in] userType = CKU_USER
[in] pPin[ulPinLen] 00007f9e7d402780 / 8
00000000 [redacted]
Returned: 0 CKR_OK
22: C_FindObjectsInit
2020-11-30 18:33:08.792
[in] hSession = 0x2
[in] pTemplate[1]:
CKA_CLASS CKO_PUBLIC_KEY
Returned: 0 CKR_OK
23: C_FindObjects
2020-11-30 18:33:08.792
[in] hSession = 0x2
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x0 matches
Returned: 0 CKR_OK
24: C_GetAttributeValue
2020-11-30 18:33:08.792
[in] hSession = 0x2
[in] hObject = 0x0
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_MODULUS 0000000000000000 / 0
CKA_PUBLIC_EXPONENT 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_MODULUS 0000000000000000 / 257
CKA_PUBLIC_EXPONENT 0000000000000000 / 3
Returned: 0 CKR_OK
25: C_GetAttributeValue
2020-11-30 18:33:08.792
[in] hSession = 0x2
[in] hObject = 0x0
[in] pTemplate[3]:
CKA_ID 00007f9e7d431580 / 270
CKA_MODULUS 00007f9e7d41d1c0 / 257
CKA_PUBLIC_EXPONENT 00007f9e7d41d2d0 / 3
[out] pTemplate[3]:
CKA_ID 00007f9e7d431580 / 270
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_MODULUS 00007f9e7d41d1c0 / 257
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_PUBLIC_EXPONENT 00007f9e7d41d2d0 / 3
00000000 [redacted]
Returned: 0 CKR_OK
26: C_FindObjects
2020-11-30 18:33:08.792
[in] hSession = 0x2
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x0
Returned: 0 CKR_OK
27: C_FindObjectsFinal
2020-11-30 18:33:08.792
[in] hSession = 0x2
Returned: 0 CKR_OK
28: C_FindObjectsInit
2020-11-30 18:33:08.792
[in] hSession = 0x2
[in] pTemplate[1]:
CKA_CLASS CKO_CERTIFICATE
Returned: 0 CKR_OK
29: C_FindObjects
2020-11-30 18:33:08.792
[in] hSession = 0x2
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x0 matches
Returned: 0 CKR_OK
30: C_GetAttributeValue
2020-11-30 18:33:08.792
[in] hSession = 0x2
[in] hObject = 0x0
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
Returned: 0 CKR_OK
31: C_FindObjects
2020-11-30 18:33:08.792
[in] hSession = 0x2
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x0
Returned: 0 CKR_OK
32: C_FindObjectsFinal
2020-11-30 18:33:08.792
[in] hSession = 0x2
Returned: 0 CKR_OK
I'll have to re-install 0.21 and reboot to test with OpenSC 0.21. I'm busy working right now, so I can't do that at the moment, but I'll do it in the next day or so. Thanks!
Good to hear you find something to get 0.20.0 working with SPY. Looks like the first pubkey/certificate was the one /usr/lib/ssh-keychain.dylib was looking for. I am looking forward to see what 0.21.0 does.
Newer Yubikeys have attestation cert. opensc-pkcs11.dylib doesn't see it (I didn't bother to figure why), but libykcs11.dylib does. That explains why it shows one more cert that were provisioned by user.
- save your public key into
.ssh/testat client side (same public key as in .ssh/authorized_keys on server side).I don't believe I'm permitted to extract keys from my card and store them off-card. I believe that's against regulations. I could be mistaken about that.
Nobody asks You for sensitive information (private key).. we need public key (and this public key is already extracted and saved on your server in your home directory in file .ssh/authorized_keys). We need same part of key - public part - at client side, to allow selecting proper private key from your card.
If I were permitted to do that, how would I go about doing that? Can you point me to instructions?
- try to connect
ssh -o IdentitiesOnly=Yes -v -i .ssh/test SERVER
IdentitiesOnly work only if propper identity file is selected by -i switch .. or, You can use CertificateFile..
more info man 5 ssh_config
You can confirm my claims if you let ssh go with the -vvv flag, you will observe the ssh client try to use all available keys until the remote server disconnects it.
In my original post, I already stated that I tried using the ssh client option
IdentitiesOnly=Yes, and it didn't work for me. Also, a stackoverflow.com article on this topic says that explicitly specifying the key with-ididn't work, at least for some people. There are multiple reports there that at least some versions of ssh apparently try all the keys that are available regardless of-ior specifyingIdentityFilein~/.ssh/config. Maybe that's a bug that was fixed in later ssh versions though, I don't know.
Yes, there is problem with ssh and pkcs11 keys if ssh-agent is not available. In this case I need to instruct ssh to use pkcs11 module (for example ssh -i /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so SERVER As You can see, I already use same switch -i for pkcs module and this file (all keys on card) is then my IdentityFile. There is no way to select only one key from pkcs11 interface. All keys are selected and ssh try to use all of them. But this is a problem with ssh and not OpenSC - maybe ssh with PKCS11Provider will have the option to select a key in future versions of ssh. And there is another bug in ssh-agent, if I have small key on card (for example RSA key with 512 bit modulus), ssh-agent fail to load any keys from card, even worse, ssh-agent quits.
@mouse07410 commented:
Newer Yubikeys have attestation cert.
opensc-pkcs11.dylibdoesn't see it (I didn't bother to figure why), butlibykcs11.dylibdoes. That explains why it shows one more cert that were provisioned by user.
Huh?
@dengert
Based on @popovec recreating the problem, it does not look like a PIV only problem. So a SPY is even more important to see what is going on. "ignore the keys that aren't useful to ssh" would be by PKCS11 requesting only key that have specific attributes.
I have 10 keys on card, and I need to access 10 different servers. All of keys are suitable to do auth ... but PKCS11 interface does not have the ability to know which key to be used to which server. pkcs11 offers the ability to read a public part or certificate of a key - that is quite sufficient.
As a user, I need to be able to announce which key should be used with which server - and this is solved in ssh by IdentityFile. Not perfect .. but it's solved.
This issue is solvable by proposed procedure - use of correct IdentityFile.
Why old opensc 0.20 and 0.21 shows different keys on card is completely another issue.
@popovec commented:
Why old opensc 0.20 and 0.21 shows different keys on card is completely another issue.
I guess this is where we differ. I feel that is exactly what this issue is about. I’d like to concentrate on that aspect. I appreciate your replies and your suggested workaround, however.
@esabol
I understand your problem and I understand that after changing from opensc 0.20 to 0.21, you expect that the functionality of your card with same setup will not change.
However, you should also accept that you currently have more keys on the card, and it doesn't matter how they got there and which ones are valid and what they are used for. It is your problem to choose the right key for a specific authentication operation
(at least as far as ssh is concerned, for example, WEB browser uses certificates from card to select proper key).
If in the future you will have even more keys on card, and it doesn't matter if pkcs11 from opensc 0.20 or 0.21 or another proprietary pkcs11 modulle shows it, you will be faced with the same problem.
And here I am suggesting that we have two different problems here, one concerning the selection of a key, and he is solvable. A completely different problem is why different pkcs11 modules show different numbers of keys (on PIV card).
Thanks, @popovec , for the clear answer. SSH doesn't allow the server to give a hint about the specific public key (RFC 4252, section 7, hence you need to predefine the key to be used at the client side (i.e. IdentityFile). In TLS, by the way, the server submits the suitable PKIs for client authentication, which allows the browser to select the correct key from the card.
I'm not too curious about why we are seeing more keys now. Most likely this is a missing feature in 0.20.0, which - by accident - made your ssh authentication work as expected. But if you can additionally submit a log of 0.21.0, then @dengert may want to double check.
@frankmorgner commented:
Most likely this is a missing feature in 0.20.0, which - by accident - made your ssh authentication work as expected. But if you can additionally submit a log of 0.21.0, then @dengert may want to double check.
I will. Thanks in advance for your time and any assistance you give, @dengert.
@esabol what version of MacOS are you running?
I agree there is more then one problem, the ssh limit of 6 and the 512 bit certificates and why 0.20.0 is different from 0.21.0
Note that the Spy trace from https://github.com/OpenSC/OpenSC/issues/2167#issuecomment-736122495 is:
ssh-> SPY -> /usr/lib/ssh-keychain.dylib
/usr/lib/ssh-keychain.dylib reports its version as:
2: C_GetInfo
2020-11-30 18:33:08.641
[out] pInfo:
cryptokiVersion: 2.20
manufacturerID: 'Apple, Inc. '
flags: 0
libraryDescription: 'Keychain emulation PKCS#11 API '
libraryVersion: 0.0
Returned: 0 CKR_OK
Then in:
5: C_GetTokenInfo
2020-11-30 18:33:08.641
[in] slotID = 0x0
[out] pInfo:
label: 'Key For PIV Authentication (Edwa'
manufacturerID: 'Apple, Inc. '
model: 'Keychain '
serialNumber: '000000 '
...
This implies that SSH->SPY-> /usr/lib/ssh-keychain.dylib.->someKeyChainPkcs11->(maybe others)...->someCardPkcs11
It is not clear if "someCardPkcs11" is opensc-pkcs11.dylib or something else. It might be OpenSC is not involved at all on MacOS. The "label" does not look like it was created by opensc-pkcs11.
Two ways to determine if opensc-pkcs11.dylib is called:
/usr/lib/ssh-keychain.dylib->someKeyChainPkcs11 ->SPY->someCardPkcs11Complicating this is MacOS proprietary or modified opensource software:
{ "identitiesonly", oIdentitiesOnly }, so does https://opensource.apple.com/source/OpenSSH/OpenSSH-209/openssh/ from 10.12A long term solution, is to take SPY, copy, rename and modify it to only return public keys that are in IdentitiesOnly=Yes
and loads /usr/lib/ssh-keychain.dylib
@esabol what version of MacOS are you running?
Correction for above:
export PKCS11SPY=/pathto/opensc.pkcs11.dylib
should read
and export PKCS11SPY=/pathto/real-opensc.pkcs11.dylib
@popovec wrote:
There is no way to select only one key from pkcs11 interface. All keys are selected and ssh try to use all of them. But this is a problem with ssh and not OpenSC - maybe ssh with PKCS11Provider will have the option to select a key in future versions of ssh.
According to https://www.redhat.com/en/blog/consistent-pkcs-11-support-red-hat-enterprise-linux-8, written by @Jakuje, the RHEL8 version of ssh has the capability to identify a particular key:
$ ssh -i “pkcs11:id=%01” example.com
@esabol Check the ownership and mod bits for the opensc-pkcs11.dylib for 0.21.0
On Ubuntu-20.04, with PIV card with 4 keypairs and certificates, I had it as 755 doug doug,
and SSH complained once.
If the opensc-pkcs11.dylib and libs it need are not in the whitelist of the ssh-agent (see man ssh-agent)
you may have to move them or add the -P when the ssh-agent is started. libopensc.so or libopensc.dylib is the opensc library.
With a PIV test card with 8 keys/certs I get the same debug output from 0.20.0 and 0.21.0 This without the
Running an an agent in one window in debug mode:
unset SSH_AUTH_SOCK
unset SSH_AGENT_PID
ssh-agent -d -P "/usr/lib/*,/usr/local/lib/*,/opt/*"
SSH_AUTH_SOCK=/tmp/ssh-Qg0VD4zHoTza/agent.2319; export SSH_AUTH_SOCK;
echo Agent pid 2319;
debug2: fd 3 setting O_NONBLOCK
Then in a different window cut-and-past the SSH_AUTH_SOCK line. This will then allow testing od
ssh-add and ssh to the ssh-agent. in first window.
ssh-add -s /opt/ossl-system_tag_0_21_0/lib/opensc-pkcs11.so
ssh -I /opt/ossl-system_tag_0_21_0/lib/opensc-pkcs11.so -v -v -v -l pi XUbuntu-20.04
Then in different set of 2 windows to test 0.20.0 that is part of Ubuntu-20.04
The -P is not needed.
I see the same 8 keys with same sha256 hashes being sent to the server.
Another thing to try on MacOS, is to not use the
@esabol Do you have new PIV card like the IDEMA ID-One PIV 2.4 on Cosmos V8.1 which has NIST sp800-73-4 extensions?
Can you send the ATR?
There may be one issue if the Global PIN is preferred, but the local PIN is also acceptable.
I have not tried the IdentitiesOnly.
Another thig to try: don't use /usr/lib/ssh-keychain.dylib for ssh or ssh-add , which I think is not using OpenSC at all,
and use the opensc-pkcs11.dylib which just uses the smart card.
@mouse07410 The attestation cert are a Yubico extension. They are not in NIST sp800-73-4 standard.
But see https://github.com/OpenSC/OpenSC/pull/2066
@esabol has a real gov issued PIV card.
@dengert asked:
@esabol what version of MacOS are you running?
10.13.6, currently, but I'm hoping to move to 10.14.latest soon. OpenSSH_7.8p1, LibreSSL 2.6.2
@dengert commented:
This implies that SSH->SPY-> /usr/lib/ssh-keychain.dylib.->someKeyChainPkcs11->(maybe others)...->someCardPkcs11
It is not clear if "someCardPkcs11" is opensc-pkcs11.dylib or something else. It might be OpenSC is not involved at all on MacOS. The "label" does not look like it was created by opensc-pkcs11.
I very much doubt it. I haven't installed anything besides OpenSC 0.20 and 0.21 that is PKCS11-related.
@esabol Do you have new PIV card like the IDEMA ID-One PIV 2.4 on Cosmos V8.1 which has NIST > sp800-73-4 extensions?
Can you send the ATR?
I'm sorry. You've exceeded my knowledge of PIV cards. My PIV card is 2-3 years old, I think. Something like that.
I've re-installed OpenSC 0.21, and here's the spy log for that:
opensc.0.21.log
*************** OpenSC PKCS#11 spy *****************
Loaded: "/usr/lib/ssh-keychain.dylib"
0: C_GetFunctionList
2020-12-03 21:25:32.313
Returned: 0 CKR_OK
1: C_Initialize
2020-12-03 21:25:32.313
[in] pInitArgs = 0x0
Returned: 0 CKR_OK
2: C_GetInfo
2020-12-03 21:25:32.462
[out] pInfo:
cryptokiVersion: 2.20
manufacturerID: 'Apple, Inc. '
flags: 0
libraryDescription: 'Keychain emulation PKCS#11 API '
libraryVersion: 0.0
Returned: 0 CKR_OK
3: C_GetSlotList
2020-12-03 21:25:32.462
[in] tokenPresent = 0x1
[out] pSlotList:
Count is 1
[out] *pulCount = 0x1
Returned: 0 CKR_OK
4: C_GetSlotList
2020-12-03 21:25:32.462
[in] tokenPresent = 0x1
[out] pSlotList:
Slot 0
[out] *pulCount = 0x1
Returned: 0 CKR_OK
5: C_GetTokenInfo
2020-12-03 21:25:32.462
[in] slotID = 0x0
[out] pInfo:
label: 'PIV_II '
manufacturerID: 'Apple, Inc. '
model: 'Keychain '
serialNumber: '000000 '
ulMaxSessionCount: 0
ulSessionCount: 0
ulMaxRwSessionCount: 0
ulRwSessionCount: 0
ulMaxPinLen: 0
ulMinPinLen: 0
ulTotalPublicMemory: 0
ulFreePublicMemory: 0
ulTotalPrivateMemory: 0
ulFreePrivateMemory: 0
hardwareVersion: 0.0
firmwareVersion: 0.0
time: ' '
flags: 404
CKF_LOGIN_REQUIRED
CKF_TOKEN_INITIALIZED
Returned: 0 CKR_OK
6: C_OpenSession
2020-12-03 21:25:32.462
[in] slotID = 0x0
[in] flags = 0x6
pApplication=0x0
Notify=0x0
[out] *phSession = 0x1
Returned: 0 CKR_OK
7: C_Login
2020-12-03 21:25:32.462
[in] hSession = 0x1
[in] userType = CKU_USER
[in] pPin[ulPinLen] 00007fa3e3e00170 / 8
00000000 [redacted]
Returned: 0 CKR_OK
8: C_FindObjectsInit
2020-12-03 21:25:32.582
[in] hSession = 0x1
[in] pTemplate[1]:
CKA_CLASS CKO_PUBLIC_KEY
Returned: 0 CKR_OK
9: C_FindObjects
2020-12-03 21:25:32.582
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x0 matches
Returned: 0 CKR_OK
10: C_GetAttributeValue
2020-12-03 21:25:32.582
[in] hSession = 0x1
[in] hObject = 0x0
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_MODULUS 0000000000000000 / 0
CKA_PUBLIC_EXPONENT 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_MODULUS 0000000000000000 / 257
CKA_PUBLIC_EXPONENT 0000000000000000 / 3
Returned: 0 CKR_OK
11: C_GetAttributeValue
2020-12-03 21:25:32.582
[in] hSession = 0x1
[in] hObject = 0x0
[in] pTemplate[3]:
CKA_ID 00007fa3e3c06d90 / 270
CKA_MODULUS 00007fa3e3c02520 / 257
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
[out] pTemplate[3]:
CKA_ID 00007fa3e3c06d90 / 270
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_MODULUS 00007fa3e3c02520 / 257
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
00000000 [redacted]
Returned: 0 CKR_OK
12: C_FindObjects
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x1 matches
Returned: 0 CKR_OK
13: C_GetAttributeValue
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] hObject = 0x1
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_MODULUS 0000000000000000 / 0
CKA_PUBLIC_EXPONENT 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_MODULUS 0000000000000000 / 257
CKA_PUBLIC_EXPONENT 0000000000000000 / 3
Returned: 0 CKR_OK
14: C_GetAttributeValue
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] hObject = 0x1
[in] pTemplate[3]:
CKA_ID 00007fa3e3c02520 / 270
CKA_MODULUS 00007fa3e3c06d90 / 257
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
[out] pTemplate[3]:
CKA_ID 00007fa3e3c02520 / 270
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_MODULUS 00007fa3e3c06d90 / 257
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
00000000 [redacted]
Returned: 0 CKR_OK
15: C_FindObjects
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x2 matches
Returned: 0 CKR_OK
16: C_GetAttributeValue
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] hObject = 0x2
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_MODULUS 0000000000000000 / 0
CKA_PUBLIC_EXPONENT 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_MODULUS 0000000000000000 / 257
CKA_PUBLIC_EXPONENT 0000000000000000 / 3
Returned: 0 CKR_OK
17: C_GetAttributeValue
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] hObject = 0x2
[in] pTemplate[3]:
CKA_ID 00007fa3e3c06d90 / 270
CKA_MODULUS 00007fa3e3c02520 / 257
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
[out] pTemplate[3]:
CKA_ID 00007fa3e3c06d90 / 270
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_MODULUS 00007fa3e3c02520 / 257
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
00000000 [redacted]
Returned: 0 CKR_OK
18: C_FindObjects
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x3 matches
Returned: 0 CKR_OK
19: C_GetAttributeValue
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] hObject = 0x3
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_MODULUS 0000000000000000 / 0
CKA_PUBLIC_EXPONENT 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_MODULUS 0000000000000000 / 257
CKA_PUBLIC_EXPONENT 0000000000000000 / 3
Returned: 0 CKR_OK
20: C_GetAttributeValue
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] hObject = 0x3
[in] pTemplate[3]:
CKA_ID 00007fa3e3c02520 / 270
CKA_MODULUS 00007fa3e3c06d90 / 257
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
[out] pTemplate[3]:
CKA_ID 00007fa3e3c02520 / 270
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_MODULUS 00007fa3e3c06d90 / 257
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
00000000 [redacted]
Returned: 0 CKR_OK
21: C_FindObjects
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x4 matches
Returned: 0 CKR_OK
22: C_GetAttributeValue
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] hObject = 0x4
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_MODULUS 0000000000000000 / 0
CKA_PUBLIC_EXPONENT 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_MODULUS 0000000000000000 / 257
CKA_PUBLIC_EXPONENT 0000000000000000 / 3
Returned: 0 CKR_OK
23: C_GetAttributeValue
2020-12-03 21:25:32.585
[in] hSession = 0x1
[in] hObject = 0x4
[in] pTemplate[3]:
CKA_ID 00007fa3e3c06d90 / 270
CKA_MODULUS 00007fa3e3c02520 / 257
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
[out] pTemplate[3]:
CKA_ID 00007fa3e3c06d90 / 270
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_MODULUS 00007fa3e3c02520 / 257
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
00000000 [redacted]
Returned: 0 CKR_OK
24: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x5 matches
Returned: 0 CKR_OK
25: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x5
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_MODULUS 0000000000000000 / 0
CKA_PUBLIC_EXPONENT 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_MODULUS 0000000000000000 / 257
CKA_PUBLIC_EXPONENT 0000000000000000 / 3
Returned: 0 CKR_OK
26: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x5
[in] pTemplate[3]:
CKA_ID 00007fa3e3c02520 / 270
CKA_MODULUS 00007fa3e3c06d90 / 257
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
[out] pTemplate[3]:
CKA_ID 00007fa3e3c02520 / 270
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_MODULUS 00007fa3e3c06d90 / 257
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
00000000 [redacted]
Returned: 0 CKR_OK
27: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x6 matches
Returned: 0 CKR_OK
28: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x6
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_MODULUS 0000000000000000 / 0
CKA_PUBLIC_EXPONENT 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_MODULUS 0000000000000000 / 257
CKA_PUBLIC_EXPONENT 0000000000000000 / 3
Returned: 0 CKR_OK
29: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x6
[in] pTemplate[3]:
CKA_ID 00007fa3e3c06d90 / 270
CKA_MODULUS 00007fa3e3c02520 / 257
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
[out] pTemplate[3]:
CKA_ID 00007fa3e3c06d90 / 270
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_MODULUS 00007fa3e3c02520 / 257
00000000 [redacted]
00000010 [redacted]
00000020 [redacted]
00000030 [redacted]
00000040 [redacted]
00000050 [redacted]
00000060 [redacted]
00000070 [redacted]
00000080 [redacted]
00000090 [redacted]
000000A0 [redacted]
000000B0 [redacted]
000000C0 [redacted]
000000D0 [redacted]
000000E0 [redacted]
000000F0 [redacted]
00000100 [redacted]
CKA_PUBLIC_EXPONENT 00007fa3e3c06d20 / 3
00000000 [redacted]
Returned: 0 CKR_OK
30: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x0
Returned: 0 CKR_OK
31: C_FindObjectsFinal
2020-12-03 21:25:32.586
[in] hSession = 0x1
Returned: 0 CKR_OK
32: C_FindObjectsInit
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] pTemplate[1]:
CKA_CLASS CKO_CERTIFICATE
Returned: 0 CKR_OK
33: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x0 matches
Returned: 0 CKR_OK
34: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x0
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
Returned: 0 CKR_OK
35: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x1 matches
Returned: 0 CKR_OK
36: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x1
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
Returned: 0 CKR_OK
37: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x2 matches
Returned: 0 CKR_OK
38: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x2
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
Returned: 0 CKR_OK
39: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x3 matches
Returned: 0 CKR_OK
40: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x3
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
Returned: 0 CKR_OK
41: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x4 matches
Returned: 0 CKR_OK
42: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x4
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
Returned: 0 CKR_OK
43: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x5 matches
Returned: 0 CKR_OK
44: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x5
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
Returned: 0 CKR_OK
45: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x1
Object 0x6 matches
Returned: 0 CKR_OK
46: C_GetAttributeValue
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] hObject = 0x6
[in] pTemplate[3]:
CKA_ID 0000000000000000 / 0
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
[out] pTemplate[3]:
CKA_ID 0000000000000000 / 270
CKA_SUBJECT 0000000000000000 / 0
CKA_VALUE 0000000000000000 / 0
Returned: 0 CKR_OK
47: C_FindObjects
2020-12-03 21:25:32.586
[in] hSession = 0x1
[in] ulMaxObjectCount = 0x1
[out] ulObjectCount = 0x0
Returned: 0 CKR_OK
48: C_FindObjectsFinal
2020-12-03 21:25:32.586
[in] hSession = 0x1
Returned: 0 CKR_OK
If I diff the two log files, I note the following differences:
3: C_GetSlotList returns Count is 2 [out] *pulCount = 0x2 on 0.20. On 0.21, it returns Count is 1 [out] *pulCount = 0x1.4: C_GetSlotList returns Slot 0 Slot 1 [out] *pulCount = 0x2 on 0.20. On 0.21, it returns Slot 0 [out] *pulCount = 0x1.5: C_GetTokenInfo returns 'Key For PIV Authentication (Edwa' on 0.20. On 0.21, it returns 'PIV_II '.11: C_GetAttributeValue, the pTemplate[3] hex values are different for the CKA_{ID,MODULUS,PUBLIC_EXPONENT}.12: C_FindObjects returns [out] ulObjectCount = 0x0 on 0.20. On 0.21, it returns [out] ulObjectCount = 0x1 Object 0x1 matches.C_FindObjectsFinal followed by C_FindObjectsInit. 0.21 does two C_GetAttributeValue steps.15: C_FindObjects returns Object 0x0 matches on 0.20. On 0.21, it returns Object 0x2 matches.16: C_GetAttributeValue has different pTemplate[3]s. 0.20 is CKA_{ID,SUBJECT,VALUE}, but 0.21 is CKA_{ID,MODULUS,PUBLIC_EXPONENT}.I hope this proves useful.
@dengert commented:
@esabol Check the ownership and mod bits for the opensc-pkcs11.dylib for 0.21.0
On Ubuntu-20.04, with PIV card with 4 keypairs and certificates, I had it as 755 doug doug,
and SSH complained once.
Is this what you want?
> ls -l /Library/OpenSC/lib/
total 48704
-rwxr-xr-x 1 root wheel 4731380 Dec 29 2019 libopensc.6.dylib*
-rwxr-xr-x 1 root wheel 5999840 Nov 24 07:12 libopensc.7.dylib*
lrwxr-xr-x 1 root wheel 17 Dec 3 21:21 libopensc.dylib@ -> libopensc.7.dylib
-rwxr-xr-x 1 root wheel 1584228 Dec 29 2019 libsmm-local.6.so*
-rwxr-xr-x 1 root wheel 3081056 Nov 24 07:12 libsmm-local.7.so*
lrwxr-xr-x 1 root wheel 17 Dec 3 21:21 libsmm-local.so@ -> libsmm-local.7.so
-rwxr-xr-x 1 root wheel 3274000 Nov 24 07:12 onepin-opensc-pkcs11.so*
drwxr-xr-x 3 root wheel 96 Dec 29 2019 opensc-pkcs11.bundle/
-rwxr-xr-x 1 root wheel 3273984 Nov 24 07:12 opensc-pkcs11.so*
drwxr-xr-x 5 root wheel 160 Dec 3 21:21 pkcs11/
-rwxr-xr-x 1 root wheel 2975472 Nov 24 07:12 pkcs11-spy.so*
drwxr-xr-x 3 root wheel 96 Dec 3 21:21 pkgconfig/
Could issue #2175 be related?
What looks strange is:
5: C_GetTokenInfo
2020-12-03 21:25:32.462
[in] slotID = 0x0
[out] pInfo:
label: 'PIV_II '
manufacturerID: 'Apple, Inc. '
model: 'Keychain '
serialNumber: '000000 '
OpenSC PKCS11 would not return "manufacturerID: 'Apple, Inc.'" or model: 'Keychain '"
So it might be using an Apple PIV driver for the keychain is called. i.e. there are more then one levels of PKCS11 modules.
Also the output of ls -l /Library/OpenSC/lib/ looks like there are two versions of the libraries and there is only one opensc-pkcs11.so but there are also two subdirectories, old opensc-pkcs11.bundle/ and new pkcs11/ We may have changed who OpenSC is installed MacOS with 0.21.0
@frankmorgner any comment on this?
I don't think #2175 is related.
@dengert commented:
What looks strange is: [...]
OpenSC PKCS11 would not return "manufacturerID: 'Apple, Inc.'" or model: 'Keychain '"
Well, those things are identical between 0.20 and 0.21. I would guess MacOS is responsible for those things?
Also the output of
ls -l /Library/OpenSC/lib/looks like there are two versions of the libraries and there is only one opensc-pkcs11.so but there are also two subdirectories, old opensc-pkcs11.bundle/ and new pkcs11/ We may have changed who OpenSC is installed MacOS with 0.21.0
Well, sure, but that’s all as I would expect. What matters are the .so and .dylib symlinks, and they point to correct versions depending on whether 0.20 or 0.21 is currently installed. The pkcs11 subdirectory just contains relative symlinks and is unchanged between versions. opensc-pkcs11.bundle contains additional subdirectories, and the files in those sub-subdirectories change wrt 0.20 vs. 0.21. Anyway, I don’t think the installation is fine.
Anything else of interest in the diff between the two spy logs?
Above @esabol has pasted some output of pkcs11-tool, which uses the OpenSC PKCS#11 module directly:
Using reader with a card: SCM Microsystems Inc. SCR 3310
PKCS#15 Card [PIV_II]:
Version : 0
Serial number : ...
Manufacturer ID: piv_II
Flags :
...
in the pkcs11-spy trace, the output of the slot info looks different:
5: C_GetTokenInfo
2020-12-03 21:25:32.462
[in] slotID = 0x0
[out] pInfo:
label: 'PIV_II '
manufacturerID: 'Apple, Inc. '
model: 'Keychain '
serialNumber: '000000 '
It looks like ssh-keychain.dylib is some Apple specific layer to access opensc.pkcs11.dylib. I assume that Apple wants to allow using your keys from Keychain.app in ssh.
Please try configuring ssh to use opensc.pkcs11.dylib without the middle man. How does the log look like in this case, does the error persist?
@esabol Since you are using ssh-keychain.dylib to make your keys visible to the system keychain, maybe the following could be of help :
1 - Load your SSH keys as you would normally using ssh-add -s /usr/lib/ssh-keychain.dylib.
2 - Get a list of all the SSH keys fingerprints using ssh-add -l, then select the one you need.
3 - SSH to your server using KEYCHAIN_CERTIFICATES="<fingerprint_of_ssh_key" ssh -o PKCS11Provider=/usr/lib/ssh-keychain.dylib user@host