<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1586" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-11-07T18:02:30+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1586</id>
<entry>
<author><name><![CDATA[dwmw2]]></name></author>
<updated>2014-11-07T18:02:30+01:00</updated>
<published>2014-11-07T18:02:30+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1586&amp;p=6147#p6147</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1586&amp;p=6147#p6147"/>
<title type="html"><![CDATA[Re: [SOLVED] NEO PIV gives CKR_USER_NOT_LOGGED_IN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1586&amp;p=6147#p6147"><![CDATA[
This is mostly fixed in GnuTLS with the following commits:<br /><!-- m --><a class="postlink" href="https://gitorious.org/gnutls/gnutls/commit/e1a0af19">https://gitorious.org/gnutls/gnutls/commit/e1a0af19</a><!-- m --><br /><!-- m --><a class="postlink" href="https://gitorious.org/gnutls/gnutls/commit/239cb7d7">https://gitorious.org/gnutls/gnutls/commit/239cb7d7</a><!-- m --><br /><br />This now works:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">openconnect -c 'pkcs11:manufacturer=piv_II;id=%01' $VPNSERVER</div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3261">dwmw2</a> — Fri Nov 07, 2014 6:02 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dwmw2]]></name></author>
<updated>2014-11-06T21:10:37+01:00</updated>
<published>2014-11-06T21:10:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1586&amp;p=6141#p6141</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1586&amp;p=6141#p6141"/>
<title type="html"><![CDATA[Re: [QUESTION] How do I use NEO as PKCS#11 token]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1586&amp;p=6141#p6141"><![CDATA[
I think this is a bug. We modified GnuTLS to call pkcs11_login() again when a key has the CKA_ALWAYS_AUTHENTICATE attribute set: <!-- m --><a class="postlink" href="https://gitorious.org/gnutls/gnutls/commit/e1a0af191">https://gitorious.org/gnutls/gnutls/commit/e1a0af191</a><!-- m --><br /><br />Now the GnuTLS pkcs11_login() function is duly called before C_SignInit() and does this:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent"><br />25: C_GetSessionInfo<br />2014-11-06 19:56:41.534<br />&#91;in&#93; hSession = 0xed7620<br />&#91;out&#93; pInfo: <br />      slotID:                  1<br />      state:                  '           CKS_RO_USER_FUNCTIONS'<br />      flags:                   4<br />        CKF_SERIAL_SESSION               <br />      ulDeviceError:           0<br />Returned:  0 CKR_OK<br /></div><br /><br />We see CKS_RO_USER_FUNCTIONS and we don't actually call C_Login(). So I hacked it again to avoid that check and now it does call C_Login() and the exchange goes like this...<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">28: C_Login<br />2014-11-06 20:02:11.599<br />&#91;in&#93; hSession = 0x2c089a0<br />&#91;in&#93; userType = CKU_USER<br />&#91;in&#93; pPin&#91;ulPinLen&#93; 000000000293d9c0 / 6<br />    00000000  31 32 33 34 35 36                                123456          <br />Returned:  256 CKR_USER_ALREADY_LOGGED_IN<br />p11: Login result = 256<br /><br />29: C_SignInit<br />2014-11-06 20:02:11.599<br />&#91;in&#93; hSession = 0x2c089a0<br />pMechanism-&gt;type=CKM_RSA_PKCS                 <br />&#91;in&#93; hKey = 0x269da90<br />Returned:  0 CKR_OK<br /><br />30: C_Sign<br />2014-11-06 20:02:11.599<br />&#91;in&#93; hSession = 0x2c089a0<br />&#91;in&#93; pData&#91;ulDataLen&#93; 00007fff4449d3d0 / 36<br />    00000000  E9 44 15 2E 2F 04 6F 66 78 9B F1 9F 35 20 1D EB  .D../.ofx...5 ..<br />    00000010  A7 8B A1 B9 70 99 36 1B 9E 75 73 2D 4D 8F 7A A6  ....p.6..us-M.z.<br />    00000020  7D DE 54 B7                                      }.T.            <br />&#91;out&#93; pSignature&#91;*pulSignatureLen&#93; NULL &#91;size : 0x100 (256)&#93;<br />Returned:  0 CKR_OK<br /><br />31: C_Sign<br />2014-11-06 20:02:11.599<br />&#91;in&#93; hSession = 0x2c089a0<br />&#91;in&#93; pData&#91;ulDataLen&#93; 00007fff4449d3d0 / 36<br />    00000000  E9 44 15 2E 2F 04 6F 66 78 9B F1 9F 35 20 1D EB  .D../.ofx...5 ..<br />    00000010  A7 8B A1 B9 70 99 36 1B 9E 75 73 2D 4D 8F 7A A6  ....p.6..us-M.z.<br />    00000020  7D DE 54 B7                                      }.T.            <br />Returned:  257 CKR_USER_NOT_LOGGED_IN<br /></div><br /><br /><br />Since this might be an OpenSC bug I've also posted to the opensc-devel list: <!-- m --><a class="postlink" href="http://permalink.gmane.org/gmane.comp.encryption.opensc.devel/15731">http://permalink.gmane.org/gmane.comp.e ... evel/15731</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3261">dwmw2</a> — Thu Nov 06, 2014 9:10 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dwmw2]]></name></author>
<updated>2014-11-07T17:55:34+01:00</updated>
<published>2014-11-06T17:38:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1586&amp;p=6140#p6140</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1586&amp;p=6140#p6140"/>
<title type="html"><![CDATA[[SOLVED] NEO PIV gives CKR_USER_NOT_LOGGED_IN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1586&amp;p=6140#p6140"><![CDATA[
I have a NEO which appears to have the PIV applet installed.<br /><br />I can't get 'ykneomgr -a' to admit that, mind you:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ ykneomgr  -d -a<br />Trying reader 0: Yubico Yubikey NEO OTP+CCID 00 00<br />--&gt; 13: 00 a4 04 00 08 a0 00 00 05 27 20 01 01 <br />&lt;-- 12: 03 02 00 01 85 07 82 00 00 00 90 00 <br />versionMajor 3<br />versionMinor 2<br />versionBuild 0<br />pgmSeq 1<br />touchLevel 34055<br />mode 82<br />crTimeout 0<br />autoEjectTime 0<br />--&gt; 4: 00 01 10 00 <br />&lt;-- 6: 00 2d ca f3 90 00 <br />serialno 3001075<br />--&gt; 13: 00 a4 04 00 08 a0 00 00 00 03 00 00 00 <br />&lt;-- 105: 6f 65 84 08 a0 00 00 00 03 00 00 00 a5 59 9f 65 01 ff 9f 6e 06 47 91 12 10 38 00 73 4a 06 07 2a 86 48 86 fc 6b 01 60 0c 06 0a 2a 86 48 86 fc 6b 02 02 01 01 63 09 06 07 2a 86 48 86 fc 6b 03 64 0b 06 09 2a 86 48 86 fc 6b 04 02 55 65 0b 06 09 2b 85 10 86 48 64 02 01 03 66 0c 06 0a 2b 06 01 04 01 2a 02 6e 01 02 90 00 <br />--&gt; 13: 80 50 00 00 08 01 02 03 04 05 06 07 08 <br />&lt;-- 30: 00 00 33 17 01 41 49 97 09 12 ff 02 00 03 4b ae 77 56 ee 49 56 66 ea 14 f5 6f 14 84 90 00 <br />error: ykneomgr_authenticate (-4): Backend error<br /></div><br /><br />But I can install a private key with yubico-piv-tool:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ yubico-piv-tool  -a import-key -s 9c  -p $PASSPHRASE -i ~/.cert/certificate.p12 -K PKCS12<br />Successfully imported a new private key.<br /></div><br /><br />(The corresponding cert is larger than 2KiB so I can't install that but that shouldn't matter).<br /><br />Now I can attempt to connect to my VPN server with openconnect:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ openconnect -c ~/.cert/certificate.pem -k 'pkcs11:model=PKCS%2315%20emulated;manufacturer=piv_II;serial=00000000;token=PIV_II%20%28PIV%20Card%20Holder%20pin%29;id=%02;object=SIGN%20key;object-type=private' $VPNSERVER -v -v<br /></div><br /><br />This appears to work fine, to start with. I'm asked for the PIN, and it doesa test signature to check that the key and certificate that I've given it are a correct match:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">*************** OpenSC PKCS#11 spy *****************<br />Loaded: &quot;/usr/lib64/opensc-pkcs11.so&quot;<br /><br />0: C_GetFunctionList<br />2014-11-06 16:32:24.165<br />Returned:  0 CKR_OK<br /><br />1: C_Initialize<br />2014-11-06 16:32:24.168<br />&#91;in&#93; pInitArgs = 0x23ca380<br />     flags: 2<br />       CKF_OS_LOCKING_OK<br />Returned:  0 CKR_OK<br /><br />2: C_GetInfo<br />2014-11-06 16:32:24.339<br />&#91;out&#93; pInfo: <br />      cryptokiVersion:         2.20<br />      manufacturerID:         'OpenSC (www.opensc-project.org) '<br />      flags:                   0<br />      libraryDescription:     'Smart card PKCS#11 API          '<br />      libraryVersion:          0.0<br />Returned:  0 CKR_OK<br /><br />3: C_GetSlotList<br />2014-11-06 16:32:24.486<br />&#91;in&#93; tokenPresent = 0x1<br />&#91;out&#93; pSlotList: <br />Slot 1<br />&#91;out&#93; *pulCount = 0x1<br />Returned:  0 CKR_OK<br /><br />4: C_GetTokenInfo<br />2014-11-06 16:32:24.866<br />&#91;in&#93; slotID = 0x1<br />&#91;out&#93; pInfo: <br />      label:                  'PIV_II (PIV Card Holder pin)    '<br />      manufacturerID:         'piv_II                          '<br />      model:                  'PKCS#15 emulated'<br />      serialNumber:           '00000000        '<br />      ulMaxSessionCount:       0<br />      ulSessionCount:          0<br />      ulMaxRwSessionCount:     0<br />      ulRwSessionCount:        0<br />      ulMaxPinLen:             8<br />      ulMinPinLen:             4<br />      ulTotalPublicMemory:     -1<br />      ulFreePublicMemory:      -1<br />      ulTotalPrivateMemory:    -1<br />      ulFreePrivateMemory:     -1<br />      hardwareVersion:         0.0<br />      firmwareVersion:         0.0<br />      time:                   '                '<br />      flags:                   40d<br />        CKF_RNG                          <br />        CKF_LOGIN_REQUIRED               <br />        CKF_USER_PIN_INITIALIZED         <br />        CKF_TOKEN_INITIALIZED            <br />Returned:  0 CKR_OK<br /><br />5: C_GetSlotInfo<br />2014-11-06 16:32:24.866<br />&#91;in&#93; slotID = 0x1<br />&#91;out&#93; pInfo: <br />      slotDescription:        'Yubico Yubikey NEO OTP+CCID 00 0'<br />                              '0                               '<br />      manufacturerID:         'OpenSC (www.opensc-project.org) '<br />      hardwareVersion:         0.0<br />      firmwareVersion:         0.0<br />      flags:                   7<br />        CKF_TOKEN_PRESENT                <br />        CKF_REMOVABLE_DEVICE             <br />        CKF_HW_SLOT                      <br />Returned:  0 CKR_OK<br />Using certificate file /home/dwmw2/.cert/certificate.pem<br />Using PKCS#11 key pkcs11:model=PKCS%2315%20emulated;manufacturer=piv_II;serial=00000000;token=PIV_II%20%28PIV%20Card%20Holder%20pin%29;id=%02;object=SIGN%20key;object-type=private;pin-source=openconnect%3a0x23c1240<br /><br />6: C_GetSlotList<br />2014-11-06 16:32:24.867<br />&#91;in&#93; tokenPresent = 0x1<br />&#91;out&#93; pSlotList: <br />Slot 1<br />&#91;out&#93; *pulCount = 0x1<br />Returned:  0 CKR_OK<br /><br />7: C_GetTokenInfo<br />2014-11-06 16:32:24.867<br />&#91;in&#93; slotID = 0x1<br />&#91;out&#93; pInfo: <br />      label:                  'PIV_II (PIV Card Holder pin)    '<br />      manufacturerID:         'piv_II                          '<br />      model:                  'PKCS#15 emulated'<br />      serialNumber:           '00000000        '<br />      ulMaxSessionCount:       0<br />      ulSessionCount:          0<br />      ulMaxRwSessionCount:     0<br />      ulRwSessionCount:        0<br />      ulMaxPinLen:             8<br />      ulMinPinLen:             4<br />      ulTotalPublicMemory:     -1<br />      ulFreePublicMemory:      -1<br />      ulTotalPrivateMemory:    -1<br />      ulFreePrivateMemory:     -1<br />      hardwareVersion:         0.0<br />      firmwareVersion:         0.0<br />      time:                   '                '<br />      flags:                   40d<br />        CKF_RNG                          <br />        CKF_LOGIN_REQUIRED               <br />        CKF_USER_PIN_INITIALIZED         <br />        CKF_TOKEN_INITIALIZED            <br />Returned:  0 CKR_OK<br /><br />8: C_GetSlotInfo<br />2014-11-06 16:32:24.868<br />&#91;in&#93; slotID = 0x1<br />&#91;out&#93; pInfo: <br />      slotDescription:        'Yubico Yubikey NEO OTP+CCID 00 0'<br />                              '0                               '<br />      manufacturerID:         'OpenSC (www.opensc-project.org) '<br />      hardwareVersion:         0.0<br />      firmwareVersion:         0.0<br />      flags:                   7<br />        CKF_TOKEN_PRESENT                <br />        CKF_REMOVABLE_DEVICE             <br />        CKF_HW_SLOT                      <br />Returned:  0 CKR_OK<br /><br />9: C_OpenSession<br />2014-11-06 16:32:24.868<br />&#91;in&#93; slotID = 0x1<br />&#91;in&#93; flags = 0x4<br />pApplication=(nil)<br />Notify=(nil)<br />&#91;out&#93; *phSession = 0x28a1560<br />Returned:  0 CKR_OK<br /><br />10: C_GetSessionInfo<br />2014-11-06 16:32:24.868<br />&#91;in&#93; hSession = 0x28a1560<br />&#91;out&#93; pInfo: <br />      slotID:                  1<br />      state:                  '           CKS_RO_PUBLIC_SESSION'<br />      flags:                   4<br />        CKF_SERIAL_SESSION               <br />      ulDeviceError:           0<br />Returned:  0 CKR_OK<br />PIN required for PIV_II (PIV Card Holder pin)<br />Enter PIN:<br /><br />11: C_Login<br />2014-11-06 16:32:38.333<br />&#91;in&#93; hSession = 0x28a1560<br />&#91;in&#93; userType = CKU_USER<br />&#91;in&#93; pPin&#91;ulPinLen&#93; 0000000002baeb30 / 6<br />    00000000  31 32 33 34 35 36                                123456          <br />Returned:  0 CKR_OK<br /><br />12: C_FindObjectsInit<br />2014-11-06 16:32:38.368<br />&#91;in&#93; hSession = 0x28a1560<br />&#91;in&#93; pTemplate&#91;3&#93;: <br />    CKA_ID                00000000029b29c0 / 1<br />    00000000  02                                               .               <br />    CKA_LABEL             00000000024a4d10 / 8<br />    5349474E 206B6579<br />     S I G N  . k e y<br />    CKA_CLASS             CKO_PRIVATE_KEY      <br />Returned:  0 CKR_OK<br /><br />13: C_FindObjects<br />2014-11-06 16:32:38.368<br />&#91;in&#93; hSession = 0x28a1560<br />&#91;in&#93; ulMaxObjectCount = 0x1<br />&#91;out&#93; ulObjectCount = 0x1<br />Object 0x2a3b950 matches<br />Returned:  0 CKR_OK<br /><br />14: C_FindObjectsFinal<br />2014-11-06 16:32:38.368<br />&#91;in&#93; hSession = 0x28a1560<br />Returned:  0 CKR_OK<br /><br />15: C_GetAttributeValue<br />2014-11-06 16:32:38.368<br />&#91;in&#93; hSession = 0x28a1560<br />&#91;in&#93; hObject = 0x2a3b950<br />&#91;in&#93; pTemplate&#91;1&#93;: <br />    CKA_KEY_TYPE          00007fff6dbbf548 / 8<br />&#91;out&#93; pTemplate&#91;1&#93;: <br />    CKA_KEY_TYPE          CKK_RSA            <br />Returned:  0 CKR_OK<br /><br />16: C_SignInit<br />2014-11-06 16:32:38.368<br />&#91;in&#93; hSession = 0x28a1560<br />pMechanism-&gt;type=CKM_RSA_PKCS                 <br />&#91;in&#93; hKey = 0x2a3b950<br />Returned:  0 CKR_OK<br /><br />17: C_Sign<br />2014-11-06 16:32:38.368<br />&#91;in&#93; hSession = 0x28a1560<br />&#91;in&#93; pData&#91;ulDataLen&#93; 00000000029a4ca0 / 35<br />    00000000  30 21 30 09 06 05 2B 0E 03 02 1A 05 00 04 14 85  0!0...+.........<br />    00000010  AF 1A B7 B2 8B 75 9C 38 47 BC 34 BA AF 3A 67 3E  .....u.8G.4..:g&gt;<br />    00000020  13 15 35                                         ..5             <br />&#91;out&#93; pSignature&#91;*pulSignatureLen&#93; NULL &#91;size : 0x100 (256)&#93;<br />Returned:  0 CKR_OK<br /><br />18: C_Sign<br />2014-11-06 16:32:38.368<br />&#91;in&#93; hSession = 0x28a1560<br />&#91;in&#93; pData&#91;ulDataLen&#93; 00000000029a4ca0 / 35<br />    00000000  30 21 30 09 06 05 2B 0E 03 02 1A 05 00 04 14 85  0!0...+.........<br />    00000010  AF 1A B7 B2 8B 75 9C 38 47 BC 34 BA AF 3A 67 3E  .....u.8G.4..:g&gt;<br />    00000020  13 15 35                                         ..5             <br />&#91;out&#93; pSignature&#91;*pulSignatureLen&#93; 00000000028f89f0 / 256<br />    00000000  09 90 5C B2 B2 A2 8E DF 00 79 A1 34 08 7F 54 6B  ..\......y.4Tk<br />    00000010  AA FC 60 DB 4E 1B 6B 0D EF 73 CB C3 EA EE 96 60  ..`.N.k..s.....`<br />    00000020  5C 1E 15 3C 18 5D 76 43 14 39 05 BC 3B 60 99 B8  \..&lt;.&#93;vC.9..;`..<br />    00000030  1E 7D 0A 73 E2 B4 78 1B 40 87 96 21 E8 90 9D 0B  .}.s..x.@..!....<br />    00000040  A2 14 27 5B AE 75 97 FE 4E 5F 81 F7 7D 68 17 5D  ..'&#91;.u..N_..}h.&#93;<br />    00000050  B8 23 4F 13 CE 3F 2B 6B 68 25 3D 70 39 D7 34 EA  .#O..?+kh%=p9.4.<br />    00000060  BD 15 D7 4D A9 EF 10 1C 1D 2F 35 CB 09 30 F4 0C  ...M...../5..0..<br />    00000070  1C 18 63 98 79 A6 5F 57 57 DC BA C6 F6 9F D2 F0  ..c.y._WW.......<br />    00000080  D0 88 60 15 68 A3 08 BA C2 06 4B A9 10 2B B1 55  ..`.h.....K..+.U<br />    00000090  8B 9C 07 7F 40 93 75 32 10 66 9B 6F 68 88 C4 BD  ..@.u2.f.oh...<br />    000000A0  46 1D 6E C9 3C 3C 85 C6 3D 55 9F 54 30 5C A3 80  F.n.&lt;&lt;..=U.T0\..<br />    000000B0  04 0F 55 69 66 F3 C3 09 CB 7C 94 FB E9 E1 B5 19  ..Uif....|......<br />    000000C0  56 9E 86 00 5C 36 F0 B8 C3 8A 33 39 4E 58 1A 90  V...\6....39NX..<br />    000000D0  F5 B6 49 77 26 00 2F AC 71 0F FD 28 71 0B FA 90  ..Iw&amp;./.q..(q...<br />    000000E0  5B 25 04 73 A1 EF 7E FC DE 84 97 4C 6D E7 74 DD  &#91;%.s..~....Lm.t.<br />    000000F0  81 61 B1 1D D5 5B A5 87 80 6F C2 5F E5 9B EA 8F  .a...&#91;...o._....<br />Returned:  0 CKR_OK<br />Using client certificate 'Woodhouse\, David'<br /></div><br /><br /><br />... but then it goes off and connects to the server, and then it's asked by the server to perform a signature, but by this time it seems to have forgotten that I'd logged in:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Attempting to connect to server xx.xx.xx.xx:443<br />SSL negotiation with xx.xx.xx.xx<br /><br />22: C_SignInit<br />2014-11-06 16:32:39.499<br />&#91;in&#93; hSession = 0x28a1560<br />pMechanism-&gt;type=CKM_RSA_PKCS                 <br />&#91;in&#93; hKey = 0x2a3b950<br />Returned:  0 CKR_OK<br /><br />23: C_Sign<br />2014-11-06 16:32:39.499<br />&#91;in&#93; hSession = 0x28a1560<br />&#91;in&#93; pData&#91;ulDataLen&#93; 00007fff6dbbf6b0 / 36<br />    00000000  42 B1 2E A0 4B A2 D6 C0 AD C0 CA 28 AD 0F 5D 34  B...K......(..&#93;4<br />    00000010  09 AD 6C 8C 2C A1 31 1E 13 FF 91 65 59 A3 9D D9  ..l.,.1....eY...<br />    00000020  24 89 88 9D                                      $...            <br />&#91;out&#93; pSignature&#91;*pulSignatureLen&#93; NULL &#91;size : 0x100 (256)&#93;<br />Returned:  0 CKR_OK<br /><br />24: C_Sign<br />2014-11-06 16:32:39.499<br />&#91;in&#93; hSession = 0x28a1560<br />&#91;in&#93; pData&#91;ulDataLen&#93; 00007fff6dbbf6b0 / 36<br />    00000000  42 B1 2E A0 4B A2 D6 C0 AD C0 CA 28 AD 0F 5D 34  B...K......(..&#93;4<br />    00000010  09 AD 6C 8C 2C A1 31 1E 13 FF 91 65 59 A3 9D D9  ..l.,.1....eY...<br />    00000020  24 89 88 9D                                      $...            <br />Returned:  257 CKR_USER_NOT_LOGGED_IN<br />SSL connection failure: PKCS #11 user error<br />Failed to open HTTPS connection to xx.xx.xx.xx<br />Failed to obtain WebVPN cookie<br /></div><br /><br />What's wrong? It looks like it's so *close* to working...<br /><br />FWIW I don't think the PKCS#11 standard permits CKR_USER_NOT_LOGGED_IN as a return value from C_Sign(). If that's the case, C_SignInit() should have failed.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3261">dwmw2</a> — Thu Nov 06, 2014 5:38 pm</p><hr />
]]></content>
</entry>
</feed>