<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2595" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-03-11T17:16:01+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2595</id>
<entry>
<author><name><![CDATA[qnox]]></name></author>
<updated>2017-03-11T17:16:01+01:00</updated>
<published>2017-03-11T17:16:01+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2595&amp;p=9452#p9452</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2595&amp;p=9452#p9452"/>
<title type="html"><![CDATA[problem with using custom ssl certificate in windows]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2595&amp;p=9452#p9452"><![CDATA[
Hi!<br /><br />I uploaded into 9a slot private key with certificate signed by our enterprise CA without a problem via PIV manager: it is displayed in PIV manager correctly. W used to use this certificate for OpenVPN from disk, now I would like to used it from Yubikey Neo.<br /><br />But truing to access it from OpenVPN gives me an issue:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">c:\Program Files (x86)\Yubico\yubico-piv-tool\bin&gt;openvpn --verb 7 --show-pkcs11-ids libykcs11-1.dll<br />Sat Mar 11 16:50:32 2017 us=492798 PKCS#11: Adding provider 'libykcs11-1.dll'-'libykcs11-1.dll'<br />Sat Mar 11 16:50:32 2017 us=531292 PKCS#11: Provider 'libykcs11-1.dll' added rv=0-'CKR_OK'<br />Sat Mar 11 16:50:32 2017 us=531792 PKCS#11: Creating a new session<br />Sat Mar 11 16:50:32 2017 us=532794 PKCS#11: Get certificate attributes failed: 179:'CKR_SESSION_HANDLE_INVALID'<br />Sat Mar 11 16:50:32 2017 us=991522 PKCS#11: Cannot get object attribute for provider 'Yubico (www.yubico.com)' object 37 rv=6-'CKR_FUNCTION_FAILED'<br /><br />The following objects are available for use.<br />Each object shown below may be used as parameter to<br />--pkcs11-id option please remember to use single quote mark.<br />Sat Mar 11 16:50:32 2017 us=992524 PKCS#11: Terminating openssl<br />Sat Mar 11 16:50:32 2017 us=992524 PKCS#11: Removing providers<br />Sat Mar 11 16:50:32 2017 us=992524 PKCS#11: Removing provider 'libykcs11-1.dll'<br />Sat Mar 11 16:50:33 2017 us=470 PKCS#11: Releasing sessions<br />Sat Mar 11 16:50:33 2017 us=470 PKCS#11: Terminating slotevent<br />Sat Mar 11 16:50:33 2017 us=470 PKCS#11: Marking as uninitialized<br /><br />c:\Program Files (x86)\Yubico\yubico-piv-tool\bin&gt;openssl<br />7688:error:02001005:system library:fopen:Input/output error:bss_file.c:175:fopen('C:\PHP\extras\ssl','rb')<br />7688:error:2006D002:BIO routines:BIO_new_file:system lib:bss_file.c:184:<br />7688:error:0E078002:configuration file routines:DEF_LOAD:system lib:conf_def.c:197:</div><br /><br />Certificate generated by PIV manager is displayed and accessed by OpenVPN without any issue:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">c:\Program Files (x86)\Yubico\yubico-piv-tool\bin&gt;openvpn --verb 7 --show-pkcs11-ids libykcs11-1.dll<br />Sat Mar 11 16:14:52 2017 us=128736 PKCS#11: Adding provider 'libykcs11-1.dll'-'libykcs11-1.dll'<br />Sat Mar 11 16:14:52 2017 us=164557 PKCS#11: Provider 'libykcs11-1.dll' added rv=0-'CKR_OK'<br />Sat Mar 11 16:14:52 2017 us=164557 PKCS#11: Creating a new session<br />Sat Mar 11 16:14:52 2017 us=165557 PKCS#11: Get certificate attributes failed: 179:'CKR_SESSION_HANDLE_INVALID'<br /><br />The following objects are available for use.<br />Each object shown below may be used as parameter to<br />--pkcs11-id option please remember to use single quote mark.<br />Sat Mar 11 16:14:52 2017 us=495035 PKCS#11: Using cached session<br /><br />Certificate<br />       DN:             CN=Test yubikey#1<br />       Serial:         AE4D23097B986B64<br />       Serialized id:  Yubico/YubiKey\x20NEO/1234/YubiKey\x20PIV/00<br />Sat Mar 11 16:14:52 2017 us=497416 PKCS#11: Terminating openssl<br />Sat Mar 11 16:14:52 2017 us=497416 PKCS#11: Removing providers<br />Sat Mar 11 16:14:52 2017 us=497416 PKCS#11: Removing provider 'libykcs11-1.dll'<br />Sat Mar 11 16:14:52 2017 us=505510 PKCS#11: Releasing sessions<br />Sat Mar 11 16:14:52 2017 us=506011 PKCS#11: Terminating slotevent<br />Sat Mar 11 16:14:52 2017 us=506011 PKCS#11: Marking as uninitialized<br /></div><br /><br />How can I import externaly generated SSL certificate to work with OpenVPN? I would be gratefull for any help.<br /><br />I'm runing:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Windows 10 version 10.0.14393 64bit</div><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">openvpn --version<br />OpenVPN 2.4.0 x86_64-w64-mingw32 &#91;SSL (OpenSSL)&#93; &#91;LZO&#93; &#91;LZ4&#93; &#91;PKCS11&#93; &#91;AEAD&#93; built on Jan 31 2017<br />library versions: OpenSSL 1.0.2k  26 Jan 2017, LZO 2.09<br />Windows version 6.2 (Windows 8 or greater) 64bit<br />Originally developed by James Yonan<br />Copyright (C) 2002-2017 OpenVPN Technologies, Inc. &lt;sales@openvpn.net&gt;<br />Compile time defines: enable_async_push=no enable_comp_stub=no enable_crypto=yes enable_crypto_ofb_cfb=yes enable_debug=yes enable_def_auth=yes enable_dlopen=unknown enable_dlopen_self=unknown enable_dlopen_self_static=unknown enable_fast_install=needless enable_fragment=yes enable_iproute2=no enable_libtool_lock=yes enable_lz4=yes enable_lzo=yes enable_management=yes enable_multi=yes enable_multihome=yes enable_pam_dlopen=no enable_pedantic=no enable_pf=yes enable_pkcs11=yes enable_plugin_auth_pam=no enable_plugin_down_root=no enable_plugins=yes enable_port_share=yes enable_selinux=no enable_server=yes enable_shared=yes enable_shared_with_static_runtimes=yes enable_small=no enable_static=yes enable_strict=no enable_strict_options=no enable_systemd=no enable_werror=no enable_win32_dll=yes enable_x509_alt_username=no with_crypto_library=openssl with_gnu_ld=yes with_mem_check=no with_plugindir='$(libdir)/openvpn/plugins' with_special_build= with_sysroot=no</div><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">yubico-piv-tool.exe -V<br />yubico-piv-tool 1.4.2</div><br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />yubikey neo firmware 3.4.9<br /></div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4728">qnox</a> — Sat Mar 11, 2017 5:16 pm</p><hr />
]]></content>
</entry>
</feed>