Re: [opensc-devel] Which libraries/APIs needed?

2012-12-04 Thread Alon Bar-Lev
Use PKCS#15 to perform the card management, it can be done using a simple script as you outlined as it done once. Then use PKCS#11 to use the keys and perform the encryption/decryption as it is more standard API, and most likely you will be able to find a utility that does exactly as you need,

Re: [opensc-devel] withdrawal of nsplugin?

2012-11-25 Thread Alon Bar-Lev
nsplugins is not supported an more as far as I know. On Sun, Nov 25, 2012 at 6:47 PM, Greg Troxel g...@ir.bbn.com wrote: ner/plugins/opensc-signer.so lib/opensc-signer.la With 0.12.2, it fails because there is no trace of nsplugin/signer support. There's a Changelog entry from 2009 that

Re: [opensc-devel] state of the project?

2012-11-23 Thread Alon Bar-Lev
On Thu, Nov 22, 2012 at 11:49 AM, Alon Bar-Lev alon.bar...@gmail.com wrote: On Thu, Nov 22, 2012 at 11:42 AM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/22 Alon Bar-Lev alon.bar...@gmail.com On Wed, Nov 21, 2012 at 4:52 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote

Re: [opensc-devel] state of the project?

2012-11-23 Thread Alon Bar-Lev
On Fri, Nov 23, 2012 at 4:21 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/23 Alon Bar-Lev alon.bar...@gmail.com: You copied the repositories without tags. I fixed this for openct, pkcs11-helper, but I guess you should check all repositories moved, make sure we did not lose

Re: [opensc-devel] state of the project?

2012-11-22 Thread Alon Bar-Lev
On Thu, Nov 22, 2012 at 11:42 AM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/22 Alon Bar-Lev alon.bar...@gmail.com On Wed, Nov 21, 2012 at 4:52 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: Hello, 2012/11/17 Alon Bar-Lev alon.bar...@gmail.com: On Sat, Nov

Re: [opensc-devel] state of the project?

2012-11-21 Thread Alon Bar-Lev
On Wed, Nov 21, 2012 at 4:52 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: Hello, 2012/11/17 Alon Bar-Lev alon.bar...@gmail.com: On Sat, Nov 17, 2012 at 11:54 PM, Ludovic Rousseau I don't think I can give you admin access to only these 2 projects. I can add you as a member

Re: [opensc-devel] state of the project?

2012-11-17 Thread Alon Bar-Lev
On Sat, Nov 17, 2012 at 6:00 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/16 Alon Bar-Lev alon.bar...@gmail.com On Wed, Nov 14, 2012 at 10:22 PM, Alon Bar-Lev alon.bar...@gmail.com wrote: On Wed, Nov 14, 2012 at 10:20 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote

Re: [opensc-devel] state of the project?

2012-11-17 Thread Alon Bar-Lev
On Sat, Nov 17, 2012 at 9:26 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/17 Alon Bar-Lev alon.bar...@gmail.com: On Sat, Nov 17, 2012 at 6:00 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/16 Alon Bar-Lev alon.bar...@gmail.com On Wed, Nov 14, 2012 at 10:22

Re: [opensc-devel] state of the project?

2012-11-17 Thread Alon Bar-Lev
On Sat, Nov 17, 2012 at 11:54 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/17 Alon Bar-Lev alon.bar...@gmail.com: On Sat, Nov 17, 2012 at 9:26 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/17 Alon Bar-Lev alon.bar...@gmail.com: On Sat, Nov 17, 2012 at 6:00

Re: [opensc-devel] state of the project?

2012-11-16 Thread Alon Bar-Lev
On Wed, Nov 14, 2012 at 10:22 PM, Alon Bar-Lev alon.bar...@gmail.com wrote: On Wed, Nov 14, 2012 at 10:20 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/14 Ludovic Rousseau ludovic.rouss...@gmail.com I could not migrate: - pkcs11-help. Something fails in the authors names

Re: [opensc-devel] state of the project?

2012-11-14 Thread Alon Bar-Lev
On Wed, Nov 14, 2012 at 10:20 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: 2012/11/14 Ludovic Rousseau ludovic.rouss...@gmail.com I could not migrate: - pkcs11-help. Something fails in the authors names conversion I forked the github repository of Alon. pkcs11-helper is now

Re: [opensc-devel] new server hoster and adminstrator for opensc-project.org required

2012-10-03 Thread Alon Bar-Lev
On Tue, Sep 18, 2012 at 11:33 AM, Jean-Michel Pouré - GOOZE jmpo...@gooze.eu wrote: Dear all, wouldn't it be better to move the remaining parts of the project to github ? Sorry if I did not catch this message before. I volunteer to take part in this project with the community.

Re: [opensc-devel] OpenSC Server Maintenance

2012-06-12 Thread Alon Bar-Lev
On Tue, Jun 12, 2012 at 5:49 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: What else do we need? Wiki, mailing list, file-server, ... Bug tracker github already has bug tracker and wiki... :) ___ opensc-devel mailing list

Re: [opensc-devel] OpenSC Server Maintenance

2012-06-11 Thread Alon Bar-Lev
Hello Andreas, GitHub is a great place... Already there, just need to migrate the wiki. The question is where Gerrit will be (if is used). And if there is a need to migrate the bugs as well... which may be difficult. Alon. On Mon, Jun 11, 2012 at 10:31 PM, Andreas Jellinghaus

Re: [opensc-devel] SO pin in pkcs11-tool?

2012-05-30 Thread Alon Bar-Lev
Hello, I think you have some confusion of what is PKCS#11 Admin PIN. The PKCS#11 Admin PIN is only usable to initialize a token, and optionally unlock the user PIN. It has no special privileges over the content of the card. So you are prompted by firefox for the user PIN, which is OK. Anyway,

Re: [opensc-devel] new release?

2012-05-27 Thread Alon Bar-Lev
On Sun, May 27, 2012 at 7:38 PM, Peter Stuge pe...@stuge.se wrote: Ludovic Rousseau wrote: 2012/5/27 Jean-Michel Pouré - GOOZE jmpo...@gooze.eu: Sufficient privileges in GIThub should be granted to a group of people. Trust is enough to agree on commits. FOAS means Free and Open. FOAS = ?

Re: [opensc-devel] FOSS development

2012-05-27 Thread Alon Bar-Lev
On Sun, May 27, 2012 at 8:26 PM, Peter Stuge pe...@stuge.se wrote: Alon Bar-Lev wrote: Peter, quality is not absolute term. In computing I actually think it is; a high quality program does exactly what it is supposed to do and never anything else. Computers are very simple machines, so

Re: [opensc-devel] Handling multiple USB tokens in IFD handler

2012-05-01 Thread Alon Bar-Lev
On Tue, May 1, 2012 at 5:20 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: OpenCT was maintained by Andreas Jellinghaus. Andreas has now left the smart card world for other opportunities. Do not expect a new release of OpenCT anytime soon. There is no problem to release what we have...

Re: [opensc-devel] OpenSC and multi-arch support

2012-04-14 Thread Alon Bar-Lev
On Thu, Apr 12, 2012 at 11:12 AM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: Le 11 avril 2012 16:43, Ludovic Rousseau ludovic.rouss...@gmail.com a écrit : Le 11 avril 2012 16:37, Douglas E. Engert deeng...@anl.gov a écrit : On 4/11/2012 8:16 AM, Frank Morgner wrote: Adjusting the

[opensc-devel] Latest build changes

2012-03-28 Thread Alon Bar-Lev
Well, I lost it, there are changes committed, the interface of gerrit is very difficult for proper review. I hope these are working. Alon. ___ opensc-devel mailing list opensc-devel@lists.opensc-project.org

Re: [opensc-devel] removing libltdl?

2012-03-24 Thread Alon Bar-Lev
On Sat, Mar 24, 2012 at 1:19 PM, Ludovic Rousseau ludovic.rouss...@gmail.com wrote: Le 24 mars 2012 12:05, Magosányi, Árpád m4g...@gmail.com a écrit : I guess you might want to discuss the pros and cons of removing libltdl dependency. There is a heap of changesets about it in gerrit. I do

Re: [opensc-devel] OpenSC and gerrit

2012-03-22 Thread Alon Bar-Lev
On Thu, Mar 22, 2012 at 12:03 AM, Peter Stuge pe...@stuge.se wrote: Alon Bar-Lev wrote: I will try again. Thanks! It really helps! I am glad! Well, let's agree we do not agree... :) At no point in time I argue that the gerrit is not a good tool, I argue the methodology. Anyway, just last

Re: [opensc-devel] OpenSC and gerrit

2012-03-20 Thread Alon Bar-Lev
On Sun, Mar 18, 2012 at 2:17 AM, Peter Stuge pe...@stuge.se wrote: Alon Bar-Lev wrote: I think you are trying to make opensc something it is not. I am not trying to do a single thing beyond pointing out that there is alot of complaints and wasted time over no *actual* problem. First I want

Re: [opensc-devel] where can I get a engine_pkcs11.dll

2012-03-10 Thread Alon Bar-Lev
What do you mean not able to compile it? https://www.opensc-project.org/engine_pkcs11 On Sat, Mar 10, 2012 at 8:33 AM, Dan Peterson drpeter...@es.net wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I am not able to compile it - -- dan -BEGIN PGP SIGNATURE- Version: PGP

Re: [opensc-devel] Moving master forward

2011-12-14 Thread Alon Bar-Lev
On Wed, Dec 14, 2011 at 4:49 PM, Peter Stuge pe...@stuge.se wrote: Douglas E. Engert wrote: Is it possible to use: https://jenkins.opensc-project.org/ instead of https://www.opensc-project.org:/ https://www.opensc-project.org/autobuild/

Re: [opensc-devel] Moving master forward

2011-12-14 Thread Alon Bar-Lev
On Wed, Dec 14, 2011 at 5:13 PM, Alon Bar-Lev alon.bar...@gmail.com wrote: No, you can use these URLs: https://www.opensc-project.org/autobuild/ https://www.opensc-project.org/codereview/ To access Jenkins and Gerrit respectively. This is great I succeed in login to gerrit using

Re: [opensc-devel] Moving master forward

2011-12-14 Thread Alon Bar-Lev
On Wed, Dec 14, 2011 at 8:41 PM, Martin Paljak mar...@martinpaljak.net wrote: On 12/14/11 5:13 , Alon Bar-Lev wrote: This is great I succeed in login to gerrit using google account. How do I login to jenkins? Actually there is no similar SSO readily available for Jenkins, nor should

Re: [opensc-devel] Moving master forward

2011-12-14 Thread Alon Bar-Lev
On Thu, Dec 15, 2011 at 1:41 AM, Alon Bar-Lev alon.bar...@gmail.com wrote: On Wed, Dec 14, 2011 at 8:41 PM, Martin Paljak mar...@martinpaljak.net wrote: On 12/14/11 5:13 , Alon Bar-Lev wrote: This is great I succeed in login to gerrit using google account. How do I login to jenkins

Re: [opensc-devel] Moving master forward

2011-12-14 Thread Alon Bar-Lev
On Thu, Dec 15, 2011 at 9:43 AM, Martin Paljak mar...@martinpaljak.net wrote: On 15/12/11 01:43, Alon Bar-Lev wrote: Oh... I was so excited I missed some important issue. When submitting a patchset it should be tested for build as atomic unit. Currently the system tries to compile each

Re: [opensc-devel] Moving master forward

2011-12-10 Thread Alon Bar-Lev
On Sat, Dec 10, 2011 at 10:39 AM, Peter Stuge pe...@stuge.se wrote: Ludovic Rousseau wrote: Can you set up standard ports so it passes firewalls? First choice: http / https Same question but to pass web proxies. git and ssh ports are not even available in some places. Note that Gerrit

Re: [opensc-devel] Moving master forward

2011-12-09 Thread Alon Bar-Lev
Can you set up standard ports so it passes firewalls? First choice: http / https Second choice: git/ssh On Thu, Dec 8, 2011 at 9:32 PM, Martin Paljak mar...@martinpaljak.net wrote: Hello, Here is an overview of updates to opensc-project.org plumbing and Git. * Jenkins (build master) has been

[opensc-devel] [PATCH 0/5] Remove libltdl

2011-12-09 Thread Alon Bar-Lev
on Gentoo tree at least that uses ltdl. I tested building on Linux, mingw64. Untested MSVC, martin, you have the environment, right? Signed-off-by: Alon Bar-Lev alon.bar...@gmail.com ___ opensc-devel mailing list opensc-devel@lists.opensc-project.org http

[opensc-devel] [PATCH 3/5] Remove libltdl: Use libscdl

2011-12-09 Thread Alon Bar-Lev
Signed-off-by: Alon Bar-Lev alon.bar...@gmail.com --- src/common/Makefile.am |3 +-- src/libopensc/Makefile.am|1 + src/libopensc/ctx.c |1 + src/libopensc/internal.h |1 - src/libopensc/pkcs15-syn.c |1 + src/libopensc/pkcs15.c |1 + src

[opensc-devel] [PATCH 4/5] Remove libltdl: Cleanup libscdl

2011-12-09 Thread Alon Bar-Lev
Signed-off-by: Alon Bar-Lev alon.bar...@gmail.com --- src/common/libscdl.c |9 ++--- src/common/libscdl.h |3 +++ 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/src/common/libscdl.c b/src/common/libscdl.c index e4746ab..b66dbd5 100644 --- a/src/common/libscdl.c +++ b

[opensc-devel] [PATCH 1/5] Remove libltdl: Remove ltld references

2011-12-09 Thread Alon Bar-Lev
Signed-off-by: Alon Bar-Lev alon.bar...@gmail.com --- configure.ac | 18 -- src/common/Makefile.am |1 - src/common/libpkcs11.c |6 src/common/libscdl.c | 57 +-- src/libopensc/Makefile.am |5

Re: [opensc-devel] how can I retrieve private key by using pkcs11-helper api?

2011-11-10 Thread Alon Bar-Lev
Hello, You can't. pkcs11-helper targets developers who want to use smartcards without overhead of the actual card management. Well behaved smartcards should not allow export of private key. Why do you need the private key anyway? Alon. On Thu, Nov 10, 2011 at 3:27 AM, weizhong qiang

Re: [opensc-devel] how can I retrieve private key by using pkcs11-helper api?

2011-11-10 Thread Alon Bar-Lev
, weizhong qiang weizhongqi...@gmail.com wrote: hi Alon, On Nov 10, 2011, at 8:24 AM, Alon Bar-Lev wrote: Hello, You can't. pkcs11-helper targets developers who want to use smartcards without overhead of the actual card management. Well behaved smartcards should not allow export of private key

Re: [opensc-devel] About OpenSC PKCS#11

2011-11-10 Thread Alon Bar-Lev
On Wed, Nov 9, 2011 at 7:39 PM, Viktor Tarasov viktor.tara...@gmail.com wrote: Hello, I would like to 'touch' the PKCS#11 module of OpenSC and looking for your opinions/suggestions about: - removing of 'pkcs15init' framework; - configurable support of the multi on-card applications and

Re: [opensc-devel] how can I retrieve private key by using pkcs11-helper api?

2011-11-10 Thread Alon Bar-Lev
On Thu, Nov 10, 2011 at 2:08 PM, weizhong qiang weizhongqi...@gmail.com wrote: OpenSSL is fully compatible with this approach, having RSA object that can be used for crypto operation without actually having the private key. This is done via the concept of engine which delegate the crypto calls

Re: [opensc-devel] how can I retrieve private key by using pkcs11-helper api?

2011-11-10 Thread Alon Bar-Lev
On Thu, Nov 10, 2011 at 3:10 PM, weizhong qiang weizhongqi...@gmail.com wrote: hi Alon, Sorry that I make you be confused. On Nov 10, 2011, at 1:20 PM, Alon Bar-Lev wrote: On Thu, Nov 10, 2011 at 2:08 PM, weizhong qiang weizhongqi...@gmail.com wrote: OpenSSL is fully compatible

Re: [opensc-devel] how can I retrieve private key by using pkcs11-helper api?

2011-11-10 Thread Alon Bar-Lev
On Thu, Nov 10, 2011 at 5:12 PM, weizhong qiang weizhongqi...@gmail.com wrote: On Nov 10, 2011, at 3:40 PM, Alon Bar-Lev wrote: On Thu, Nov 10, 2011 at 4:06 PM, weizhong qiang weizhongqi...@gmail.com wrote: As I mentioned that I need to use EEC credential to generate a proxy credential

Re: [opensc-devel] Problems with opensc+openvpn builds from Alon starting v10

2011-10-19 Thread Alon Bar-Lev
...@reebs.org wrote: Hello Gents, just enquiring for a feedback. did you find something out on this issue? Seems something was brocken in never OpenSC / OpenVPN... Rgds, PR On Mon, 3 Oct 2011 15:09:28 +0200, Alon Bar-Lev alon.bar...@gmail.com wrote: Martin, I need your help here... On Fri

Re: [opensc-devel] Problems with opensc+openvpn builds from Alon starting v10

2011-10-03 Thread Alon Bar-Lev
          : 3f0050154545        ID             : 45        Encoded serial : 02 01 02 C:\Program Files\OpenVPN\share\openvpn-win32\config On Fri, 30 Sep 2011 18:45:31 +0300, Alon Bar-Lev alon.bar...@gmail.com wrote: --- 2011-09-30 12:05:15.330 [opensc-pkcs11] iso7816.c:103:iso7816_check_sw

Re: [opensc-devel] Problems with opensc+openvpn builds from Alon starting v10

2011-09-29 Thread Alon Bar-Lev
us=796000 ERROR: could not not read OpenSC Card (xxx yyy) token password from stdin Wed Sep 28 17:51:25 2011 us=796000 Exiting Wed Sep 28 17:51:25 2011 us=796000 Closing Win32 semaphore 'openvpn_netcmd' On Wed, 28 Sep 2011 18:30:14 +0300, Alon Bar-Lev alon.bar...@gmail.com wrote: set verb 255

Re: [opensc-devel] Problems with opensc+openvpn builds from Alon starting v10

2011-09-29 Thread Alon Bar-Lev
, it asks twice for the PIN, for the second and following connection attempts (I aborded here not to loose start of log because of buffer limitations) it asks only once... On Thu, 29 Sep 2011 21:13:52 +0300, Alon Bar-Lev alon.bar...@gmail.com wrote: This is strange. The signature just fails I need

Re: [opensc-devel] Problems with opensc+openvpn builds from Alon starting v10

2011-09-28 Thread Alon Bar-Lev
, On Wed, 28 Sep 2011 15:40:00 +0300, Alon Bar-Lev alon.bar...@gmail.com wrote: Use build-011 On Wed, Sep 28, 2011 at 1:39 PM, busin...@reebs.org wrote: Hi All, any clue what is wrong?! :( Rgds On Sun, 25 Sep 2011 18:38:39 +0200, busin...@reebs.org wrote: Hello All, Currently I am having

Re: [opensc-devel] Problems with opensc+openvpn builds from Alon starting v10

2011-09-28 Thread Alon Bar-Lev
Use build-011 On Wed, Sep 28, 2011 at 1:39 PM, busin...@reebs.org wrote: Hi All, any clue what is wrong?! :( Rgds On Sun, 25 Sep 2011 18:38:39 +0200, busin...@reebs.org wrote: Hello All, Currently I am having troubles to get the latest build (32bit) of prebuild

Re: [opensc-devel] Problems with opensc+openvpn builds from Alon starting v10

2011-09-28 Thread Alon Bar-Lev
2011 TLS Error: TLS object - incoming plaintext read error Wed Sep 28 16:04:07 2011 TLS Error: TLS handshake failed On Wed, 28 Sep 2011 16:04:24 +0300, Alon Bar-Lev alon.bar...@gmail.com wrote: Now? On Wed, Sep 28, 2011 at 4:01 PM,  busin...@reebs.org wrote: Alon, I believe

Re: [opensc-devel] PIN caching problems with pkcs11-helper 1.08

2011-08-16 Thread Alon Bar-Lev
Thanks for your report and testing! 2011/8/16 Jonatan Åkerlind jonatan.akerl...@sgsstudentbostader.se: On fre, 2011-08-12 at 23:20 +0300, Alon Bar-Lev wrote: Jonatan, Can you please try the attached patch and see if it helps? Thanks! ... seems to work fine, will continue testing during

[opensc-devel] pkcs11-helper-1.09 released

2011-08-16 Thread Alon Bar-Lev
Hello, pkcs11-helper-1.09 is available. Fixed issue introduced in 1.08 related to OpenSSL engine signature. ChangeLog 2011-08-16 - Version 1.09 * Do not retry if CKR_BUFFER_TOO_SMALL and none NULL target. * Fixup OpenSSL engine's rsa_priv_enc to use RSA size output buffer.

Re: [opensc-devel] Integrating p11-kit into pkcs11-helper?

2011-08-15 Thread Alon Bar-Lev
So Stef, How do you want to proceed? On Thu, Aug 4, 2011 at 7:58 PM, Alon Bar-Lev alon.bar...@gmail.com wrote: 2011/8/4 Jean-Michel Pouré - GOOZE jmpo...@gooze.eu: Le lundi 01 août 2011 à 14:11 +0200, Stef Walter a écrit :  * Initializing modules via p11-kit so that refcounting

Re: [opensc-devel] Rationale for Microsoft's MiniDriver

2011-08-14 Thread Alon Bar-Lev
There had been always unified API: PKCS#11. Well, at Microsoft environment there was CryptoAPI Provider. The good about the CryptoAPI is that it allowed enough flexibility so that, for example, you could have created a generic CryptoAPI provider on-top of PKCS#11. In the MiniDriver, Microsoft

Re: [opensc-devel] PIN caching problems with pkcs11-helper 1.08

2011-08-12 Thread Alon Bar-Lev
Jonatan, Can you please try the attached patch and see if it helps? Thanks! On Thu, Aug 11, 2011 at 11:20 AM, Alon Bar-Lev alon.bar...@gmail.com wrote: Martin, The openssl engine is called with 0x24 buffer size and expect it to be encrypted by private key with same length. Prototype

Re: [opensc-devel] Integrating p11-kit into pkcs11-helper?

2011-08-04 Thread Alon Bar-Lev
Hello Stef, I think that each project is targeting a different set of problems. I am fully opened for discussion, but this is how I see things: pkcs11-helper targets developers who like to introduce PKCS#11 into their application, especially for smartcard. It allows to minimize the user

Re: [opensc-devel] Integrating p11-kit into pkcs11-helper?

2011-08-04 Thread Alon Bar-Lev
2011/8/4 Jean-Michel Pouré - GOOZE jmpo...@gooze.eu: Le lundi 01 août 2011 à 14:11 +0200, Stef Walter a écrit :  * Initializing modules via p11-kit so that refcounting, and    pInitArgs stuff works if more than one app/library in the    same process uses a PKCS#11 module.  * Safe forking

Re: [opensc-devel] Patch for libp11 to fix compatibility with AET SafeSign PKCS#11 library

2011-06-17 Thread Alon Bar-Lev
Right. But you forgot to free the memory. I've applied similar solution at r201. On Fri, Jun 17, 2011 at 2:55 PM, Jonathan Giannuzzi jonat...@giannuzzi.be wrote: Hello, When using libp11 to wrap around the AET SafeSign PKCS#11 library, C_GetInfo fails with CKR_MUTEX_BAD. This is because an

Re: [opensc-devel] [opensc-commits] svn opensc changed[5567] pkcs11: framework-pkcs15: OpenSC specific ' non-repudiation' cryptoki attribute ...

2011-06-16 Thread Alon Bar-Lev
OK. I think we have all facts. Thanks. On Thu, Jun 16, 2011 at 1:14 PM, Martin Paljak mar...@martinpaljak.net wrote: Hello, On Wed, Jun 15, 2011 at 14:28, Alon Bar-Lev alon.bar...@gmail.com wrote: On Wed, Jun 15, 2011 at 2:05 PM, Martin Paljak mar...@martinpaljak.net wrote: Given

Re: [opensc-devel] Git build status.

2011-06-09 Thread Alon Bar-Lev
On Thu, Jun 9, 2011 at 10:33 AM, Martin Paljak mar...@martinpaljak.net wrote: On Jun 8, 2011, at 21:12 , Alon Bar-Lev wrote: On Wed, Jun 8, 2011 at 2:18 PM, Martin Paljak mar...@martinpaljak.net wrote: Trac sends emails about new tickets, can you convert that into RSS? RSS has *always

Re: [opensc-devel] Static link for opensc-pkcs11.dll

2011-05-28 Thread Alon Bar-Lev
This is only for MSC build, not for mingw. But as this project is going to MSC release anyway... On Sat, May 28, 2011 at 11:07 PM, Viktor Tarasov viktor.tara...@gmail.com wrote: Hello, I would like to link statically the PKCS#11 module for Windows, or at least to include the static version

Re: [opensc-devel] [opensc-commits] svn opensc changed[5447] pkcs11-tool: move --module to the first position in help text and make it mandatory.

2011-05-17 Thread Alon Bar-Lev
This will break many of people's usages. Until now it was assumed that if --module is not specified the opensc provider is loaded. And as pkcs11-tool is part of opensc, I know many who did not specify this. I know that something was broken recently with finding the default module, however, do you

Re: [opensc-devel] Bug in engine_pkcs11

2011-05-10 Thread Alon Bar-Lev
On Tue, May 10, 2011 at 1:18 PM, Giuliano Bertoletti g...@symbolic.it wrote: I pointed out the slot_id matter instead because it is just wrong to start from the assumption that the user knows it and it won't change between multiple executions. Same for index. Sorry, I still cannot see your

Re: [opensc-devel] Bug in engine_pkcs11

2011-05-10 Thread Alon Bar-Lev
Use this[1] to build using cross compiler. [1] https://www.opensc-project.org/build On Tue, May 10, 2011 at 10:36 AM, Giuliano Bertoletti g...@symbolic.it wrote: Hello, unfortunatelly I'm still fighting with the compiler to rebuild the engine_pkcs11 library (under Windows / Mingw or Visual

Re: [opensc-devel] Bug in engine_pkcs11

2011-05-09 Thread Alon Bar-Lev
This is a matter of interpretation. Either is not constant and user is not suppose to know of. Apart of the special case of having a single slot, so you expect 0 I presume. You can check which slot is what simply by using: pkcs11-tool --list-slots --module /usr/lib/pkcs11/ On Mon, May 9, 2011

Re: [opensc-devel] OpenSC shared mode

2011-05-07 Thread Alon Bar-Lev
1. Firefox behaves correctly, it opens long living session with crypto token, in order to reduce the number of times user is prompted for passphrase. 2. Firefox monitors slots, to be able to detect new certificate availability so it can prompt the user for one if requested. It is true that it can

Re: [opensc-devel] OpenSC shared mode

2011-05-07 Thread Alon Bar-Lev
On Sat, May 7, 2011 at 10:57 PM, Peter Stuge pe...@stuge.se wrote: Alon Bar-Lev wrote: However, there are some advanced cards that can generate authentication token, so you can actually authenticate once using PIN get authentication token out of the card (many can be available at same time

Re: [opensc-devel] OpenSC shared mode

2011-05-06 Thread Alon Bar-Lev
-project.org/mailman/private/opensc-internal/2008-June/000335.html Discussion with Nils 5/2008, a prototype option, we agreed this is fundemental problem of the project, but neither had resources to actually solve it. Regards, Alon Bar-Lev. ___ opensc-devel

Re: [opensc-devel] usb p11 token

2011-04-26 Thread Alon Bar-Lev
On Tue, Apr 26, 2011 at 1:23 PM, Peter Stuge pe...@stuge.se wrote: Alon Bar-Lev wrote: it would be better to emulate some standard interface, such as serial over USB. Absolutely not. I would not dismiss this entirely... Serial over USB has the advantage to work on all modern operating

Re: [opensc-devel] usb p11 token

2011-04-26 Thread Alon Bar-Lev
) with the PKCS#11 forwarding features built-in. Just a though... but any implementation will do. [1] http://www.mail-archive.com/opensc-devel@lists.opensc-project.org/msg01733.html On Tue, Apr 26, 2011 at 3:44 PM, NdK ndk.cla...@gmail.com wrote: Il 26/04/2011 11:28, Alon Bar-Lev ha scritto: Since

Re: [opensc-devel] Broadcom 5880 in openct.conf

2011-04-25 Thread Alon Bar-Lev
Although I am in favor of improving openct, I agree with Martin in this case. The most CCID compliant library we have is libccid, first work out the problem with libccid. It may be that openct's CCID implementation works for you as it much simpler and use smaller set of features. On Mon, Apr 25,

Re: [opensc-devel] make maintainer-clean patch

2011-04-25 Thread Alon Bar-Lev
Applied. Thanks. On Mon, Apr 25, 2011 at 12:39 PM, jons...@terra.es jons...@terra.es wrote: Seems that make maintainer-clean forgets to delete trunk/MacOSX/Makefile.in file This patch does the work: --- ../trunk/MacOSX/Makefile.am    2011-04-21 11:33:09.0 +0200 +++

Re: [opensc-devel] OpenCT source repository

2011-04-23 Thread Alon Bar-Lev
Should be same as opensc just openct. On 4/22/11, Stef Walter st...@collabora.co.uk wrote: Hi guys, Is there an openct git repository somewhere? I couldn't find it at the 'Subversion Repository' page [1] I'm fiddling with my Broadcom 5880 smart card reader, and want to whip up a small patch.

Re: [opensc-devel] Compiling for windows in Fedora 14

2011-03-31 Thread Alon Bar-Lev
On Thu, Mar 31, 2011 at 1:34 PM, Martin Paljak mar...@martinpaljak.net wrote: 2- In building process an strip error found: - i686-pc-mingw32-strip: unable to copy file '/home/jantonio/work/dnie/opendnie/opensc-opendnie/trunk/win32/build/image/opensc/lib/engines/gosteay32.dll';

Re: [opensc-devel] [opensc-commits] svn build changed[112] Update openvpn patch

2011-03-08 Thread Alon Bar-Lev
To be able to built it using a cross compiler. Submitted to upstream several times. 2011/3/8 Jean-Michel Pouré - GOOZE jmpo...@gooze.eu: Le vendredi 04 mars 2011 à 21:02 +, webmas...@opensc-project.org a écrit : trunk/patches/openvpn-001-windows.patch Sorry to ask a silly question, but

Re: [opensc-devel] pkcs11-helper and pkcs11h_logout

2011-02-23 Thread Alon Bar-Lev
OK. Thanks. I added similar solution. On Wed, Feb 23, 2011 at 12:41 PM, Jan Just Keijser janj...@nikhef.nl wrote: hi all, there's an OpenVPN bug report that is traced back to an issue with pkcs11h_logout; it seems that if you call this function before initializing the pkcs11 libs then it

Re: [opensc-devel] pkcs11-helper and pkcs11h_logout

2011-02-23 Thread Alon Bar-Lev
Today? On Wed, Feb 23, 2011 at 1:32 PM, Jan Just Keijser janj...@nikhef.nl wrote: Alon Bar-Lev wrote: OK. Thanks. I added similar solution. Excellent, thanks. Any idea when the next version of pkcs11-helper is released? cheers, JJK / Jan Just Keijser On Wed, Feb 23, 2011 at 12:41

Re: [opensc-devel] pkcs11-helper and pkcs11h_logout

2011-02-23 Thread Alon Bar-Lev
OK. Released. Please test, there was a change in the usage of openssl engine. On Wed, Feb 23, 2011 at 1:45 PM, Jan Just Keijser janj...@nikhef.nl wrote: Alon Bar-Lev wrote: Today? Wow - that is far quicker than I expected. Again, many thanks for such a quick response. cheers, JJK

Re: [opensc-devel] Building cardmod Mindriver using Build environment

2011-01-14 Thread Alon Bar-Lev
At build script there is a comment: # Disable until we solve license issue # if [ -n ${BUILD_FOR_WINDOWS} ]; then # extra_opensc=${extra_opensc} --enable-cardmod # fi I have modified cardmod.h to meet mingw, but was remove at revision 101 due to license issue.

Re: [opensc-devel] Building cardmod Mindriver using Build environment

2011-01-14 Thread Alon Bar-Lev
2011/1/14 Douglas E. Engert deeng...@anl.gov: If the license issues can not be addressed, then maybe cardmod could be built as a separate package by the user. On perfect world, it would have been possible to write cardmod that uses PKCS#11 interface, to enable any PKCS#11 provider to be used by

Re: [opensc-devel] [opensc-commits] svn opensc changed[4776] Don't dump wiki content into distribution package.

2010-10-05 Thread Alon Bar-Lev
Martin, Waiting for your decision. On Mon, Sep 27, 2010 at 1:34 PM, Alon Bar-Lev alon.bar...@gmail.com wrote: On Mon, Sep 27, 2010 at 1:07 PM, Martin Paljak mar...@paljak.pri.ee wrote: But... the only dependency we require is xsltproc, so maybe we can rethink this... Provided you agree

Re: [opensc-devel] [opensc-commits] svn opensc changed[4776] Don't dump wiki content into distribution package.

2010-10-05 Thread Alon Bar-Lev
On Tue, Oct 5, 2010 at 7:12 PM, Martin Paljak mar...@paljak.pri.ee wrote: Personally I don't mind simplicity in build files. 99% of people run binaries or packages, 99% of people who don't run binary packages on Linux know what they are doing. Or won't mind downloading an extra few packages

Re: [opensc-devel] [opensc-commits] svn opensc changed[4776] Don't dump wiki content into distribution package.

2010-09-27 Thread Alon Bar-Lev
On Mon, Sep 27, 2010 at 7:52 AM, Martin Paljak mar...@paljak.pri.ee wrote: But it is working correctly, that patch was incorrect. Leaving the possible changed logic for ChangeLog generation aside, what was incorrect in that patch? The changes in the docs, exactly what you request next.

Re: [opensc-devel] [opensc-commits] svn opensc changed[4776] Don't dump wiki content into distribution package.

2010-09-27 Thread Alon Bar-Lev
On Mon, Sep 27, 2010 at 12:34 PM, Martin Paljak mar...@paljak.pri.ee wrote: Does this actually break anything in real life, other than make distcheck? Yes. Whatever broken during distcheck will probably break somewhere. Major check of distcheck is separate build directory, this is used by many

Re: [opensc-devel] [opensc-commits] svn opensc changed[4776] Don't dump wiki content into distribution package.

2010-09-27 Thread Alon Bar-Lev
On Mon, Sep 27, 2010 at 1:07 PM, Martin Paljak mar...@paljak.pri.ee wrote: But... the only dependency we require is xsltproc, so maybe we can rethink this... Provided you agree that building the package with --enable-doc or --enable-man requires xsltproc available on build machine, we can

Re: [opensc-devel] [opensc-commits] svn opensc changed[4776] Don't dump wiki content into distribution package.

2010-09-26 Thread Alon Bar-Lev
On Sun, Sep 26, 2010 at 11:51 PM, Martin Paljak mar...@paljak.pri.ee wrote: But this does not remove the api.out/api.tmp/api.work voodoo, what was one of my goals and what caused problems in my original change patch. I knew only the goal was to remove the wiki stuff... Can you explain why do

Re: [opensc-devel] [opensc-commits] svn opensc changed[4776] Don't dump wiki content into distribution package.

2010-09-26 Thread Alon Bar-Lev
On Mon, Sep 27, 2010 at 7:15 AM, Martin Paljak mar...@paljak.pri.ee wrote: On Sep 27, 2010, at 1:42 AM, Alon Bar-Lev wrote: On Sun, Sep 26, 2010 at 11:51 PM, Martin Paljak mar...@paljak.pri.ee wrote: But this does not remove the api.out/api.tmp/api.work voodoo, what was one of my goals

Re: [opensc-devel] Don't dump wiki content into distribution package.

2010-09-25 Thread Alon Bar-Lev
We discussed this a few years ago. Building a package should not access the web. Once you checkout a fresh checkout, you should be able to build distribution tarball even if you have no access to internet. What I recommended, and still am, is to split the tarballs into two.

Re: [opensc-devel] OpenSSL 1.0 on windows

2010-09-14 Thread Alon Bar-Lev
What was the problem? We should report this to upstream... 0.9.8 does not support cross compile so it is unusable unless building differently. But better help fixing openssl. On Tue, Sep 14, 2010 at 7:59 PM, Andreas Jellinghaus a...@dungeon.inka.de wrote: I got very bad results with OpenSSL

Re: [opensc-devel] OpenSC 0.12.0 windows installer = 64bit?

2010-09-13 Thread Alon Bar-Lev
I try to compile now. 2010/9/13 Jean-Michel Pouré - GOOZE jmpo...@gooze.eu Based on Google, visitors to opensc-project.org consist of ~60% Windows users, ~30% Linux users and ~10% Mac OS X users (57%, 27%, 12%), which is not a scientific fact or result of a study, but still shows

Re: [opensc-devel] OpenSC 0.12.0 windows installer = 64bit?

2010-09-13 Thread Alon Bar-Lev
Is opensc-0.12 released? Or should I use trunk? On Mon, Sep 13, 2010 at 4:40 PM, Alon Bar-Lev alon.bar...@gmail.com wrote: I try to compile now. 2010/9/13 Jean-Michel Pouré - GOOZE jmpo...@gooze.eu Based on Google, visitors to opensc-project.org consist of ~60% Windows users, ~30% Linux

Re: [opensc-devel] OpenSC 0.12.0 windows installer = 64bit?

2010-09-13 Thread Alon Bar-Lev
OK. I have the images, hope it is working. But using the svn to upload these takes forever, if someone has ssh account somewhere I will send it to him much quickly. On Mon, Sep 13, 2010 at 5:20 PM, Martin Paljak mar...@martinpaljak.net wrote: On Sep 13, 2010, at 6:02 PM, Alon Bar-Lev wrote

Re: [opensc-devel] OpenSC 0.12.0 windows installer = 64bit?

2010-09-13 Thread Alon Bar-Lev
Available: http://www.opensc-project.org/downloads/users/alonbl/temp/opensc-i686-w64-mingw32-010-setup.exe http://www.opensc-project.org/downloads/users/alonbl/temp/opensc-x86_64-w64-mingw32-010-setup.exe On Mon, Sep 13, 2010 at 6:45 PM, Alon Bar-Lev alon.bar...@gmail.com wrote: OK. I have

Re: [opensc-devel] Encoding of CKA_SERIAL_NUMBER

2010-05-24 Thread Alon Bar-Lev
Yes, good catch. But I don't know any application that actually uses this attribute... :) On Mon, May 24, 2010 at 8:05 PM, Viktor TARASOV viktor.tara...@opentrust.com wrote: Hello, according to PKCS#11 specification the CKA_SERIAL_NUMBER is DER-encoded value. Actually OpenSC PKCS#11 module

Re: [opensc-devel] [opensc-commits] svn opensc changed[4359] pkcs11: by default do not lock login

2010-05-19 Thread Alon Bar-Lev
For a security product, I don't think it is wise to have default of none secure behavior, especially such that allows everyone to use the private objects once authenticated. On Wed, May 19, 2010 at 11:17 AM, webmas...@opensc-project.org wrote: Revision: 4359 Author:   viktor.tarasov Date:    

Re: [opensc-devel] openct windows

2010-05-12 Thread Alon Bar-Lev
It cannot run under Windows. It is harder to access USB devices under Windows... But it should be somewhat simple to port it with serial port only. On Wed, May 12, 2010 at 12:03 PM, Bart Vanherck b...@twixel.be wrote: Hello, Can openct be run on windows ? How to build with for example mingw ?

Re: [opensc-devel] [opensc-commits] svn opensc changed[4268] tools: thanks to Andreas; for win32 'get password' procedure uses _getch() instead of getchar()

2010-04-28 Thread Alon Bar-Lev
And what about ./src/common/compat_getpass.c do we still need it? On Tue, Apr 27, 2010 at 10:53 AM, Viktor TARASOV viktor.tara...@opentrust.com wrote: Alon Bar-Lev wrote: Shouldn't you include conio.h? Agree, 'it worked for me' compiled with Visual Studio 8.0, and I missed it. On Tue

Re: [opensc-devel] [opensc-commits] svn opensc changed[4268] tools: thanks to Andreas; for win32 'get password' procedure uses _getch() instead of getchar()

2010-04-27 Thread Alon Bar-Lev
Shouldn't you include conio.h? On Tue, Apr 27, 2010 at 10:30 AM, webmas...@opensc-project.org wrote: Revision: 4268 Author:   viktor.tarasov Date:     2010-04-27 07:30:38 + (Tue, 27 Apr 2010) Log Message: --- tools: thanks to Andreas; for win32 'get password' procedure uses

Re: [opensc-devel] Compilation error

2010-04-14 Thread Alon Bar-Lev
You compiling with openct while not have openct on your system? 2010/4/14 Jean-Michel Pouré - GOOZE jmpo...@gooze.eu: Dear friends, There seems to be a small compilation error in latest SVN sources: make[2]: Entering directory `/home/jmpoure/logiciels/opensc/opensc/src/libopensc' /bin/bash

Re: [opensc-devel] New project coordinator: Martin Paljak

2010-04-13 Thread Alon Bar-Lev
On Mon, Apr 12, 2010 at 1:59 PM, Martin Paljak mar...@paljak.pri.ee wrote: My main goals and improvement areas in OpenSC are: snip 1. Make OpenSC secured? The fact that OpenSC locks the reader for its own use for the duration of the session is the most critical issue OpenSC has. As a result

Re: [opensc-devel] New project coordinator: Martin Paljak

2010-04-11 Thread Alon Bar-Lev
Thank you for your efforts in the past years! Good luck Martin! On Sun, Apr 11, 2010 at 9:48 AM, Andreas Jellinghaus a...@dungeon.inka.de wrote: Dear all, for several years I have coordinated the OpenSC, OpenCT, Libp11, Pam_p11 and Engine_PKCS11 projects: Created new releases, fixed some

Re: [opensc-devel] OpenSC experimental installer ?

2010-04-01 Thread Alon Bar-Lev
Now? 2010/4/1 Jean-Michel Pouré - GOOZE jmpo...@gooze.eu: On Thu, 2010-04-01 at 07:25 +0300, Alon Bar-Lev wrote: [1] http://www.opensc-project.org/downloads/users/alonbl/temp/ Forbidden You don't have permission to access /downloads/users/alonbl/temp/opensc-i686-w64-mingw32-010-setup.exe

  1   2   3   4   5   >