Gentoo Archives: gentoo-hardened

From: Daniel Struck <community@××××××.lu>
To: gentoo-hardened@g.o
Subject: [gentoo-hardened] smartcards: apache & openssl - internet explorer / mozilla
Date: Tue, 26 Aug 2003 11:14:42
Message-Id: 20030826131041.1c23ecc4.community@struck.lu
1 Hello,
2
3 I am a little bit puzzled how to solve what I try to do:
4
5 Idea: Clients should be authenticated to apache over openssl by a client-certificate.
6 I got it working on gentoo without a problem, well after applying a patch provided on bugs.gentoo.org (bug 25258) ;-)
7
8 Now I want to put the client-certificates on smartcards, problem:
9 I don't know yet how to do this :-(
10
11 My basic understanding is that, the key (private&public) is generated on the smartcard, then the public key? is send out to be signed by a CA.
12 I think on Windows this steps are performed by Internet Explorer by contacting a CA.
13
14 My question: Is it possible to prepare the smartcards for the clients on a gentoo station and how should one proceed to do it?
15 (I think opensc with muscle-driver could provide this fonctionality?)
16
17 Does anyone by chance know good documentations/ books on this subject?
18
19 Best regards,
20 Daniel Struck
21
22
23
24 --
25 gentoo-hardened@g.o mailing list