Re: [Openvpn-devel] Smartcard Authentication

2007-05-22 Thread Alon Bar-Lev
On 5/22/07, Thomas Glanzmann wrote: Actually I don't consider PKCS#11 a standard interface. It's more like everyone puts its binary blob anywhere. Actually I think it's horrible by design. It's more like a "standard" interface to a binary blob that does something that isn't standard with the act

Re: [Openvpn-devel] Smartcard Authentication

2007-05-21 Thread Alon Bar-Lev
On 5/21/07, sithg...@stud.uni-erlangen.de wrote: Note: It isn't enough to have a private/public key on the card. You also need a certificate. The certificate can be self signed. It doesn't matter. If there is _no_ certificate ssh-agent refuses to add it. Don't ask me why. Markus, can you answer

Re: [Openvpn-devel] Smartcard Authentication

2007-05-21 Thread Peter Warasin
hi Alon Bar-Lev wrote: > On 5/21/07, sithg...@stud.uni-erlangen.de > wrote: > How do you use with OpenSSH? > I recommend of using PKCS#11 as well. > http://alon.barlev.googlepages.com/openssh-pkcs11 also consider reading openvpn smartcard howto which has been posted here on the list short time

Re: [Openvpn-devel] Smartcard Authentication

2007-05-20 Thread sithglan
Hello Alon, > How do you use with OpenSSH? I am using Debian etch. I typed in apt-get source openssh edited debian/rules and added "--with-opensc=/usr" after that I build new debian packages using "fakeroot debian/rules binary". I installed corresponding packages. Note: It isn't enough

Re: [Openvpn-devel] Smartcard Authentication

2007-05-20 Thread Alon Bar-Lev
On 5/21/07, sithg...@stud.uni-erlangen.de wrote: I got ssh-agent also working. At the moment I am only able to use 1024 bit RSA keys under Linux. ssh-agent and openvpn doesn't work at the same time. :-( It seems that OpenVPN keeps the connection open and blocks ssh-agent from doing anything with

Re: [Openvpn-devel] Smartcard Authentication

2007-05-20 Thread sithglan
Hello Jochen, > Just visit me in my office on friday morning and I can handover you > one or two for a test. :-) ) thanks a lot for the offer. I used one of your tokens under Linux with openct and opensc/openct. Tomorrow I am going to do a few tests with Windows. Linux: apt-get install opensc op

Re: [Openvpn-devel] Smartcard Authentication

2007-05-16 Thread Alon Bar-Lev
You can mix software and hardware based in one installation. If you are going to use Linux, I recommend you use one of the OpenSC supported cards. On 5/16/07, sithg...@stud.uni-erlangen.de wrote: Hello, I am incredible interested in the smartcard authentication for OpenVPN. Can anyone suggest a

Re: [Openvpn-devel] Smartcard Authentication

2007-05-16 Thread Jochen Kaiser
Hi Thomas, two weeks ago, I purchased 10 Aladdin eToken Pro32K 10 Unit Starter pack for a total of 760 Euro. Afaik they should work for linux. (I've 10 of them but I don't need all of them at the moment. Just visit me in my office on friday morning and I can handover you one or two for a test.