Re: APR with PKCS11 support

2014-12-01 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sanaullah, On 12/1/14 6:09 AM, Sanaullah wrote: > I have attached the diff [that allows external crypto decides to > be used via tcnative). let me know if its ok? For reference, here's the diff: > > 304c304 < #if 1 //HAVE_ENGINE_LOAD_BUILTIN_ENGI

Re: APR with PKCS11 support

2014-12-01 Thread Sanaullah
Hi Chris, I have attached the diff.let me know if its ok? Regards, Sanaullah On Fri, Nov 21, 2014 at 2:08 AM, Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Sanaullah, > > On 11/18/14 10:26 PM, Sanaullah wrote: > > Hi Chris, >

Re: APR with PKCS11 support

2014-11-20 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sanaullah, On 11/18/14 10:26 PM, Sanaullah wrote: > Hi Chris, > > Engine is loaded Successfully. the issue is with tcnative. > tcnative was not loading any engine and it was due to > HAVE_ENGINE_LOAD_BUILTIN_ENGINES preprocessor which is unable to

Re: APR with PKCS11 support

2014-11-18 Thread Sanaullah
Hi Chris, Engine is loaded Successfully. the issue is with tcnative. tcnative was not loading any engine and it was due to HAVE_ENGINE_LOAD_BUILTIN_ENGINES preprocessor which is unable to call ENGINE_load_builtin_engines. I made one change and in ssl.c of tomcat-native-1.1.31 original Preprocess

Re: APR with PKCS11 support

2014-11-18 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sanaullah, On 11/14/14 10:04 PM, Sanaullah wrote: > The Engine name is correct its "LunaCA3" Here is the code snippet > from the openssl for the confirmation. > > openssl-1.0.1g/engines/e_lunaca3.c:#define ENGINE_LUNACA3_ID > "LunaCA3" > > I thi

Re: APR with PKCS11 support

2014-11-14 Thread Sanaullah
Hi Chris, The Engine name is correct its "LunaCA3" Here is the code snippet from the openssl for the confirmation. openssl-1.0.1g/engines/e_lunaca3.c:#define ENGINE_LUNACA3_ID "LunaCA3" I think the issue is with static and shared libraries of openssl. if openssl build as shared then this LunaCA

Re: APR with PKCS11 support

2014-11-14 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sanaullah, On 10/29/14 9:54 AM, Sanaullah wrote: > I again started working on SSLEngine with safenet and i need some > help, how to enable the debugging? I configure the engine as > "LunaCA3". > > SSLEngine="LunaCA3" /> > > Here is error log afte

Re: APR with PKCS11 support

2014-10-29 Thread Sanaullah
I again started working on SSLEngine with safenet and i need some help, how to enable the debugging? I configure the engine as "LunaCA3". Here is error log after starting the server. Oct 29, 2014 1:40:21 PM org.apache.catalina.core.AprLifecycleListener init INFO: Loaded APR based Apache Tomcat

Re: APR with PKCS11 support

2014-08-25 Thread Sanaullah
Hi Chris, did you get any chance to take a look into the issue ? Regards, Sanaullah On Wed, Aug 6, 2014 at 5:12 AM, Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Sunaullah, > > On 7/26/14, 4:50 AM, Sanaullah wrote: > > I trie

Re: APR with PKCS11 support

2014-08-05 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sunaullah, On 7/26/14, 4:50 AM, Sanaullah wrote: > I tried that configuration but getting errrors. I just want you to know that you haven't been forgotten: I'm on vacation for a bit but I'd really like to take a look at this issue when I return. I

Re: APR with PKCS11 support

2014-07-26 Thread Sanaullah
I tried that configuration but getting errrors. NFO: Loaded APR based Apache Tomcat Native library 1.1.30 using APR version 1.4.6. Jul 23, 2014 3:06:40 AM org.apache.catalina.core.AprLifecycleListener init INFO: APR capabilities: IPv6 [true], sendfile [true], accept filters [false], random [true].

Re: APR with PKCS11 support

2014-07-25 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sanaullah, On 7/25/14, 9:16 AM, Sanaullah wrote: > httpd is working with HSM with addition of parameter > SSLCryptoDevice=LunaCA but when i try the same parameter in tomEE. > TomEE don't recognized this parameters. > > WARNING: [SetAllPropertiesR

Re: APR with PKCS11 support

2014-07-25 Thread Sanaullah
Hi Chris, httpd is working with HSM with addition of parameter SSLCryptoDevice=LunaCA but when i try the same parameter in tomEE. TomEE don't recognized this parameters. WARNING: [SetAllPropertiesRule]{Server/Service/Connector} Setting property 'SSLCryptoDevice' to 'LunaCA3' did not find a match

Re: APR with PKCS11 support

2014-07-10 Thread Sanaullah
Thanks chris, I haven't tried such configurations with httpd. I will explore now. Regards, Sanaullah On Thu, Jul 10, 2014 at 7:40 PM, Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Sanaullah, > > On 7/10/14, 4:19 AM, Sanaullah

Re: APR with PKCS11 support

2014-07-10 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sanaullah, On 7/10/14, 4:19 AM, Sanaullah wrote: > is there a way i can use pkcs11 supported SmartCard/token when > using APR based SSL Connector in tomcat ? PEM encoded certificates > and keys are stored in smartcard. > > I know BIO/NIO connectors