[openssl-dev] openssl cms unable to access keys on token?

Blumenthal, Uri - 0553 - MITLL uri at ll.mit.edu
Mon Mar 14 19:27:41 UTC 2016


$ openssl cms -engine pkcs11 -aes256 -encrypt -binary -in data.txt -outform engine "pkcs11:object=KEY%20MAN%20pubkey;object-type=public"

engine "pkcs11" set.

Error opening recipient certificate file pkcs11:object=KEY%20MAN%20pubkey;object-type=public

140735201178448:error:02001002:system library:fopen:No such file or directory:bss_file.c:398:fopen('pkcs11:object=KEY%20MAN%20pubkey;object-type=public','r')

140735201178448:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:400:

unable to load certificate

$ openssl cms -engine pkcs11 -aes256 -encrypt -binary -in data.txt -outform engine "pkcs11:object=Certificate%20for%20Key%20Management;object-type=certificate"

engine "pkcs11" set.

Error opening recipient certificate file pkcs11:object=Certificate%20for%20Key%20Management;object-type=certificate

140735201178448:error:02001002:system library:fopen:No such file or directory:bss_file.c:398:fopen('pkcs11:object=Certificate%20for%20Key%20Management;object-type=certificate','r')

140735201178448:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:400:

unable to load certificate

$ openssl cms -engine pkcs11 -aes256 -encrypt -binary -in data.txt -outform engine "pkcs11:object=Certificate%20for%20Key%20Management;object-type=cert"

engine "pkcs11" set.

Error opening recipient certificate file pkcs11:object=Certificate%20for%20Key%20Management;object-type=cert

140735201178448:error:02001002:system library:fopen:No such file or directory:bss_file.c:398:fopen('pkcs11:object=Certificate%20for%20Key%20Management;object-type=cert','r')

140735201178448:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:400:

unable to load certificate

$

--
Regards,
Uri Blumenthal
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20160314/cda06496/attachment.html>


More information about the openssl-dev mailing list