Home | History | Annotate | Line # | Download | only in examples
      1  1.1  christos # EAP-TLS using private key and certificates via OpenSSL PKCS#11 engine and
      2  1.1  christos # openCryptoki (e.g., with TPM token)
      3  1.1  christos 
      4  1.1  christos # This example uses following PKCS#11 objects:
      5  1.1  christos # $ pkcs11-tool --module /usr/lib/opencryptoki/libopencryptoki.so  -O -l
      6  1.1  christos # Please enter User PIN:
      7  1.1  christos # Private Key Object; RSA
      8  1.1  christos #   label:      rsakey
      9  1.1  christos #   ID:         04
     10  1.1  christos #   Usage:      decrypt, sign, unwrap
     11  1.1  christos # Certificate Object, type = X.509 cert
     12  1.1  christos #   label:      ca
     13  1.1  christos #   ID:         01
     14  1.1  christos # Certificate Object, type = X.509 cert
     15  1.1  christos #   label:      cert
     16  1.1  christos #   ID:         04
     17  1.1  christos 
     18  1.1  christos # Configure OpenSSL to load the PKCS#11 engine and openCryptoki module
     19  1.1  christos pkcs11_engine_path=/usr/lib/engines/engine_pkcs11.so
     20  1.1  christos pkcs11_module_path=/usr/lib/opencryptoki/libopencryptoki.so
     21  1.1  christos 
     22  1.1  christos network={
     23  1.1  christos 	ssid="test network"
     24  1.1  christos 	key_mgmt=WPA-EAP
     25  1.1  christos 	eap=TLS
     26  1.1  christos 	identity="User"
     27  1.1  christos 
     28  1.1  christos 	# use OpenSSL PKCS#11 engine for this network
     29  1.1  christos 	engine=1
     30  1.1  christos 	engine_id="pkcs11"
     31  1.1  christos 
     32  1.1  christos 	# select the private key and certificates based on ID (see pkcs11-tool
     33  1.1  christos 	# output above)
     34  1.1  christos 	key_id="4"
     35  1.1  christos 	cert_id="4"
     36  1.1  christos 	ca_cert_id="1"
     37  1.1  christos 
     38  1.1  christos 	# set the PIN code; leave this out to configure the PIN to be requested
     39  1.1  christos 	# interactively when needed (e.g., via wpa_gui or wpa_cli)
     40  1.1  christos 	pin="123456"
     41  1.1  christos }
     42