1 1.1 christos # EAP-TLS using private key and certificates via OpenSSL PKCS#11 engine and 2 1.1 christos # openCryptoki (e.g., with TPM token) 3 1.1 christos 4 1.1 christos # This example uses following PKCS#11 objects: 5 1.1 christos # $ pkcs11-tool --module /usr/lib/opencryptoki/libopencryptoki.so -O -l 6 1.1 christos # Please enter User PIN: 7 1.1 christos # Private Key Object; RSA 8 1.1 christos # label: rsakey 9 1.1 christos # ID: 04 10 1.1 christos # Usage: decrypt, sign, unwrap 11 1.1 christos # Certificate Object, type = X.509 cert 12 1.1 christos # label: ca 13 1.1 christos # ID: 01 14 1.1 christos # Certificate Object, type = X.509 cert 15 1.1 christos # label: cert 16 1.1 christos # ID: 04 17 1.1 christos 18 1.1 christos # Configure OpenSSL to load the PKCS#11 engine and openCryptoki module 19 1.1 christos pkcs11_engine_path=/usr/lib/engines/engine_pkcs11.so 20 1.1 christos pkcs11_module_path=/usr/lib/opencryptoki/libopencryptoki.so 21 1.1 christos 22 1.1 christos network={ 23 1.1 christos ssid="test network" 24 1.1 christos key_mgmt=WPA-EAP 25 1.1 christos eap=TLS 26 1.1 christos identity="User" 27 1.1 christos 28 1.1 christos # use OpenSSL PKCS#11 engine for this network 29 1.1 christos engine=1 30 1.1 christos engine_id="pkcs11" 31 1.1 christos 32 1.1 christos # select the private key and certificates based on ID (see pkcs11-tool 33 1.1 christos # output above) 34 1.1 christos key_id="4" 35 1.1 christos cert_id="4" 36 1.1 christos ca_cert_id="1" 37 1.1 christos 38 1.1 christos # set the PIN code; leave this out to configure the PIN to be requested 39 1.1 christos # interactively when needed (e.g., via wpa_gui or wpa_cli) 40 1.1 christos pin="123456" 41 1.1 christos } 42