Статус: Новичок
Группы: Участники
Зарегистрирован: 06.03.2019(UTC) Сообщений: 3 Сказал(а) «Спасибо»: 1 раз Поблагодарили: 1 раз в 1 постах
|
Автор: Lirein
Добрый день. Для Рутокен-S нужно устанавливать драйвер, идёт в комплекте с КриптоПро: ifd-rutokens_1.0.1_amd64. Кроме него в системе должен быть установлен демон pcscd обеспечивающий работу со смарт-картами. Если драйвер уcтановлен, обязательно проверьте что верно указан тип провайдера, для ГОСТ 2001 должен быть 75, для ГОСТ2012 - соответственно 80. При установке с токена можно указать через ключ -provtype 75 или -provtype 80.
Драйвер установлен и сертификаты видны, НО при попытке использовать такие пары в логе ошибка подписания... Правильно ли я понимаю, что при установки сертификата в хранилище указать тип провайдера
SHA1 Hash : b59405feb7469724dafd9122c0d2e16bfb41dda2 SubjKeyID : fc854c126a74b088453bedb8d8a2e5def02fc9b4 Signature Algorithm : ГОСТ Р 34.11-2012/34.10-2012 256 бит PublicKey Algorithm : ГОСТ Р 34.10-2012 (512 bits) Not valid before : 16/01/2019 12:16:42 UTC Not valid after : 17/01/2020 10:34:00 UTC PrivateKey Link : Yes Container : SCARD\rutoken_31296178\0A00\5F40 Provider Name : Crypto-Pro GOST R 34.10-2012 KC2 CSP Provider Info : ProvType: 80, KeySpec: 1, Flags: 0x0
engine.log:
2019-03-06 11:52:00:WEBLIB:process_request:Request string(length = 51) = "{"func_name":"free_x509","params":{"x509Handle":2}}" 2019-03-06 11:52:00:IFC:ifc_free_x509:STARTED 2019-03-06 11:52:00:IFC:ifc_free_x509:result [0] 2019-03-06 11:52:00:WEBLIB:process_request:Response string(length = 16) = "{"error_code":0}" 2019-03-06 11:52:10:WEBLIB:process_request:Request string(length = 58) = "{"func_name":"get_list_info","params":{"cryptoType":null}}" 2019-03-06 11:52:10:IFC:ifc_get_list_info:STARTED 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [0] 2019-03-06 11:52:10:IFC:list_keys_capi:STARTED 2019-03-06 11:52:10:IFC:list_keys_capi:provider name is 'Infotecs Cryptographic Service Provider', provider type is '2' i_keys is not set 2019-03-06 11:52:10:IFC:list_keys_capi:Provider Infotecs Cryptographic Service Provider type capi was not acquired. The requested provider does not exist. 2019-03-06 11:52:10:IFC:list_keys_capi:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [1] 2019-03-06 11:52:10:IFC:list_keys_capi:STARTED 2019-03-06 11:52:10:IFC:list_keys_capi:provider name is 'Infotecs Cryptographic Service Provider', provider type is '2' i_keys is not set 2019-03-06 11:52:10:IFC:list_keys_capi:dlopen failed: libcrypt32.so: cannot open shared object file: No such file or directory 2019-03-06 11:52:10:IFC:list_keys_capi:Infotecs Cryptographic Service Provider is not installed 2019-03-06 11:52:10:IFC:list_keys_capi:result [1] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [2] 2019-03-06 11:52:10:IFC:list_keys_capi:STARTED 2019-03-06 11:52:10:IFC:list_keys_capi:provider name is 'Crypto-Pro GOST R 34.10-2001 Cryptographic Service Provider', provider type is '75' i_keys is not set 2019-03-06 11:52:10:IFC:list_keys_capi:Provider Crypto-Pro GOST R 34.10-2001 Cryptographic Service Provider type capi was not acquired. The requested provider does not exist. 2019-03-06 11:52:10:IFC:list_keys_capi:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [3] 2019-03-06 11:52:10:IFC:list_keys_capi:STARTED 2019-03-06 11:52:10:IFC:list_keys_capi:provider name is 'GOST R 34.10-2001 Rutoken CSP', provider type is '75' i_keys is not set 2019-03-06 11:52:10:IFC:list_keys_capi:Provider GOST R 34.10-2001 Rutoken CSP type capi was not acquired. The requested provider does not exist. 2019-03-06 11:52:10:IFC:list_keys_capi:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [4] 2019-03-06 11:52:10:IFC:list_keys_capi:STARTED 2019-03-06 11:52:10:IFC:list_keys_capi:provider name is 'Signal-COM CPGOST Cryptographic Provider', provider type is '75' i_keys is not set 2019-03-06 11:52:10:IFC:list_keys_capi:Provider Signal-COM CPGOST Cryptographic Provider type capi was not acquired. The requested provider does not exist. 2019-03-06 11:52:10:IFC:list_keys_capi:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [5] 2019-03-06 11:52:10:IFC:list_keys_capi:STARTED 2019-03-06 11:52:10:IFC:list_keys_capi:provider name is 'Signal-COM GOST R 34.10-2012 (256) Cryptographic Provider', provider type is '80' i_keys is not set 2019-03-06 11:52:10:IFC:list_keys_capi:Provider Signal-COM GOST R 34.10-2012 (256) Cryptographic Provider type capi was not acquired. The requested provider does not exist. 2019-03-06 11:52:10:IFC:list_keys_capi:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [6] 2019-03-06 11:52:10:IFC:list_keys_capi:STARTED 2019-03-06 11:52:10:IFC:list_keys_capi:provider name is 'Signal-COM GOST R 34.10-2012 (512) Cryptographic Provider', provider type is '81' i_keys is not set 2019-03-06 11:52:10:IFC:list_keys_capi:Provider Signal-COM GOST R 34.10-2012 (512) Cryptographic Provider type capi was not acquired. The requested provider does not exist. 2019-03-06 11:52:10:IFC:list_keys_capi:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [7] 2019-03-06 11:52:10:IFC:list_keys_capi:STARTED 2019-03-06 11:52:10:IFC:list_keys_capi:provider name is 'LISSI-CSP', provider type is '75' i_keys is not set 2019-03-06 11:52:10:IFC:list_keys_capi:Provider LISSI-CSP type capi was not acquired. The requested provider does not exist. 2019-03-06 11:52:10:IFC:list_keys_capi:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [8] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:STARTED 2019-03-06 11:52:10:IFC:list_keys_pkcs11:pkcs11_lib is 'libjcPKCS11-2.so.2.4.0', i_keys is not set 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:STARTED 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:module path: libjcPKCS11-2.so.2.4.0 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:cached PKCS#11 library found 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:C_Initialize already initialized 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:result [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:slots count: [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:No connected tokens found 2019-03-06 11:52:10:IFC:list_keys_pkcs11:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [9] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:STARTED 2019-03-06 11:52:10:IFC:list_keys_pkcs11:pkcs11_lib is 'librtpkcs11ecp.so', i_keys is not set 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:STARTED 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:module path: librtpkcs11ecp.so 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:cached PKCS#11 library found 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:C_Initialize already initialized 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:result [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:slots count: [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:No connected tokens found 2019-03-06 11:52:10:IFC:list_keys_pkcs11:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [10] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:STARTED 2019-03-06 11:52:10:IFC:list_keys_pkcs11:pkcs11_lib is '/opt/cprocsp/lib/amd64/libcppkcs11.so', i_keys is not set 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:STARTED 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:module path: /opt/cprocsp/lib/amd64/libcppkcs11.so 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:cached PKCS#11 library found 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:C_Initialize already initialized 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:result [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:slots count: [1] 2019-03-06 11:52:10:IFC:get_slot_and_token_info:STARTED 2019-03-06 11:52:10:IFC:get_slot_and_token_info:GetSlotInfo [0] 2019-03-06 11:52:10:IFC:get_slot_and_token_info:Slot description: "\CryptoPro Slot" 2019-03-06 11:52:10:IFC:get_slot_and_token_info:C_GetTokenInfo [0] 2019-03-06 11:52:10:IFC:get_slot_and_token_info:Token Serial Number: "0000000000000000" 2019-03-06 11:52:10:IFC:get_slot_and_token_info:Token Model: "CPPKCS 3" 2019-03-06 11:52:10:IFC:get_slot_and_token_info:result [0] 2019-03-06 11:52:10:IFC:check_token_support:STARTED 2019-03-06 11:52:10:IFC:check_token_support:result [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [11] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:STARTED 2019-03-06 11:52:10:IFC:list_keys_pkcs11:pkcs11_lib is '/opt/cprocsp/lib/amd64/libcppkcs11.so', i_keys is not set 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:STARTED 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:module path: /opt/cprocsp/lib/amd64/libcppkcs11.so 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:cached PKCS#11 library found 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:C_Initialize already initialized 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:result [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:slots count: [1] 2019-03-06 11:52:10:IFC:get_slot_and_token_info:STARTED 2019-03-06 11:52:10:IFC:get_slot_and_token_info:GetSlotInfo [0] 2019-03-06 11:52:10:IFC:get_slot_and_token_info:Slot description: "\CryptoPro Slot" 2019-03-06 11:52:10:IFC:get_slot_and_token_info:C_GetTokenInfo [0] 2019-03-06 11:52:10:IFC:get_slot_and_token_info:Token Serial Number: "0000000000000000" 2019-03-06 11:52:10:IFC:get_slot_and_token_info:Token Model: "CPPKCS 3" 2019-03-06 11:52:10:IFC:get_slot_and_token_info:result [0] 2019-03-06 11:52:10:IFC:check_token_support:STARTED 2019-03-06 11:52:10:IFC:check_token_support:result [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:config record [12] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:STARTED 2019-03-06 11:52:10:IFC:list_keys_pkcs11:pkcs11_lib is '/opt/cprocsp/lib/amd64/libcppkcs11.so', i_keys is not set 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:STARTED 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:module path: /opt/cprocsp/lib/amd64/libcppkcs11.so 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:cached PKCS#11 library found 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:C_Initialize already initialized 2019-03-06 11:52:10:IFC:ifc_load_pkcs11_lib:result [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:slots count: [1] 2019-03-06 11:52:10:IFC:get_slot_and_token_info:STARTED 2019-03-06 11:52:10:IFC:get_slot_and_token_info:GetSlotInfo [0] 2019-03-06 11:52:10:IFC:get_slot_and_token_info:Slot description: "\CryptoPro Slot" 2019-03-06 11:52:10:IFC:get_slot_and_token_info:C_GetTokenInfo [0] 2019-03-06 11:52:10:IFC:get_slot_and_token_info:Token Serial Number: "0000000000000000" 2019-03-06 11:52:10:IFC:get_slot_and_token_info:Token Model: "CPPKCS 3" 2019-03-06 11:52:10:IFC:get_slot_and_token_info:result [0] 2019-03-06 11:52:10:IFC:check_token_support:STARTED 2019-03-06 11:52:10:IFC:check_token_support:result [0] 2019-03-06 11:52:10:IFC:list_keys_pkcs11:result [0] 2019-03-06 11:52:10:IFC:ifc_get_list_info:result [0] 2019-03-06 11:52:10:WEBLIB:process_request:Response string(length = 817) = "{"error_code":0,"ifc_list":[{"alg":"gost2001","alias":"CPPKCS11_2001","description":"\\CryptoPro Slot","model":"CPPKCS 3","name":"CPPKCS11_2001","num":"0","path":"/opt/cprocsp/lib/amd64/libcppkcs11.so","serial_number":"0000000000000000","skip_pkcs11_list":"","type":"pkcs11"},{"alg":"gost2012_256","alias":"CPPKCS11_2012_256","description":"\\CryptoPro Slot","model":"CPPKCS 3","name":"CPPKCS11_2012_256","num":"0","path":"/opt/cprocsp/lib/amd64/libcppkcs11.so","serial_number":"0000000000000000","skip_pkcs11_list":"","type":"pkcs11"},{"alg":"gost2012_512","alias":"CPPKCS11_2012_512","description":"\\CryptoPro Slot","model":"CPPKCS 3","name":"CPPKCS11_2012_512","num":"0","path":"/opt/cprocsp/lib/amd64/libcppkcs11.so","serial_number":"0000000000000000","skip_pkcs11_list":"","type":"pkcs11"}],"ifc_list_length":3}" 2019-03-06 11:52:10:WEBLIB:process_request:Request string(length = 212) = "{"func_name":"sign","params":{"containerId":"CPPKCS11_2001/0/5CB9E2C6F55F803A6BFA3F3D99C3A2006951DFEE","userPin":"********","inDataType":1,"data":"**********","hashType":1,"signType":3,"cspUI":1,"outDataType":1}}" 2019-03-06 11:52:10:IFC:ifc_sign:STARTED 2019-03-06 11:52:10:IFC:ifc_sign:data type: 1, signature type: 3, encode_to_base64: 1 2019-03-06 11:52:10:IFC:ifc_engine:STARTED 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:STARTED 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:p11 lib name: /opt/cprocsp/lib/amd64/libcppkcs11.so, slot: 0, engine lib name: pkcs11_engine 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:cached crypto slot found 2019-03-06 11:52:10:IFC:pkcs11_engine_login:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:make_login:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:make_login:PASSED 2019-03-06 11:52:10:IFC:pkcs11_engine_login:pkcs11 login was proceeded 2019-03-06 11:52:10:IFC:pkcs11_engine_login:result [0] 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:result [0] 2019-03-06 11:52:10:IFC:ifc_engine:result [0] 2019-03-06 11:52:10:IFC:do_work_sign_cms:STARTED 2019-03-06 11:52:10:IFC:ifc_engine:STARTED 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:STARTED 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:p11 lib name: /opt/cprocsp/lib/amd64/libcppkcs11.so, slot: 0, engine lib name: pkcs11_engine 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:cached crypto slot found 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:result [0] 2019-03-06 11:52:10:IFC:ifc_engine:result [0] 2019-03-06 11:52:10:IFC:find_cert_in_store_by_id:STARTED 2019-03-06 11:52:10:IFC:find_cert_in_store_by_id:ID to find: 5CB9E2C6F55F803A6BFA3F3D99C3A2006951DFEE 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_start:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_start:PASSED 2019-03-06 11:52:10:IFC:find_cert_in_store_by_id:STORE_list_certificate_start done 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_next:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:make_object_to_return:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:make_x509_by_handle:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:make_x509_by_handle:PASSED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:make_object_to_return:PASSED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_next:PASSED 2019-03-06 11:52:10:IFC:find_cert_in_store_by_id:STORE_list_certificate_next done 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_end:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_end:PASSED 2019-03-06 11:52:10:IFC:find_cert_in_store_by_id:STORE_list_certificate_end done 2019-03-06 11:52:10:IFC:find_cert_in_store_by_id:result [found cert handle] 2019-03-06 11:52:10:IFC:get_priv_key_by_id:STARTED 2019-03-06 11:52:10:IFC:get_priv_key_by_id:ID to find: 5CB9E2C6F55F803A6BFA3F3D99C3A2006951DFEE 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_start:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_start:PASSED 2019-03-06 11:52:10:IFC:get_priv_key_by_id:STORE_list_private_key_start done 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_next:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_next:No such objects 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:gost_store_list_next:PASSED 2019-03-06 11:52:10:IFC:get_priv_key_by_id:result [NULL] 2019-03-06 11:52:10:IFC:do_work_sign_cms:ERROR:get_priv_key_by_id error:ifc_sign_cms.c:110 2019-03-06 11:52:10:IFC:do_work_sign_cms:result [1] 2019-03-06 11:52:10:IFC:ifc_p11_logout:STARTED 2019-03-06 11:52:10:IFC:ifc_engine:STARTED 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:STARTED 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:p11 lib name: /opt/cprocsp/lib/amd64/libcppkcs11.so, slot: 0, engine lib name: pkcs11_engine 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:cached crypto slot found 2019-03-06 11:52:10:IFC:ifc_init_pkcs11_engine:result [0] 2019-03-06 11:52:10:IFC:ifc_engine:result [0] 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:make_logout:STARTED 2019-03-06 11:52:10:pkcs11_engine-CPPKCS11_2001-0:make_logout:PASSED 2019-03-06 11:52:10:IFC:ifc_p11_logout:result [0] 2019-03-06 11:52:10:IFC:ifc_sign:result [1] 2019-03-06 11:52:10:WEBLIB:process_request:Response string(length = 16) = "{"error_code":1}"
|