Oracle Java 7 keytool无法将pkcs11密钥库导入JKS:不是PKCS 8编码的

时间:2016-11-24 16:16:18

标签: java keystore keytool pkcs#11 keystore-access

我已经按照Oracle指南尝试将我的智能卡中的PKCS#11密钥库导入到我的文件系统中的JKS密钥库中,在Ubuntu 16.04中。我安装了Oracle JDK 7,以及我的Izenpe卡的驱动文件。

http://docs.oracle.com/javase/7/docs/technotes/guides/security/p11guide.html

我在Open JDK 7中遇到过这个错误:

java keytool with opensc pkcs#11 provider only works with debug option enabled

声明使用Open JDK实现有一个bug,你应该绕过它。帖子没有解决我的问题,我切换到Oracle JDK 7,我可以列出我的卡中的私钥条目:

keytool -keystore NONE -storetype PKCS11 \
        -providerClass sun.security.pkcs11.SunPKCS11 \
            -providerArg $JAVA_HOME/config.ini \
        -v -list

config.ini所在的位置:

name=Izenpe-static
library=/usr/lib/libbit4ipki.so
showInfo=true

所以,我得到了:

easternfox@easternfox-Ubuntu:~/下载/electronic-wechat-production$ keytool -keystore NONE -storetype PKCS11 -providerClass sun.security.pkcs11.SunPKCS11 -providerArg /home/easternfox/文档/config.ini -v -list 

Information for provider SunPKCS11-Izenpe-static
Library info:
  cryptokiVersion: 2.20
  manufacturerID: bit4id srl                      
  flags: 0
  libraryDescription: bit4id PKCS#11                  
  libraryVersion: 1.02
All slots: 0
Slots with tokens: 0
Slot info for slot 0:
  slotDescription: Cherry GmbH SmartBoard XX44 [Smart Card Reader USB] 00 00       
  manufacturerID: unknown                         
  flags: CKF_TOKEN_PRESENT | CKF_REMOVABLE_DEVICE | CKF_HW_SLOT
  hardwareVersion: 0.00
  firmwareVersion: 0.00
Token info for token in slot 0:
  label: IZENPE                          
  manufacturerID: Oberthur Technologies           
  model: Cosmo ID ONE (L)
  serialNumber: 1550001000002654
  flags: CKF_RNG | CKF_LOGIN_REQUIRED | CKF_USER_PIN_INITIALIZED | CKF_TOKEN_INITIALIZED
  ulMaxSessionCount: CK_EFFECTIVELY_INFINITE
  ulSessionCount: 0
  ulMaxRwSessionCount: CK_EFFECTIVELY_INFINITE
  ulRwSessionCount: CK_UNAVAILABLE_INFORMATION
  ......

Enter keystore password:  

Keystore type: PKCS11
Keystore provider: SunPKCS11-Izenpe-static

Your keystore contains 1 entry

Alias name: CIUDADANO FICTICIO ACTIVO
Entry type: PrivateKeyEntry
Certificate chain length: 1
Certificate[1]:
Owner: SERIALNUMBER=92920000T, SURNAME=FICTICIO, GIVENNAME=CIUDADANO, CN=CIUDADANO FICTICIO ACTIVO, DNQ=-dni 92920000T, OU=Condiciones de uso en www.izenpe.com nola erabili jakiteko, OU=Herritar ziurtagiria - Certificado de ciudadano, OU=Ziurtagiri onartua - Certificado reconocido, C=ES
Issuer: CN=Herritar eta Erakundeen CA - CA de Ciudadanos y Entidades (4), OU=NZZ Ziurtagiri publikoa - Certificado publico SCI, O=IZENPE S.A., C=ES
......

#10: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 00 DE A8 79 08 14 F9 FA   05 2C BF 8B 65 99 69 91  ...y.....,..e.i.
0010: EA 5D 70 45                                        .]pE
]
]

*******************************************
*******************************************

而且,当我尝试keytool -importkeystore时,我有几个错误:

运行keytool -importkeystore --help为我提供了很多有用的信息:

keytool -importkeystore [OPTION]...

Imports one or all entries from another keystore

Options:

 -srckeystore <srckeystore>            source keystore name
 -destkeystore <destkeystore>          destination keystore name
 -srcstoretype <srcstoretype>          source keystore type
 -deststoretype <deststoretype>        destination keystore type
 -srcstorepass <arg>                   source keystore password
 -deststorepass <arg>                  destination keystore password
 -srcprotected                         source keystore password protected
 -srcprovidername <srcprovidername>    source keystore provider name
 -destprovidername <destprovidername>  destination keystore provider name
 -srcalias <srcalias>                  source alias
 -destalias <destalias>                destination alias
 -srckeypass <arg>                     source key password
 -destkeypass <arg>                    destination key password
 -noprompt                             do not prompt
 -providerclass <providerclass>        provider class name
 -providerarg <arg>                    provider argument
 -providerpath <pathlist>              provider classpath
 -v                                    verbose output

Use "keytool -help" for all available commands

如果我省略srckeypass / destkeypass,我有:

easternfox@easternfox-Ubuntu:$ keytool -srckeystore NONE -srcstoretype PKCS11 \
    -destkeystore /home/easternfox/my.new.jks -deststoretype jks -deststorepass qwerqwer \
    -providerClass sun.security.pkcs11.SunPKCS11 \
         -providerArg $JAVA_HOME/config.ini 
    -v -importkeystore


Information for provider SunPKCS11-Izenpe-static
Library info:
  cryptokiVersion: 2.20
  manufacturerID: bit4id srl                      
  flags: 0
  libraryDescription: bit4id PKCS#11                  
  libraryVersion: 1.02
All slots: 0
Slots with tokens: 0
Slot info for slot 0:
  slotDescription: Cherry GmbH SmartBoard XX44 [Smart Card Reader USB] 00 00       
  manufacturerID: unknown                         
  flags: CKF_TOKEN_PRESENT | CKF_REMOVABLE_DEVICE | CKF_HW_SLOT
  hardwareVersion: 0.00
  firmwareVersion: 0.00
Token info for token in slot 0:
  label: IZENPE                          
  manufacturerID: Oberthur Technologies           
  model: Cosmo ID ONE (L)
  serialNumber: 1550001000002654
  flags: CKF_RNG | CKF_LOGIN_REQUIRED | CKF_USER_PIN_INITIALIZED | CKF_TOKEN_INITIALIZED
  ulMaxSessionCount: CK_EFFECTIVELY_INFINITE
  ulSessionCount: 0
  ulMaxRwSessionCount: CK_EFFECTIVELY_INFINITE
  ulRwSessionCount: CK_UNAVAILABLE_INFORMATION
  ulMaxPinLen: 8
  ulMinPinLen: 4
  ulTotalPublicMemory: 65535
  ....
Enter source keystore password:  
Problem importing entry for alias CIUDADANO FICTICIO ACTIVO: java.security.KeyStoreException: non-null password required to create PrivateKeyEntry.
Entry for alias CIUDADANO FICTICIO ACTIVO not imported.
Do you want to quit the import process? [no]:  n
Import command completed:  0 entries successfully imported, 1 entries failed or cancelled
[Storing /home/easternfox/my.new.jks]

所以,我看到non-null password required错误,我尝试指定srckeypassdestkeypass,并收到另一个错误:

keytool error: java.lang.Exception: if alias not specified, destalias, srckeypass, and destkeypass must not be specified
java.lang.Exception: if alias not specified, destalias, srckeypass, and destkeypass must not be specified
    at sun.security.tools.KeyTool.doImportKeyStore(KeyTool.java:1864)
    at sun.security.tools.KeyTool.doCommands(KeyTool.java:1024)
    at sun.security.tools.KeyTool.run(KeyTool.java:340)
    at sun.security.tools.KeyTool.main(KeyTool.java:333)

所以,我必须添加srcalias。所以我这样做了,并且:

Problem importing entry for alias CIUDADANO FICTICIO ACTIVO: java.security.KeyStoreException: Cannot get key bytes, not PKCS#8 encoded.
Entry for alias CIUDADANO FICTICIO ACTIVO not imported.
[Storing /home/easternfox/my.new.jks]

发生了另一个错误,表明卡中的私钥不是PKCS#8编码的。

如何解决这个问题?这是一个错误吗?或者只是制造商相关的问题?

我尝试过:

  • 我尝试将参数-providerpath指定为更改为Oracle JDK 8的另一个sunpkcs11.jar,但无济于事。
  • 我将随卡附带的驱动程序更改为另一个版本。不工作。

编辑:

我尝试编写一些代码,并使用一些堆栈跟踪获得相同的错误:

java.security.KeyStoreException: Cannot get key bytes, not PKCS#8 encoded
    at sun.security.provider.KeyProtector.protect(KeyProtector.java:174)
    at sun.security.provider.JavaKeyStore.engineSetKeyEntry(JavaKeyStore.java:259)
    at sun.security.provider.JavaKeyStore$JKS.engineSetKeyEntry(JavaKeyStore.java:55)
    at java.security.KeyStore.setKeyEntry(KeyStore.java:909)
    at com.JSILTRA.logic.PKCS11KeyStoreConstuctor.constructJKSKeyStore(PKCS11KeyStoreConstuctor.java:66)
    at com.JSILTRA.logic.PKCS11KeyStoreConstuctor.main(PKCS11KeyStoreConstuctor.java:22)

0 个答案:

没有答案