Page MenuHomeSolus

Rebuild request OpenVPN with enable-pkcs11
Closed, ResolvedPublic

Description

If possible, I ask you to rebuild OpenVPN with pkcs 11. I need to connect to servers using a hardware key. Using the library https://download.rutoken.ru/Rutoken/PKCS11Lib/Current/Linux/x64/librtpkcs11ecp.so,
I tried to rebuild it myself.
But the problem is with lib pkcs11-helper, which I also tried to build, but due to lack of experience I could not do it.
Please, I don't want to go back to other operating systems, they drain my battery very quickly.
Harvey advised me to submit a request.
https://discuss.getsol.us/d/7857-openvpn-pkcs11-etoken-and-rutoken

Revisions and Commits

Event Timeline

Girtablulu triaged this task as Needs More Info priority.
Girtablulu added subscribers: ReillyBrogan, Girtablulu.

@ReillyBrogan as someone who updated it lately, what's your opinion to this?

Should be fine, but it doesn't look like pkcs11-helper is packaged yet so that would need to be done as well. Doesn't look like it would be too much difficulty though.

@klaisens I have built OpenVPN with pkcs11-helper but unfortunately don't have a way to test it. Would you be willing to test a few experimental packages for me to see if they actually work for your usecase? If so, please let me know if your Solus install is on unstable or stable (if you've never explicitly enabled unstable you are on stable).

joebonrichie raised the priority of this task from Needs More Info to Normal.Jan 13 2022, 6:19 PM
joebonrichie moved this task from Backlog to Improvement on the Software board.
joebonrichie added a subscriber: joebonrichie.

Hopefully @klaisens can confirm it's all working correctly first before we land it.

@ReillyBrogan I agree to test it. I'm using a stable one now. If necessary, I will switch to unstable.

@ReillyBrogan I agree to test it. I'm using a stable one now. If necessary, I will switch to unstable.

@klaisens The updated openvpn with pcks11 support will be landing in this sync. Should show up later today unless the sync is suddenly deferred for whatever reason (very unlikely).