- added customization via OPENSC_CONFIGURE
- changed information regarding opensc - fixed pkg-config file git-svn-id: https://vsmartcard.svn.sourceforge.net/svnroot/vsmartcard@389 96b47cad-a561-4643-ad3b-153ac7d7599c
This commit is contained in:
@@ -1,15 +1,16 @@
|
|||||||
/** @mainpage
|
/** @mainpage
|
||||||
|
|
||||||
Welcome to ccid. The purpose of ccid is to forward a PCSC smartcard reader
|
Welcome to ccid-emulator. The purpose of ccid-emulator is to forward a PCSC
|
||||||
as a standard USB CCID reader. If the host system is in USB device mode, ccid
|
smartcard reader as a standard USB CCID reader. If the host system is in USB
|
||||||
forwards the local reader via USB to an other device. If in USB host mode,
|
device mode, ccid-emulator forwards the local reader via USB to an other
|
||||||
ccid virtually plugges in a USB CCID reader to the host system. ccid has
|
device. If in USB host mode, ccid-emulator virtually plugges in a USB CCID
|
||||||
support for Password Authenticated Connection Establishment (PACE) using
|
reader to the host system. ccid-emulator has support for Password
|
||||||
OpenPACE (http://sourceforge.net/projects/openpace/).
|
Authenticated Connection Establishment (PACE) using OpenPACE
|
||||||
|
(http://sourceforge.net/projects/openpace/).
|
||||||
|
|
||||||
ccid is implemented using GadgetFS. Some fragments of the source code is based
|
ccid-emulator is implemented using GadgetFS. Some fragments of the source code
|
||||||
on the GadgetFS example at http://www.linux-usb.org/gadget/ and on the source
|
is based on the GadgetFS example at http://www.linux-usb.org/gadget/ and on the
|
||||||
code of the OpenSC tools.
|
source code of the OpenSC tools.
|
||||||
|
|
||||||
|
|
||||||
@section i INSTALLATION
|
@section i INSTALLATION
|
||||||
@@ -32,27 +33,20 @@ https://docs.openmoko.org/trac/ticket/2240).
|
|||||||
|
|
||||||
@subsection o HINTS ON OPENSC
|
@subsection o HINTS ON OPENSC
|
||||||
|
|
||||||
ccid links against libopensc, which is discouraged and hindered since
|
ccid-emulator links against libopensc, which is discouraged and hindered since
|
||||||
opensc>=0.12. We really need to get rid of this dependency. But since this is a
|
opensc>=0.12. We really need to get rid of this dependency. But so far we
|
||||||
lot of work, you will have to use older versions of opensc.
|
manually build it to have libopensc for linking. The good thing is that you
|
||||||
|
don't need any opensc components to be installed. The bad thing is, that
|
||||||
OpenSC older than r4244 will yield something like this error:
|
ccid-emulator configures and builds opensc on its own. So you might need to
|
||||||
|
pass some extra configure options to opensc. So if you need to pass options to
|
||||||
[default] apdu.c:341:sc_check_apdu: Invalid Case 4 short APDU:
|
opensc, use something like the following command:
|
||||||
cse=04 cla=10 ins=86 p1=00 p2=00 lc=2 le=0
|
./configure \
|
||||||
resp=0x10353c0 resplen=256 data=0x1034a30 datalen=2
|
OPENSC_CONFIGURE="options"
|
||||||
[default] pace.c:1110:EstablishPACEChannel: Could not get encrypted nonce from card (General Authenticate step 1 failed).
|
|
||||||
|
|
||||||
This requires the following patch:
|
|
||||||
http://www.opensc-project.org/opensc/raw-attachment/ticket/209/le0.patch
|
|
||||||
|
|
||||||
The following patch makes the hex dumped output more readable:
|
|
||||||
http://www.opensc-project.org/opensc/raw-attachment/ticket/263/hex_dump_align.2.patch
|
|
||||||
|
|
||||||
|
|
||||||
@subsection o HINTS ON LIBPACE
|
@subsection l HINTS ON LIBPACE
|
||||||
|
|
||||||
If you have a local build of OpenSSL with OpenPACE, that you want to link
|
If you have a local build of libpace and OpenPACE, that you want to link
|
||||||
against use something like the following command:
|
against use something like the following command:
|
||||||
./configure \
|
./configure \
|
||||||
OPENSSL_CFLAGS="-I/path/to/openssl-1.0.0c_with_openpace-0.4/include" \
|
OPENSSL_CFLAGS="-I/path/to/openssl-1.0.0c_with_openpace-0.4/include" \
|
||||||
|
|||||||
@@ -46,26 +46,22 @@ if test "x$enable_ccid" != xno ; then
|
|||||||
|
|
||||||
enable_ccid=yes
|
enable_ccid=yes
|
||||||
fi
|
fi
|
||||||
AC_SUBST(PTHREAD_CFLAGS)
|
|
||||||
AC_SUBST(PTHREAD_LIBS)
|
|
||||||
AM_CONDITIONAL(WITH_CCID, test "${enable_ccid}" != "no")
|
AM_CONDITIONAL(WITH_CCID, test "${enable_ccid}" != "no")
|
||||||
|
|
||||||
|
|
||||||
PKG_CHECK_EXISTS([libssl],
|
PKG_CHECK_EXISTS([libssl],
|
||||||
[PKG_CHECK_MODULES([OPENSSL], [libssl])],
|
[PKG_CHECK_MODULES([OPENSSL], [libssl >= 1.0.0])],
|
||||||
[AC_MSG_WARN([libssl not found by pkg-config])])
|
[AC_MSG_WARN([libssl not found by pkg-config])])
|
||||||
|
|
||||||
saved_CPPFLAGS="$CPPFLAGS"
|
saved_CPPFLAGS="$CPPFLAGS"
|
||||||
saved_LIBS="$LIBS"
|
saved_LIBS="$LIBS"
|
||||||
CPPFLAGS="$CPPFLAGS $OPENSSL_CFLAGS"
|
CPPFLAGS="$CPPFLAGS $OPENSSL_CFLAGS"
|
||||||
LIBS="$LDFLAGS $OPENSSL_LIBS"
|
LIBS="$LDFLAGS $OPENSSL_LIBS"
|
||||||
AC_CHECK_HEADERS(openssl/evp.h, [], [ AC_MSG_ERROR([openssl/evp.h not found, install OpenSSL or use ./configure OPENSSL_CFLAGS=...]) ])
|
AC_CHECK_HEADERS(openssl/evp.h, [], [ AC_MSG_ERROR([openssl/evp.h not found, install OpenSSL >= 1.0.0 or use ./configure OPENSSL_CFLAGS=...]) ])
|
||||||
AC_MSG_CHECKING([for EVP_read_pw_string_min])
|
AC_MSG_CHECKING([for EVP_read_pw_string_min])
|
||||||
AC_TRY_LINK_FUNC(EVP_read_pw_string_min, [ AC_MSG_RESULT([yes]) ], [ AC_MSG_ERROR([OpenSSL not found, use ./configure OPENSSL_LIBS=...]) ])
|
AC_TRY_LINK_FUNC(EVP_read_pw_string_min, [ AC_MSG_RESULT([yes]) ], [ AC_MSG_ERROR([OpenSSL >= 1.0.0 not found, use ./configure OPENSSL_LIBS=...]) ])
|
||||||
CPPFLAGS="$saved_CPPFLAGS"
|
CPPFLAGS="$saved_CPPFLAGS"
|
||||||
LIBS="$saved_LIBS"
|
LIBS="$saved_LIBS"
|
||||||
AC_SUBST(OPENSSL_CFLAGS)
|
|
||||||
AC_SUBST(OPENSSL_LIBS)
|
|
||||||
|
|
||||||
# --enable-pace
|
# --enable-pace
|
||||||
AC_ARG_ENABLE(pace,
|
AC_ARG_ENABLE(pace,
|
||||||
@@ -138,6 +134,9 @@ fi
|
|||||||
AM_CONDITIONAL(DOC_ENABLED, [test x"$enable_doc" = xyes])
|
AM_CONDITIONAL(DOC_ENABLED, [test x"$enable_doc" = xyes])
|
||||||
|
|
||||||
|
|
||||||
|
AC_SUBST(OPENSC_CONFIGURE)
|
||||||
|
|
||||||
|
|
||||||
# Checks for header files.
|
# Checks for header files.
|
||||||
AC_CHECK_HEADERS([arpa/inet.h fcntl.h memory.h stdint.h stdlib.h string.h sys/ioctl.h unistd.h])
|
AC_CHECK_HEADERS([arpa/inet.h fcntl.h memory.h stdint.h stdlib.h string.h sys/ioctl.h unistd.h])
|
||||||
|
|
||||||
@@ -179,6 +178,7 @@ LIBPACE_CFLAGS: ${LIBPACE_CFLAGS}
|
|||||||
LIBPACE_LIBS: ${LIBPACE_LIBS}
|
LIBPACE_LIBS: ${LIBPACE_LIBS}
|
||||||
PCSC_CFLAGS: ${PCSC_CFLAGS}
|
PCSC_CFLAGS: ${PCSC_CFLAGS}
|
||||||
PCSC_LIBS: ${PCSC_LIBS}
|
PCSC_LIBS: ${PCSC_LIBS}
|
||||||
|
OPENSC_CONFIGURE: ${OPENSC_CONFIGURE}
|
||||||
|
|
||||||
CCID emulator: ${enable_ccid}
|
CCID emulator: ${enable_ccid}
|
||||||
PACE support: ${enable_pace}
|
PACE support: ${enable_pace}
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ opensc: opensc-$(OPENSCVERSION)
|
|||||||
cd $(top_builddir)/src && cp -r opensc-$(OPENSCVERSION) opensc
|
cd $(top_builddir)/src && cp -r opensc-$(OPENSCVERSION) opensc
|
||||||
|
|
||||||
libopensc.la: opensc
|
libopensc.la: opensc
|
||||||
cd $(top_builddir)/src/opensc && ./configure
|
cd $(top_builddir)/src/opensc && ./configure $(OPENSC_CONFIGURE)
|
||||||
$(MAKE) -C opensc
|
$(MAKE) -C opensc
|
||||||
cp $(top_builddir)/src/opensc/src/libopensc/.libs/libopensc* $(top_builddir)/src
|
cp $(top_builddir)/src/opensc/src/libopensc/.libs/libopensc* $(top_builddir)/src
|
||||||
|
|
||||||
|
|||||||
@@ -19,22 +19,20 @@ See file INSTALL.
|
|||||||
|
|
||||||
@subsection o HINTS ON OPENSC
|
@subsection o HINTS ON OPENSC
|
||||||
|
|
||||||
npa links against libopensc, which is discouraged and hindered since
|
libnpa links against libopensc, which is discouraged and hindered since
|
||||||
opensc>=0.12. We really need to get rid of this dependency. But since this is a
|
opensc>=0.12. We really need to get rid of this dependency. But so far we
|
||||||
lot of work, you will have to use older versions of opensc.
|
manually build it to have libopensc for linking. The good thing is that you
|
||||||
|
don't need any opensc components to be installed. The bad thing is, that libnpa
|
||||||
|
configures and builds opensc on its own. So you might need to pass some extra
|
||||||
|
configure options to opensc. So if you need to pass options to opensc, use
|
||||||
|
something like the following command:
|
||||||
|
./configure \
|
||||||
|
OPENSC_CONFIGURE="options"
|
||||||
|
|
||||||
OpenSC older than r4244 will yield something like this error:
|
Worse gets the situation if you need to link against libnpa and some opensc
|
||||||
|
library at the same time. This will yield conflicts since functionality of
|
||||||
[default] apdu.c:341:sc_check_apdu: Invalid Case 4 short APDU:
|
libopensc is linked into both libraries. This is possible (see ccid-emulator),
|
||||||
cse=04 cla=10 ins=86 p1=00 p2=00 lc=2 le=0
|
but not recommended. Only do this if you know what you are doing.
|
||||||
resp=0x10353c0 resplen=256 data=0x1034a30 datalen=2
|
|
||||||
[default] pace.c:1110:EstablishPACEChannel: Could not get encrypted nonce from card (General Authenticate step 1 failed).
|
|
||||||
|
|
||||||
This requires the following patch:
|
|
||||||
http://www.opensc-project.org/opensc/raw-attachment/ticket/209/le0.patch
|
|
||||||
|
|
||||||
The following patch makes the hex dumped output more readable:
|
|
||||||
http://www.opensc-project.org/opensc/raw-attachment/ticket/263/hex_dump_align.2.patch
|
|
||||||
|
|
||||||
|
|
||||||
@subsection o HINTS ON OPENSSL
|
@subsection o HINTS ON OPENSSL
|
||||||
|
|||||||
@@ -39,8 +39,6 @@ AC_TRY_LINK_FUNC(parse_ef_card_access, [ AC_MSG_RESULT([yes]) ], [ AC_MSG_ERROR(
|
|||||||
|
|
||||||
CPPFLAGS="$saved_CPPFLAGS"
|
CPPFLAGS="$saved_CPPFLAGS"
|
||||||
LIBS="$saved_LIBS"
|
LIBS="$saved_LIBS"
|
||||||
AC_SUBST(OPENSSL_CFLAGS)
|
|
||||||
AC_SUBST(OPENSSL_LIBS)
|
|
||||||
|
|
||||||
AC_DEFINE(BUERGERCLIENT_WORKAROUND, 1, [Always get EF.CardAccess, when connecting to a smart card. This is a workaround for the recent Buergerclient])
|
AC_DEFINE(BUERGERCLIENT_WORKAROUND, 1, [Always get EF.CardAccess, when connecting to a smart card. This is a workaround for the recent Buergerclient])
|
||||||
|
|
||||||
@@ -58,6 +56,9 @@ fi
|
|||||||
AM_CONDITIONAL(DOC_ENABLED, [test x"$enable_doc" = xyes])
|
AM_CONDITIONAL(DOC_ENABLED, [test x"$enable_doc" = xyes])
|
||||||
|
|
||||||
|
|
||||||
|
AC_SUBST(OPENSC_CONFIGURE)
|
||||||
|
|
||||||
|
|
||||||
# Checks for header files.
|
# Checks for header files.
|
||||||
AC_CHECK_HEADERS([arpa/inet.h fcntl.h memory.h stdint.h stdlib.h string.h sys/ioctl.h unistd.h])
|
AC_CHECK_HEADERS([arpa/inet.h fcntl.h memory.h stdint.h stdlib.h string.h sys/ioctl.h unistd.h])
|
||||||
|
|
||||||
@@ -93,6 +94,7 @@ Linker flags: ${LDFLAGS}
|
|||||||
Libraries: ${LIBS}
|
Libraries: ${LIBS}
|
||||||
OPENSSL_CFLAGS: ${OPENSSL_CFLAGS}
|
OPENSSL_CFLAGS: ${OPENSSL_CFLAGS}
|
||||||
OPENSSL_LIBS: ${OPENSSL_LIBS}
|
OPENSSL_LIBS: ${OPENSSL_LIBS}
|
||||||
|
OPENSC_CONFIGURE: ${OPENSC_CONFIGURE}
|
||||||
|
|
||||||
Documentation: ${enable_doc}
|
Documentation: ${enable_doc}
|
||||||
|
|
||||||
|
|||||||
@@ -6,6 +6,6 @@ includedir=@includedir@
|
|||||||
Name: libpace
|
Name: libpace
|
||||||
Description: Password Authenticated Connection Establishment (PACE) library
|
Description: Password Authenticated Connection Establishment (PACE) library
|
||||||
Version: @VERSION@
|
Version: @VERSION@
|
||||||
Requires: libopensc libssl
|
Requires: libssl
|
||||||
Libs: -L${libdir} -lpace
|
Libs: -L${libdir} -lpace
|
||||||
Cflags: -I${includedir}
|
Cflags: -I${includedir}
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ opensc: opensc-$(OPENSCVERSION)
|
|||||||
cd $(top_builddir)/src && cp -r opensc-$(OPENSCVERSION) opensc
|
cd $(top_builddir)/src && cp -r opensc-$(OPENSCVERSION) opensc
|
||||||
|
|
||||||
libopensc.la: opensc
|
libopensc.la: opensc
|
||||||
cd $(top_builddir)/src/opensc && ./configure
|
cd $(top_builddir)/src/opensc && ./configure $(OPENSC_CONFIGURE)
|
||||||
$(MAKE) -C opensc
|
$(MAKE) -C opensc
|
||||||
cp $(top_builddir)/src/opensc/src/libopensc/.libs/libopensc* $(top_builddir)/src
|
cp $(top_builddir)/src/opensc/src/libopensc/.libs/libopensc* $(top_builddir)/src
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user