Running python-pkcs11 in Docker - DeviceError
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- docker, python
- Lĩnh vực
- cryptography, infrastructure, security
Hướng nghiên cứu
Start with the failing private_key.decrypt call in the Python snippet and compare the Docker run configuration with the host setup, including the bound pcscd socket, USB device access, and installed ykcs11 library. Use pcsc_scan as the baseline, then determine what differs during decryption; done means the same RSA_PKCS_OAEP operation succeeds inside the Ubuntu 22.04 container.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
When I try to execute PKCS#11 functions (with python-pkcs11 and ykcs11) inside a Docker (ubuntu 22.04) container, it fails in decrypt with DeviceError.
This is the code:
# Use the YubiKey PKCS#11 library.
PKCS11_LIB = "/usr/lib/x86_64-linux-gnu/libykcs11.so"
lib = pkcs11.lib(PKCS11_LIB)
with lib.get_token().open(user_pin=pin) as session:
private_key = session.get_key(object_class=ObjectClass.PRIVATE_KEY, key_type=KeyType.RSA, id=KEY_ID)
private_key.decrypt(encrypted_aes_key, mechanism=Mechanism.RSA_PKCS_OAEP) # Fails with error below
The error:
File "/usr/local/lib/python3.10/dist-packages/pkcs11/types.py", line 970, in decrypt
return self._decrypt(data, **kwargs)
File "pkcs11/_pkcs11.pyx", line 1631, in pkcs11._pkcs11.DecryptMixin._decrypt
File "pkcs11/_pkcs11.pyx", line 1634, in pkcs11._pkcs11.DecryptMixin._decrypt
File "pkcs11/_pkcs11.pyx", line 1562, in pkcs11._pkcs11.DataCryptOperation.crypt_process_fully
File "pkcs11/_pkcs11.pyx", line 693, in pkcs11._pkcs11.OperationWithBinaryOutput.process_fully
File "pkcs11/_pkcs11.pyx", line 583, in pkcs11._pkcs11.OperationContext._handle_final_retval
File "pkcs11/_pkcs11.pyx", line 47, in pkcs11._pkcs11.assertRV
pkcs11.exceptions.DeviceError
If I run the same command with the same installed tools on the host machine (ubuntu 22.04), it just works.
This is the docker command I use:
sudo docker run -it --rm \
--device /dev/bus/usb:/dev/bus/usb \
--mount type=bind,source=/run/pcscd/pcscd.comm,target=/run/pcscd/pcscd.comm \
--privileged \
$IMAGE
How to solve this issue?
pcsc_scan does find the YubiKey inside the docker without problem, with all properties.
- Ngôn ngữ chính
- Python
- Star
- 170
- Fork
- 79
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của pyauth/python-pkcs11
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 65/100
pyauth/python-pkcs11#225 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
pyauth/python-pkcs11#233 ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100
pyauth/python-pkcs11#228 · 3 bình luận ·
-
readthedocs.io setupĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
pyauth/python-pkcs11#211 · 1 bình luận ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
pyauth/python-pkcs11#192 · 2 bình luận ·
Tất cả issue của pyauth/python-pkcs11
Issue tương tự
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 82/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 64/100
agrc/palletjack#208 ·
-
status/needs-triage type/bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
PKU-YuanGroup/OpenAI4S#218 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Test LeakageCó thể đã có người làm @garland3 đã nhận hôm nay. Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
sandialabs/atlas-ui-3#1030 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 84/100
aws-samples/sample-ai-persona#151 ·
Maintainer thường phản hồi trong vòng 1 ngày