无法将PKCS#11引擎中的密钥加载到Nginx配置的问题
Nginx配置SSL从SoftHSM加载密钥失败问题
我正尝试在nginx.conf中配置SSL,需要从SoftHSM而非文件加载密钥。以下是/etc/nginx/nginx.conf文件内容:
user nginx; worker_processes 1; error_log /var/log/nginx/error.log debug; pid /var/run/nginx.pid; events { worker_connections 1024; } ssl_engine pkcs11; http { include /etc/nginx/mime.types; default_type application/octet-stream; server { listen 80; listen 443 ssl; ssl_protocols TLSv1.2 TLSv1.3; # include snippets/ssl-params.conf; server_name www.SEexample.com SEexample.com; ssl_certificate /etc/ssl/certs/seexample.com.crt; ssl_certificate_key "engine:pkcs11:pkcs11:model=SoftHSM%20v2;token=mytoken2;object=sekey;type=private?pin=1234"; root /var/www/html; index index.html; ssl_trusted_certificate /etc/ssl/certs/SEcombine2.crt; } log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /var/log/nginx/access.log main; sendfile on; #tcp_nopush on; keepalive_timeout 65; #gzip on; include /etc/nginx/conf.d/*.conf; }
执行sudo nginx -t测试时,出现如下错误:
Failed to enumerate slots PKCS11_get_private_key returned NULL nginx: [emerg] cannot load certificate key "engine:pkcs11:pkcs11:model=SoftHSM%20v2;token=mytoken2;object=sekey;": ENGINE_load_private_key() failed (SSL: error:26096080:engine routines:ENGINE_load_private_key:failed loading private key) free(): invalid pointer Aborted
注意事项
- 未配置
ssl_engine pkcs11且从文件加载ssl_certificate_key时,Nginx服务器可正常连接; - 以下命令可正常执行,说明PKCS#11 URI正确,但在Nginx.conf中尝试带pin、pin-value或不带pin的写法均无效:
sudo openssl req -engine pkcs11 -keyform engine -key "pkcs11:model=SoftHSM%20v2;token=mytoken2;object=sekey;type=private" -new -sha512 -out csr/secert.csr -config req.cnf
内容的提问来源于stack exchange,提问作者Hyfo36z
相关产品推荐
相关产品推荐

