You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用SoftHSM2密钥生成CSR失败,提示Failed to enumerate slots in PKCS#11

PKCS#11枚举插槽失败,无法使用SoftHSM2密钥签署CSR

出现错误:Failed to enumerate slots in PKCS#11

SoftHSM2中已存在的密钥对象

通过pkcs11-tool可正常列出对象:

$ sudo pkcs11-tool --module /usr/lib/softhsm/libsofthsm2.so --list-objects -l
Using slot 0 with a present token (0x74a6136e)
Logging in to "token-label".
Please enter User PIN:
Private Key Object; RSA
  label:      foo
  ID:         1001
  Usage:      decrypt, sign, signRecover, unwrap
  Access:     sensitive, always sensitive, never extractable, local
Public Key Object; RSA 2048 bits
  label:      foo
  ID:         1001
  Usage:      encrypt, verify, verifyRecover, wrap
  Access:     local
Private Key Object; EC
  label:      key-label
  ID:         1001
  Usage:      decrypt, sign, signRecover, unwrap, derive
  Access:     sensitive, always sensitive, never extractable, local
Private Key Object; RSA
  label:      test
  ID:         01
  Usage:      decrypt, sign, signRecover, unwrap
  Access:     sensitive, always sensitive, never extractable, local
Public Key Object; EC  EC_POINT 256 bits
  EC_POINT:   044104677475aed10d3447f451513be316e97a12089c2c8fbb0b9a2f6baaaee341781b2dcf695d84e1b74452f194d97d904b1c5a92750764aaba08c59ebe7f8f189f74
  EC_PARAMS:  06082a8648ce3d030107 (OID 1.2.840.10045.3.1.7)
  label:      key-label
  ID:         1001
  Usage:      encrypt, verify, verifyRecover, wrap, derive
  Access:     local
Public Key Object; RSA 2048 bits
  label:      test
  ID:         01
  Usage:      encrypt, verify, verifyRecover, wrap
  Access:     local

签署CSR时的错误

执行以下命令尝试创建并签署CSR时失败:

$ OPENSSL_CONF=engine.conf sudo openssl req -new -subj '/CN=test/' -sha256 -engine pkcs11 -keyform engine -key 01 > my-request.csr
Engine "pkcs11" set.
Failed to enumerate slots
PKCS11_get_private_key returned NULL
Could not read private key from org.openssl.engine:pkcs11:01
40772E3E8E7F0000:error:40000067:pkcs11 engine:ERR_ENG_error:invalid parameter:eng_back.c:603:
40772E3E8E7F0000:error:13000080:engine routines:ENGINE_load_private_key:failed loading private key:../crypto/engine/eng_pkey.c:79:

已知情况:已更新PKCS#11路径,其余配置未变;手动注册引擎成功,但签署操作执行失败。


解决步骤

1. 检查engine.conf配置正确性

确保配置文件中指定了正确的PKCS#11引擎路径和SoftHSM2模块路径,示例配置:

[openssl_init]
engines = engine_section

[engine_section]
pkcs11 = pkcs11_section

[pkcs11_section]
engine_id = pkcs11
# 此路径为OpenSSL的pkcs11引擎文件路径,不同系统可能不同
dynamic_path = /usr/lib/x86_64-linux-gnu/engines-3/pkcs11.so
# SoftHSM2模块路径,与pkcs11-tool中使用的一致
MODULE_PATH = /usr/lib/softhsm/libsofthsm2.so
# 可选:预先指定PIN避免交互,生产环境谨慎使用
PIN = your_user_pin
init = 0

2. 解决权限问题

  • 运行sudo时环境变量可能丢失,可直接在命令中明确传递必要配置,或确保root用户能访问SoftHSM2的token目录:
sudo chown -R root:root /var/lib/softhsm/tokens/
sudo chmod -R 700 /var/lib/softhsm/tokens/

3. 明确指定Slot或Token标签

引擎可能无法自动定位到目标slot,尝试在命令中通过slot_<编号>-id_<密钥ID>或token_<标签>-id_<密钥ID>的格式指定密钥:

# 使用slot编号+密钥ID
OPENSSL_CONF=engine.conf sudo openssl req -new -subj '/CN=test/' -sha256 -engine pkcs11 -keyform engine -key slot_0-id_01 > my-request.csr

# 或使用token标签+密钥ID
OPENSSL_CONF=engine.conf sudo openssl req -new -subj '/CN=test/' -sha256 -engine pkcs11 -keyform engine -key token_token-label-id_01 > my-request.csr

4. 验证组件兼容性

确保OpenSSL、pkcs11引擎和SoftHSM2版本兼容,可尝试升级相关组件:

sudo apt update && sudo apt install --upgrade openssl libengine-pkcs11-openssl softhsm2

内容的提问来源于stack exchange,提问作者Hyfo36z

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 05:34:52