Enhance FES docs, plans, and SoftHSM integration
Updated README.md for clarity and added official references. Introduced detailed infrastructure and integration plans for FES, including phased implementation, deployment options, and risk mitigations. Added FES workflow diagrams in draw.io and PDF formats. Documented SoftHSM testing process and integration details in ticket.md. Improved alignment with clean architecture principles and production readiness.
This commit is contained in:
@@ -0,0 +1,301 @@
|
||||
# FES Signature Infrastructure Plan
|
||||
|
||||
## 1. Goal
|
||||
|
||||
Build a reusable and modular cryptography infrastructure in `EnvelopeGenerator.Infrastructure.Crypt` to support FES (Advanced Electronic Signature) workflows.
|
||||
|
||||
This module must:
|
||||
|
||||
- use PKCS#11 providers (SoftHSMv2 first, real HSM later),
|
||||
- stay independent from UI/API concerns,
|
||||
- expose clean interfaces to `Application` layer use-cases,
|
||||
- support future extensions (timestamping, certificate chain validation, multiple key algorithms).
|
||||
|
||||
---
|
||||
|
||||
## 2. Context and Constraints
|
||||
|
||||
1. SoftHSMv2 is **not** a REST service. It is a PKCS#11 module loaded as a native library.
|
||||
2. `EnvelopeGenerator.Server` is presentation only; cryptographic implementation belongs to infrastructure.
|
||||
3. Clean Architecture boundaries must be respected:
|
||||
- `Application` depends on abstractions.
|
||||
- `Infrastructure.Crypt` implements abstractions.
|
||||
4. Initial target framework is `net8.0`.
|
||||
5. We need production-ready behavior, not only PoC signing.
|
||||
|
||||
---
|
||||
|
||||
## 3. High-Level Design
|
||||
|
||||
## 3.1 Architecture slice
|
||||
|
||||
- **Application layer (contracts/use-cases):**
|
||||
- request signing hash/document,
|
||||
- request certificate/public key material,
|
||||
- request verification,
|
||||
- consume signature evidence result.
|
||||
|
||||
- **Infrastructure.Crypt layer (this project):**
|
||||
- PKCS#11 session handling,
|
||||
- key/certificate object discovery,
|
||||
- hash signing operations,
|
||||
- local cryptographic verification,
|
||||
- certificate parsing helpers,
|
||||
- error normalization.
|
||||
|
||||
## 3.2 Provider model
|
||||
|
||||
Define provider-agnostic APIs and add one concrete provider first:
|
||||
|
||||
- `Pkcs11SignatureProvider` (primary)
|
||||
- future providers:
|
||||
- `RemoteSigningProvider` (if a dedicated signing gateway is introduced)
|
||||
- `MockSignatureProvider` (for deterministic test scenarios)
|
||||
|
||||
---
|
||||
|
||||
## 4. Deliverables (Phase by Phase)
|
||||
|
||||
## Phase 0 - Contracts and Domain Language
|
||||
|
||||
Create neutral models and interfaces in `Infrastructure.Crypt` (or shared abstractions if needed later):
|
||||
|
||||
- `SigningAlgorithm` (enum/value object)
|
||||
- `Pkcs11ProviderOptions`
|
||||
- `KeyLocator` (label/id/slot/token selectors)
|
||||
- `SignHashRequest`
|
||||
- `SignHashResult`
|
||||
- `VerifySignatureRequest`
|
||||
- `VerifySignatureResult`
|
||||
- `CertificateDescriptor`
|
||||
- `SignatureEvidence` (technical evidence payload)
|
||||
|
||||
Interfaces:
|
||||
|
||||
- `ISignatureProvider`
|
||||
- `ICertificateProvider`
|
||||
- `ISignatureVerifier`
|
||||
- `ICryptographicHealthCheck`
|
||||
|
||||
Acceptance criteria:
|
||||
|
||||
- no dependency on ASP.NET types,
|
||||
- no UI/API naming leakage,
|
||||
- all model names are business-neutral.
|
||||
|
||||
## Phase 1 - PKCS#11 Core Adapter (SoftHSM-ready)
|
||||
|
||||
Implement:
|
||||
|
||||
- `Pkcs11LibraryLoader`
|
||||
- `Pkcs11SessionFactory`
|
||||
- `Pkcs11ObjectFinder`
|
||||
- `Pkcs11SignatureProvider`
|
||||
- `Pkcs11CertificateProvider`
|
||||
|
||||
Capabilities:
|
||||
|
||||
1. load module path from options (`libsofthsm2.so` or proxy module when required),
|
||||
2. enumerate slots/tokens,
|
||||
3. open read-write session,
|
||||
4. login with user pin,
|
||||
5. find private key by label/id,
|
||||
6. sign digest with selected mechanism,
|
||||
7. read certificate object by label/id.
|
||||
|
||||
Acceptance criteria:
|
||||
|
||||
- deterministic disposal of sessions,
|
||||
- no leaked native handles,
|
||||
- detailed typed errors (not raw exception strings only).
|
||||
|
||||
## Phase 2 - Verification and Certificate Utilities
|
||||
|
||||
Implement:
|
||||
|
||||
- `DefaultSignatureVerifier`
|
||||
- `X509CertificateParser`
|
||||
- optional `CertificateChainValidator` (toggleable)
|
||||
|
||||
Capabilities:
|
||||
|
||||
1. verify signature using returned certificate/public key,
|
||||
2. expose certificate metadata (`thumbprint`, `subject`, `issuer`, `notBefore`, `notAfter`),
|
||||
3. map validation failures into stable error codes.
|
||||
|
||||
Acceptance criteria:
|
||||
|
||||
- same request yields same verification outcome,
|
||||
- invalid signature returns structured negative result.
|
||||
|
||||
## Phase 3 - Evidence Builder
|
||||
|
||||
Implement:
|
||||
|
||||
- `SignatureEvidenceBuilder`
|
||||
|
||||
Evidence payload should contain:
|
||||
|
||||
- transaction/correlation id,
|
||||
- algorithm,
|
||||
- hash metadata,
|
||||
- key locator snapshot (safe subset),
|
||||
- certificate fingerprint and subject,
|
||||
- sign timestamp (UTC),
|
||||
- verification outcome,
|
||||
- provider type (`PKCS11`).
|
||||
|
||||
Acceptance criteria:
|
||||
|
||||
- no secret values in evidence (pin, private key id internals),
|
||||
- evidence serializable for storage/audit.
|
||||
|
||||
## Phase 4 - Dependency Injection Module
|
||||
|
||||
Implement:
|
||||
|
||||
- `CryptInfrastructureDependencyInjection` extension methods
|
||||
|
||||
Methods:
|
||||
|
||||
- `AddCryptInfrastructure(...)`
|
||||
- `AddPkcs11Provider(...)`
|
||||
|
||||
Acceptance criteria:
|
||||
|
||||
- one-line registration from composition root,
|
||||
- options validation on startup.
|
||||
|
||||
## Phase 5 - Test Suite (`EnvelopeGenerator.Tests`)
|
||||
|
||||
Add test categories for `net8.0`:
|
||||
|
||||
1. `Unit`:
|
||||
- request validation,
|
||||
- algorithm mapping,
|
||||
- evidence building,
|
||||
- error mapping.
|
||||
2. `Integration` (conditional/manual profile):
|
||||
- SoftHSM slot listing,
|
||||
- login,
|
||||
- sign hash,
|
||||
- verify,
|
||||
- certificate read.
|
||||
|
||||
Acceptance criteria:
|
||||
|
||||
- unit tests run in CI without native SoftHSM,
|
||||
- integration tests run when module path + pins are provided via environment variables.
|
||||
|
||||
---
|
||||
|
||||
## 5. Proposed Project Structure
|
||||
|
||||
```text
|
||||
EnvelopeGenerator.Infrastructure.Crypt/
|
||||
Abstractions/
|
||||
ISignatureProvider.cs
|
||||
ICertificateProvider.cs
|
||||
ISignatureVerifier.cs
|
||||
ICryptographicHealthCheck.cs
|
||||
Models/
|
||||
SigningAlgorithm.cs
|
||||
SignHashRequest.cs
|
||||
SignHashResult.cs
|
||||
VerifySignatureRequest.cs
|
||||
VerifySignatureResult.cs
|
||||
SignatureEvidence.cs
|
||||
CertificateDescriptor.cs
|
||||
KeyLocator.cs
|
||||
Options/
|
||||
Pkcs11ProviderOptions.cs
|
||||
Pkcs11/
|
||||
Pkcs11LibraryLoader.cs
|
||||
Pkcs11SessionFactory.cs
|
||||
Pkcs11ObjectFinder.cs
|
||||
Pkcs11SignatureProvider.cs
|
||||
Pkcs11CertificateProvider.cs
|
||||
Verification/
|
||||
DefaultSignatureVerifier.cs
|
||||
X509CertificateParser.cs
|
||||
Evidence/
|
||||
SignatureEvidenceBuilder.cs
|
||||
DependencyInjection/
|
||||
CryptInfrastructureDependencyInjection.cs
|
||||
Exceptions/
|
||||
CryptographicOperationException.cs
|
||||
Pkcs11ProviderException.cs
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 6. Configuration Strategy
|
||||
|
||||
Use options (bound from host config) with environment override support:
|
||||
|
||||
- `Crypt:Provider = PKCS11`
|
||||
- `Crypt:Pkcs11:LibraryPath`
|
||||
- `Crypt:Pkcs11:SlotId` or token selectors
|
||||
- `Crypt:Pkcs11:UserPin` (from secret store/env, not plain committed value)
|
||||
- `Crypt:Pkcs11:PrivateKeyLabel`
|
||||
- `Crypt:Pkcs11:CertificateLabel`
|
||||
- `Crypt:Pkcs11:LoginType`
|
||||
|
||||
Validation rules:
|
||||
|
||||
- library path required,
|
||||
- at least one key locator required,
|
||||
- pin required for signing operations.
|
||||
|
||||
---
|
||||
|
||||
## 7. Error Model
|
||||
|
||||
Define stable error codes to prevent provider-specific leakage:
|
||||
|
||||
- `CRYPT_PROVIDER_UNAVAILABLE`
|
||||
- `CRYPT_SLOT_NOT_FOUND`
|
||||
- `CRYPT_LOGIN_FAILED`
|
||||
- `CRYPT_KEY_NOT_FOUND`
|
||||
- `CRYPT_CERT_NOT_FOUND`
|
||||
- `CRYPT_SIGN_FAILED`
|
||||
- `CRYPT_VERIFY_FAILED`
|
||||
|
||||
Map low-level exceptions to these codes with safe diagnostics.
|
||||
|
||||
---
|
||||
|
||||
## 8. Non-Functional Requirements
|
||||
|
||||
1. **Security:** never log pins or raw private key handles.
|
||||
2. **Reliability:** deterministic cleanup (`IDisposable`/`IAsyncDisposable`).
|
||||
3. **Observability:** structured logs with correlation id.
|
||||
4. **Performance:** avoid repeated login per operation when a safe session strategy is available.
|
||||
5. **Extensibility:** algorithm/provider mapping must be open for extension.
|
||||
|
||||
---
|
||||
|
||||
## 9. Implementation Order (Small Tasks)
|
||||
|
||||
1. Add models + interfaces.
|
||||
2. Add options + validators.
|
||||
3. Add PKCS#11 low-level loader/session wrappers.
|
||||
4. Implement `Pkcs11SignatureProvider` for hash signing.
|
||||
5. Implement certificate retrieval.
|
||||
6. Implement verifier.
|
||||
7. Implement evidence builder.
|
||||
8. Add DI registration extension.
|
||||
9. Add unit tests.
|
||||
10. Add optional integration tests (SoftHSM profile).
|
||||
|
||||
---
|
||||
|
||||
## 10. Definition of Done
|
||||
|
||||
Done means:
|
||||
|
||||
1. `Infrastructure.Crypt` exposes generic cryptographic services usable by Application use-cases.
|
||||
2. SoftHSM-backed PKCS#11 sign/verify path works in integration tests.
|
||||
3. All sensitive configuration is externalized.
|
||||
4. Structured error codes are returned for expected failure scenarios.
|
||||
5. Documentation exists for host registration and required settings.
|
||||
@@ -0,0 +1,228 @@
|
||||
# FES (Advanced Electronic Signature) Summary and Integration Plan - EN
|
||||
|
||||
This document summarizes the shared diagram flow (`Ablauf SignFlow Unternehmenszertifikat`) and provides a small-step integration plan for the `EnvelopeGenerator` solution.
|
||||
|
||||
---
|
||||
|
||||
## 1) Simplified flow summary
|
||||
|
||||
Flow logic:
|
||||
|
||||
1. The sender uploads a document and defines signers.
|
||||
2. If a valid company certificate already exists in HSM, it is used with the company key pair.
|
||||
3. If no valid company certificate exists, CA issuance/renewal flow is required.
|
||||
4. The signer receives an e-mail with a signing link.
|
||||
5. The signer completes SMS OTP (2FA) and performs UI signature interaction.
|
||||
6. Backend computes the hash for the current signing stage and sends it to HSM.
|
||||
7. HSM signs the hash with the private key and returns signature + certificate context.
|
||||
8. Backend embeds digital signature and certificate into PDF and writes audit trail.
|
||||
9. After all signers complete, the final artifact is archived.
|
||||
10. The final signed document is distributed to signers.
|
||||
|
||||
Important: The visible UI signature is not yet the legal electronic signature. The legal signature is produced in backend+HSM steps.
|
||||
|
||||
---
|
||||
|
||||
## 2) Relation to current codebase (as-is)
|
||||
|
||||
- `EnvelopeGenerator.Server` is the presentation layer host (Blazor + API hosting).
|
||||
- Business flow is handled in `Application` via MediatR pipelines.
|
||||
- Current receiver flow is centered around UI overlay/signature capture.
|
||||
- Missing FES core: PKCS#11 hash-sign-verify + certificate-based PDF embedding pipeline.
|
||||
|
||||
Critical deployment fact:
|
||||
|
||||
- `EnvelopeGenerator.Server` is planned to run on Windows.
|
||||
- SoftHSM is currently planned to run on Linux.
|
||||
- A Windows process cannot directly load Linux PKCS#11 module (`libsofthsm2.so`).
|
||||
- Therefore, architecture must include a compatibility bridge (service or proxy) unless HSM/SoftHSM is local to Windows.
|
||||
|
||||
Conclusion: FES is not a replacement of the current flow; it is a cryptographic hardening layer behind it.
|
||||
|
||||
---
|
||||
|
||||
## 3) Why SoftHSM tests are foundational
|
||||
|
||||
The tests defined in `SOFTHSM_TEST_KILAVUZU_TR.md` are the technical prerequisite for FES:
|
||||
|
||||
- `slots/login` -> HSM connectivity and authentication
|
||||
- `certificate` -> certificate retrieval path
|
||||
- `sign` -> hash signing with private key
|
||||
- `verify` -> signature and certificate consistency validation
|
||||
|
||||
Without these tests passing, diagram steps 6-8 should not go live.
|
||||
|
||||
---
|
||||
|
||||
## 4) Target architecture (clean architecture aligned)
|
||||
|
||||
### Deployment topology options (must choose one)
|
||||
|
||||
1. **Linux signing service (recommended)**
|
||||
- Windows `EnvelopeGenerator.Server` calls Linux signing API over HTTPS.
|
||||
- Linux signing service performs PKCS#11 operations against SoftHSM.
|
||||
- Private keys never leave Linux/HSM boundary.
|
||||
|
||||
2. **PKCS#11 proxy bridge**
|
||||
- Windows host loads a Windows PKCS#11 proxy client DLL.
|
||||
- Proxy forwards PKCS#11 operations to Linux side connected to SoftHSM.
|
||||
|
||||
3. **Windows-local SoftHSM (dev/test)**
|
||||
- SoftHSM also installed on Windows and used locally.
|
||||
- Useful for local testing, not preferred production topology.
|
||||
|
||||
Decision note:
|
||||
|
||||
- For production-critical FES, choose option 1 by default unless enterprise HSM policy requires option 2.
|
||||
- Keep option 3 for development convenience only.
|
||||
|
||||
### Layer responsibilities
|
||||
|
||||
- `EnvelopeGenerator.Server`:
|
||||
- API endpoints, auth orchestration, input validation.
|
||||
- FES branch routing: standard-sign path vs external signing-service/proxy path.
|
||||
- No private-key material handling.
|
||||
|
||||
- `EnvelopeGenerator.Application`:
|
||||
- Use cases such as `SignWithHsmCommand`.
|
||||
- MediatR pipeline orchestration for status/history/audit.
|
||||
- FES evidence model aggregation (ip/email/phone/user-agent/otp proof/timestamps).
|
||||
|
||||
- `EnvelopeGenerator.Infrastructure`:
|
||||
- Implementations for `IPkcs11Service`, `IPdfSignatureService`, `ITimestampService`.
|
||||
- Pkcs11Interop integration and cryptographic operations.
|
||||
- Optional client for Linux signing service if topology option 1 is selected.
|
||||
|
||||
- `Domain`:
|
||||
- Signature evidence and audit-trail models.
|
||||
|
||||
---
|
||||
|
||||
## 5) Small-step integration plan
|
||||
|
||||
## Phase 0 - Scope and contracts
|
||||
|
||||
1. Finalize signing algorithms (for example `SHA256_RSA_PKCS`).
|
||||
2. Confirm strategy: company certificate vs signer-specific certificate.
|
||||
3. Freeze mandatory audit fields:
|
||||
- identity, OTP proof, IP, user-agent, transaction id, timestamps, hash metadata.
|
||||
4. Freeze deployment topology decision:
|
||||
- option 1 (Linux signing service), option 2 (PKCS#11 proxy), or option 3 (Windows-local SoftHSM).
|
||||
5. Define production host mapping:
|
||||
- where `EnvelopeGenerator.Server` runs,
|
||||
- where HSM/SoftHSM runs,
|
||||
- where certificate lifecycle is managed.
|
||||
|
||||
Deliverable: Technical decision record (ADR-style markdown).
|
||||
|
||||
## Phase 1 - PKCS#11 connector (infrastructure)
|
||||
|
||||
1. Define `IPkcs11Service` interface.
|
||||
2. Add `Pkcs11Interop` implementation.
|
||||
3. Add config model:
|
||||
- library path, slot, token label, key label, certificate label.
|
||||
4. Ensure secure secret handling for PIN.
|
||||
5. Ensure host-compatible module loading:
|
||||
- Windows server must load Windows DLL,
|
||||
- Linux server must load Linux `.so`.
|
||||
|
||||
Deliverable: Testable PKCS#11 service with health/slot/login/sign/verify capabilities.
|
||||
|
||||
## Phase 1.5 - Cross-host bridge implementation
|
||||
|
||||
1. If option 1 selected:
|
||||
- implement Linux signing service API contract (`/sign`, `/certificate`, `/health`),
|
||||
- implement authenticated HTTP client in `EnvelopeGenerator.Server`.
|
||||
2. If option 2 selected:
|
||||
- install/configure PKCS#11 proxy client DLL on Windows,
|
||||
- install/configure proxy server on Linux and bind to SoftHSM.
|
||||
|
||||
Deliverable: Windows-to-Linux signing communication path proven end-to-end.
|
||||
|
||||
## Phase 2 - Application use case
|
||||
|
||||
1. Add `SignDocumentHashCommand` (or equivalent).
|
||||
2. Pipeline flow:
|
||||
- compute/receive hash,
|
||||
- sign with HSM,
|
||||
- attach certificate context,
|
||||
- verify,
|
||||
- produce evidence object.
|
||||
3. Add resilient error mapping and retry strategy.
|
||||
|
||||
Deliverable: HSM signing use case in Application layer.
|
||||
|
||||
## Phase 3 - PDF signature embedding
|
||||
|
||||
1. Implement PDF signature embedding via `IPdfSignatureService`.
|
||||
2. Build signer-specific audit-trail pages.
|
||||
3. Append all audit pages to final PDF artifact.
|
||||
|
||||
Deliverable: Signed PDF with certificate context and audit trail pages.
|
||||
|
||||
## Phase 4 - Presentation/API integration
|
||||
|
||||
1. Integrate FES option into submit flow (feature flag guarded).
|
||||
2. Add operational endpoints:
|
||||
- HSM health/check
|
||||
- signature evidence query (restricted roles)
|
||||
3. Keep DTOs safe; avoid exposing sensitive cryptographic material.
|
||||
4. In `SignatureController.Submit`, add FES branch that sends signing payload + audit context to selected signing backend.
|
||||
|
||||
Deliverable: API-level orchestration with minimal UI disruption.
|
||||
|
||||
## Phase 5 - Audit, archive, distribution
|
||||
|
||||
1. Persist signature evidence records.
|
||||
2. Include hash/cert metadata in archival package.
|
||||
3. Add signed artifact reference to distribution e-mails.
|
||||
|
||||
Deliverable: Alignment with diagram steps 9-10.
|
||||
|
||||
## Phase 6 - Testing and operations
|
||||
|
||||
1. Postman collection + Newman automation.
|
||||
2. Positive/negative matrix:
|
||||
- wrong pin, wrong slot, missing cert, expired cert, HSM timeout.
|
||||
3. Observability:
|
||||
- structured logs, correlation id, latency metrics.
|
||||
|
||||
Deliverable: Production readiness checklist.
|
||||
|
||||
---
|
||||
|
||||
## 6) Transition strategy from test API to production flow
|
||||
|
||||
1. Keep `/api/pkcs11-test/*` only for non-production.
|
||||
2. In production, use the same internal services through business endpoints only.
|
||||
3. Roll out by feature flag:
|
||||
- `FesEnabled=false` initially
|
||||
- pilot sender group
|
||||
- full rollout
|
||||
|
||||
4. Keep explicit environment matrix:
|
||||
- local dev (option 3),
|
||||
- integration/staging (option 1 or 2),
|
||||
- production (option 1 or 2 only).
|
||||
|
||||
---
|
||||
|
||||
## 7) Risks and mitigations
|
||||
|
||||
- Certificate expiry risk -> proactive monitoring and renewal alerting.
|
||||
- HSM connectivity risk -> retry policy, circuit breaker, fallback queue.
|
||||
- PIN/secret exposure risk -> vault-backed secrets and rotation policy.
|
||||
- Verification failure risk -> block PDF sealing and move envelope to technical hold state.
|
||||
- Cross-host connectivity risk -> mTLS/JWT auth + timeout/retry/circuit breaker + health probe.
|
||||
|
||||
---
|
||||
|
||||
## 8) Short done checklist
|
||||
|
||||
- [ ] PKCS#11 service interface + implementation
|
||||
- [ ] Application command + pipeline behaviors
|
||||
- [ ] PDF signature embedding
|
||||
- [ ] Audit-trail generation
|
||||
- [ ] API integration + feature flag
|
||||
- [ ] Postman/Newman regression suite
|
||||
- [ ] Operational runbook and alerting rules
|
||||
File diff suppressed because one or more lines are too long
Binary file not shown.
84
EnvelopeGenerator.Infrastructure.Crypt/resources/ticket.md
Normal file
84
EnvelopeGenerator.Infrastructure.Crypt/resources/ticket.md
Normal file
@@ -0,0 +1,84 @@
|
||||
10/6/26, 10:46 PM
|
||||
|
||||
Test SoftHSM : SWINFRA-54
|
||||
|
||||
Projects / Infrastruktur Software / Issues /
|
||||
|
||||
Enter search…
|
||||
|
||||
SWINFRA-54
|
||||
|
||||
All…
|
||||
|
||||
Created by Marvin Kamm 3 months ago
|
||||
|
||||
Visible to issue readers 1
|
||||
|
||||
Updated by Matthias Dewald about 1 month ago
|
||||
|
||||
# **Test SoftHSM**
|
||||
|
||||
Project Priorität Status **SWI** Infrastruktur Softwa H Hoch O Offen re… Bearbeiter Fälligkeit Projekteinfluss MD _ ? ? Matthias Dewald Kein fälligkeit Kein projektbezug Boards No visible boards
|
||||
|
||||
Bitte eine Test-VM mit der Software SoftHSM bereitstellen.
|
||||
|
||||
Laut Info von @Henning Emrich soll die Installation unter Debian Linux deutlich einfacher sein, als unter Windows. Bitte prüfen.
|
||||
|
||||
@Hakan Tek & @OlgunR
|
||||
|
||||
Sollen bitte die API Ansteuerung testen
|
||||
|
||||
FYI
|
||||
|
||||
@Marlon Schreiber @Jan-Ulrich Hoss @Henning Emrich @Hakan Tek @OlgunR
|
||||
|
||||
**Attachments** 1
|
||||
|
||||
Files Attached to Comments
|
||||
|
||||
**PDF**
|
||||
|
||||
Ablauf SignFlow Un ternehme… 83 kB
|
||||
|
||||
MD _ **Matthias Dewald** Commented 3 months ago Ist für Dienstag 30.6 10:00 Uhr Eingeplant
|
||||
|
||||
HT **Hakan Tek** Commented 3 months ago
|
||||
|
||||
Für die Integration auf der .NET-Seite können wir die Pkcs11Interop-Bibliothek und die entsprechende DevExpress-Infrastruktur verwenden. @OlgunR, falls du noch weitere Vorschläge hast, füge sie bitte hinzu. @Marvin Kamm, @Henning Emrich, @Matthias Dewald, um mit den Tests beginnen zu können, benötigen wir die entsprechenden Verbindungsdaten für SoftHSM (Slot-ID, PIN, Bibliothekspfad usw.).
|
||||
|
||||
FYI
|
||||
|
||||
@Marlon Schreiber @Jan-Ulrich Hoss
|
||||
|
||||
bugtracker.dd:8080/issue/SWINFRA-54/Test-SoftHSM
|
||||
|
||||
1/2
|
||||
|
||||
10/6/26, 10:46 PM
|
||||
|
||||
Test SoftHSM : SWINFRA-54
|
||||
|
||||
MD
|
||||
|
||||
## **Matthias Dewald** Commented 3 months ago
|
||||
|
||||
Hallo zusammen, SoftHSM ist auf der 172.24.12.64 installiert:
|
||||
|
||||
Der Proxy läuft auf Port 5657 und erwartet Verbindungen über die Proxy-Bibliothek (libpkcs11-proxy.so)
|
||||
|
||||
@Hakan Tek Bitte testen
|
||||
|
||||
MD
|
||||
|
||||
## **Matthias Dewald** Commented about 1 month ago
|
||||
|
||||
Ablauf SignFlow Unternehmenszertifikat.drawio.pdf
|
||||
|
||||
**PDF**
|
||||
|
||||
Ablauf SignFlow Un ternehme… 83 kB
|
||||
|
||||
bugtracker.dd:8080/issue/SWINFRA-54/Test-SoftHSM
|
||||
|
||||
2/2
|
||||
|
||||
Reference in New Issue
Block a user