background image

3. Additionally Microsoft Visual Studio is required to build OpenSSL and BIND. Microsoft Visual

Studio 2005 (Visual Studio 8) with Service Pack 1 and Service Pack 1 Update for Windows

Vista

5

is used here.

4. Set necessary environment variables for running Visual Studio from the command line, run the

following command from the command line:

”C:\Program Files\Microsoft\Visual Studio 8\Common7\

Tools\vsvars32.bat”

5. Configure OpenSSL as follows:

cd openssl-0.9.8l

perl Configure VC-WIN32 \

--pk11-libname=c:/windows/system32/cs2_pkcsll.dll \

--pk11-flavor=crypto-accelerator

The given

pk11-libname

parameter points to the path of the PKCS#11 library, pk11-flavor de-

termines which kind of PKCS#11 engine (provided by the patch) is used - sign-only or crypto-

accelerator. The optional prefix parameter would point to the directory where the libraries and

the OpenSSL configuration file are additionally copied during the installation of OpenSSL.

6. Build OpenSSL with these command line tools

ms\do_masm

nmake -f ms\ntdll.mak

7. Check the availability of the engine before you install BIND running the command:

out32dll\openssl.exe engine pkcs11 -t

If the previuous check isn’t successfully, test the accessibility of the PKCS#11 slot first.

p11tool slot=0 GetSlotInfo

The folder

out32dll

now contains the PKCS#11 enabled OpenSSL libraries for BIND.

8. Make the modified OpenSSL suite available in c:\usr\local\ssl or to the directory specified by

the prefix parameter in configuration by running the command:

nmake -f ms\ntdll.mak install

5

Service Pack 1 and Service Pack 1 Update for Windows Vista - http://support.microsoft.com/kb/929470

Page 11

Содержание Bind 9

Страница 1: ...Integration Guide Bind 9 Linux 3 19 Microsoft Windows Server 2008...

Страница 2: ...rved No part of this documentation may be reproduced in any form printing photocopy or according to any other process without the written approval of Utimaco IS GmbH or be processed reproduced or dist...

Страница 3: ...s 7 4 1 Con gure PKCS 11 Environment 7 4 1 1 Linux 7 4 1 2 Microsoft Windows 7 4 1 3 Adjust Con guration File 7 4 2 Test PKCS 11 Environment 8 4 3 Patch and Build OpenSSL 9 4 3 1 Linux 9 4 3 2 Microso...

Страница 4: ...et The original design of the Domain Name System did not include any security Instead it was developed as a simple scalable distributed system The Domain Name System Security Extensions DNSSEC attempt...

Страница 5: ...eries S Series Se Series PCI CryptoServer CS Series S Series Se Series LAN CryptoServer Simulator CS Se HSM Firmware CryptoServer 2 50 Software CryptoServer 2 50 Linux 3 19 Ubuntu 15 04 amd64 Microsof...

Страница 6: ...I LAN Installation Operating manual There is no need to install any software speci c for running CryptoServer 3 2 Install CryptoServer Software The CryptoServer software this includes administrative t...

Страница 7: ...soft Windows operating system Therefore the procedures to setup the PKCS 11 respectively PKCS 11 R2 environment is described separately 4 1 1 Linux The PKCS 11 library and con guration les for Linux o...

Страница 8: ...g Installation Manual For debugging purposes change the parameter Logging from value 0 which means no logging to 15 respectively 5 for PKCS 11 R2 to provide full logging details 4 2 Test PKCS 11 Envir...

Страница 9: ...PKCS 11 The patch is bundled with the BIND source code Download and extract the sources for OpenSSL 2 and Bind 93 rst 4 3 1 Linux 1 Apply the patch Bind 9 7 2 bind 9 7 2 P3 bin pkcs11 openssl 0 9 8l...

Страница 10: ...some errors occur at this point recheck the con guration 4 Check the availability of the engine by running the command apps openssl engine pkcs11 t 5 Install OpenSSL binary make install To make the mo...

Страница 11: ...patch is used sign only or crypto accelerator The optional pre x parameter would point to the directory where the libraries and the OpenSSL con guration le are additionally copied during the installa...

Страница 12: ...ine configure CC gcc m32 enable threads with openssl opt openssl p11 with pkcs11 usr lib cryptoserver libcs2_pkcs11 so If you are on a 64 bit machine con gure BIND via configure CC gcc m64 enable thre...

Страница 13: ...prepares the contents of Build Release directory for BIND installation with mod i ed OpenSSL libraries 3 Install BIND from the Build Release folder Further steps usually concern general con guration...

Страница 14: ...more You will be prompted to enter the user pin for the PKCS 11 slot 2 Switch to the default folder for zone les and generate the key les for BIND dnssec keyfromlabel l ksk f KSK utimaco com dnssec k...

Страница 15: ...ones or new records inserted via nsupdate Therefore named requires access to the private key unattended from user interaction For PKCS 11 you have to provide the user pin of the PKCS 11 slot to access...

Страница 16: ...f the information and support which is provided by the Utimaco IS GmbH Additional documentation can be found on the product CD in the documentation directory All CryptoServer product documentation is...

Страница 17: ...Page 17...

Страница 18: ...Integration Guide Bind 9 Page 18...

Страница 19: ...Page 19...

Страница 20: ...Contact Utimaco IS GmbH Germanusstra e 4 D 52080 Aachen Germany phone 49 241 1696 200 fax 49 241 1696 199 web https hsm utimaco com email support cs utimaco com...

Отзывы: