Testing with pkcs11-tool
Comprehensive guide for testing the DuoKey PKCS#11 library using OpenSC pkcs11-tool
Applies to:
OpenSC pkcs11-toolDuoKey PKCS#11 LibraryLinux / Windows
Prerequisites
Prerequisites
- OpenSC pkcs11-tool installed
- DuoKey PKCS#11 library compiled (libdke_pkcs11.so or dke_pkcs11.dll)
- A pkcs11.toml (path in DKE_PKCS11_CONF) or DKE_PKCS11_* variables configured (see Overview → Configuration)
Note
The PIN value (e.g.,
1234) can be any value as it is not currently validated by the library. It is required by pkcs11-tool syntax but ignored by the DuoKey library.General Information
Show Token Information
pkcs11-tool --module ./libdke_pkcs11.so --list-token-slots
List Supported Mechanisms
pkcs11-tool --module ./libdke_pkcs11.so --list-mechanisms
Listing Objects and Keys
List All Objects
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so --list-objects
List a Specific Key by Label
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--list-objects \
--label "test-key-RSA-2048"
Filter by Key Type
# List public keys only
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--list-objects \
--type pubkey
# List by key type (e.g., AES)
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--list-objects \
--key-type "AES"
Caution
The
--key-type filter is broken (not working) in pkcs11-tool version 0.26.Exporting Public Keys
Only public keys can be exported. Private keys remain protected in the Cockpit backend.
Export RSA Public Key
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--read-object \
--type pubkey \
--label "test-key-RSA-2048" \
--output-file test-key-RSA-2048.pubkey
Export ECC Public Key
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--read-object \
--type pubkey \
--label "test-key-ECC-256" \
--output-file test-key-ECC-256.pubkey
Encryption and Decryption
Important
For encrypt/decrypt operations, pkcs11-tool only supports key lookup by ID (not by label). Use the
--list-objects command above to discover the key ID to use.RSA Encrypt / Decrypt
# Encrypt
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--encrypt \
--mechanism RSA-PKCS-OAEP \
--hash-algorithm sha256 \
--mgf MGF1-SHA256 \
--id "63336235376338372d333734662d346366332d396231332d626532353837333865666336" \
--input-file plaintext.txt \
--output-file encrypted.txt
# Decrypt
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--decrypt \
--mechanism RSA-PKCS-OAEP \
--hash-algorithm sha256 \
--mgf MGF1-SHA256 \
--id "63336235376338372d333734662d346366332d396231332d626532353837333865666336" \
--input-file encrypted.txt \
--output-file plaintext-2.txt
AES-GCM Encrypt / Decrypt
# Encrypt with AES-GCM
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--encrypt \
--mechanism AES-GCM \
--iv 000102030405060708090a0b0c0d0e0f \
--aad "48656c6c6f" \
--tag-bits-len 128 \
--id "30613263353462622d643436322d343864632d613132302d343135326661393033323063" \
--input-file plaintext.txt \
--output-file encrypted-aes.txt
# Decrypt with AES-GCM
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--decrypt \
--mechanism AES-GCM \
--iv 000102030405060708090a0b0c0d0e0f \
--aad "48656c6c6f" \
--tag-bits-len 128 \
--id "30613263353462622d643436322d343864632d613132302d343135326661393033323063" \
--input-file encrypted-aes.txt \
--output-file plaintext-2-aes.txt
AES-CBC-PAD Encrypt / Decrypt
# Encrypt with AES-CBC-PAD
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--encrypt \
--mechanism AES-CBC-PAD \
--iv 000102030405060708090a0b0c0d0e0f \
--id "30613263353462622d643436322d343864632d613132302d343135326661393033323063" \
--input-file plaintext.txt \
--output-file encrypted-aes-cbc.txt
# Decrypt with AES-CBC-PAD
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--decrypt \
--mechanism AES-CBC-PAD \
--iv 000102030405060708090a0b0c0d0e0f \
--id "30613263353462622d643436322d343864632d613132302d343135326661393033323063" \
--input-file encrypted-aes-cbc.txt \
--output-file plaintext-2-aes-cbc.txt
Object Management
Objects are created by the key-generation commands below or discovered with --list-objects. Creating a data object with --write-object is not supported (C_CreateObject).
Delete a key
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--delete-object \
--type secrkey \
--label 'test-pkcs11-generated-key-aes-1'
Not supported
Creating objects (--write-object), copying objects and modifying attributes are not supported. See Function Coverage.
Key Generation
Generate RSA Key Pair
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--keypairgen \
--label 'test-pkcs11-generated-key-rsa' \
--key-type RSA:2048
Generate AES Key
pkcs11-tool -l --pin 1234 --module ./libdke_pkcs11.so \
--keygen \
--label 'test-pkcs11-generated-key-aes-1' \
--key-type AES:256
Caveats
Sign / verify and wrap / unwrap are supported (for RSA / EC keys; they do not apply to AES-only Oracle TDE master keys). The real caveats are:
| Item | Note |
|---|---|
| Object creation (--write-object) | Not supported (C_CreateObject / C_CopyObject / C_SetAttributeValue). |
| Multi-part operations | Only single-part encrypt / decrypt / sign / verify / digest are supported. |
| Key derivation | Not supported (C_DeriveKey). |
| SHA-1 digest | CKM_SHA_1 is advertised but rejected by the backend — use SHA-256 / 384 / 512. |
| --key-type filter | Broken in pkcs11-tool 0.26 (a pkcs11-tool bug, not the library). |