From darrenm@sac.sfbay.sun.com Wed Oct 15 01:47:12 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m9F8lB9o002380
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 15 Oct 2008 01:47:11 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m9F8l5SZ005964;
	Wed, 15 Oct 2008 01:47:11 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K8R00710V2NAJ00@brm-avmta-1.central.sun.com>; Wed,
 15 Oct 2008 02:47:11 -0600 (MDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K8R005PLV2LQ220@brm-avmta-1.central.sun.com>; Wed,
 15 Oct 2008 02:47:10 -0600 (MDT)
Received: from sac.sfbay.sun.com (new-sac.SFBay.Sun.COM [129.146.175.65])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m9F8l9QS011516; Wed, 15 Oct 2008 01:47:09 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m9F8l83p002375; Wed,
 15 Oct 2008 01:47:08 -0700 (PDT)
Received: (from darrenm@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id m9F8l88a002371; Wed,
 15 Oct 2008 01:47:08 -0700 (PDT)
Date: Wed, 15 Oct 2008 01:47:08 -0700 (PDT)
From: Darren J Moffat <darrenm@sac.sfbay.sun.com>
Subject: PAM prompt configuration enhancement for the pam_pkcs11 module
 [PSARC/2008/635 Self Review]
To: PSARC-ext@sun.com
Cc: Huie-Ying.Lee@sun.com
Message-id: <200810150847.m9F8l88a002371@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 2028


Template Version: @(#)sac_nextcase %I% %G% SMI
This information is Copyright 2008 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 PAM prompt configuration enhancement for the pam_pkcs11 module
    1.2. Name of Document Author/Supplier:
	 Author:  HuieYing Lee
    1.3  Date of This Document:
	15 October, 2008
4. Technical Description

Update to PSARC/2006/283 Certificate & PKCS#11 PAM module.

To port the pam_pkcs11 module to OpenSolaris, we removed the "Smart card"
keywords from the PAM prompt messages and updated the messages to be more
generic because the original OpenSC/pam_pkcs11 module incorrectly assumed that
all PKCS#11 tokens are smartcards.

After we contributed these prompt message changes back to the upstream
communtity (opensc.org) a couple of weeks ago, they requested that we make
further changes to allow the PAM prompt messages configurable.  In this
enhancement, a new "token_type" parameter is added to the pam_pkcs11.conf
configuration file and its value will be used in the user prompt messages.

This enhancement request has been implemented and integrated into the upstream
community on Oct/14.   To keep the OpenSolaris source in sync with the upstream
OpenSC community, we would like to integrate the change to OpenSolaris as well.
For more information, see the attached diffs to the default pam_pkcs11.conf
below.


*** pam_pkcs11.conf.orig	Tue Oct 14 14:34:29 2008
--- pam_pkcs11.conf	Tue Oct 14 14:38:20 2008
***************
*** 75,80 ****
--- 75,84 ----
      # cert_policy = ca,signature;
      cert_policy = signature;
  
+     # What kind of token?
+     # The value of the token_type parameter will be used in the user prompt
+     # messages.  The default value is "Smart card".
+     token_type = "Secure token";
    }
  
    # Which mappers ( Cert to login ) to use?


6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		SFW
    6.5. ARC review type: Automatic
    6.6. ARC Exposure: open


From gww@eng.sun.com Wed Oct 15 08:00:58 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m9FF0wgC023523
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 15 Oct 2008 08:00:58 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m9FF0vup028696
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 15 Oct 2008 08:00:57 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K8S00B6PCDKVI00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 15 Oct 2008 09:00:56 -0600 (MDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K8S00844CDIUN70@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 15 Oct 2008 09:00:54 -0600 (MDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m9FF0rLF057893; Wed, 15 Oct 2008 08:00:53 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id m9FF21rI018211; Wed,
 15 Oct 2008 08:02:01 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id m9FF21tt018210; Wed,
 15 Oct 2008 08:02:01 -0700 (PDT)
Date: Wed, 15 Oct 2008 08:02:01 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: PAM prompt configuration enhancement for the pam_pkcs11 module
 [PSARC/2008/635 Self Review]
To: PSARC-ext@sun.com, darrenm@sac.sfbay.sun.com
Cc: Huie-Ying.Lee@sun.com
Message-id: <200810151502.m9FF21tt018210@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 84

> Update to PSARC/2006/283 Certificate & PKCS#11 PAM module.

+1 if needed.

Gary..

