PageSourceSearch

https://eideasy-docs.netlify.app/assets/on-premises-eseal.html-dc704606.js

js eideasy-docs.netlify.app collected 2026-10-03 10:43:05 UTC 21,868 bytes, 107 lines download raw bytes

1import{_ as r,r as l,o,c as d,e as a,b as n,d as s,a as t}from"./app-4488e322.js";const c="/assets/yubikey-1-205b4693.png",p="/assets/yubikey-certs-ccdf63db.png",u="/assets/raspberry-pi-setup-fe6468c6.png",b={},m={href:"https://www.yubico.com/products/services-software/download/yubikey-manager/",target:"_blank",rel:"noopener noreferrer"},v={href:"https://github.com/eideasy/e-seal-digital-signature-service",target:"_blank",rel:"noopener noreferrer"};function k(h,e){const i=l("ExternalLinkIcon");return o(),d("div",null,[e[4]||(e[4]=a('<h1 id="e-seal-on-premises-setup-guide" tabindex="-1"><a class="header-anchor" href="#e-seal-on-premises-setup-guide" aria-hidden="true">#</a> e-Seal on-premises setup guide</h1><p>eID Easy document signing e-Seal application is app that you can run in your own machine and in your own environment. This means that it is under your sole control as it is supposed to according to eIDAS regulation. Our reference appliance is built with Raspberry PI and Yubikey FIPS. This device does not need to run in the datacenter and it can even be located next to your WiFi router or in your locked switch cabinet.</p><p>Steps to get it running.</p><ol><li>Generate keypair and Certificate Signing Request</li><li>Order document signing certificat and import certificate to the Yubikey</li><li>Install Ubuntu server to Raspberry PI and install all dependencies using Cloud Init</li><li>Examine Yubikey and identify needed token parameters</li><li>Configure Yubikey environment parameters and run docker machine</li><li>Configure network routing</li></ol><h2 id="_1-generate-keypair-and-csr-on-the-yubikey-hsm" tabindex="-1"><a class="header-anchor" href="#_1-generate-keypair-and-csr-on-the-yubikey-hsm" aria-hidden="true">#</a> 1. Generate keypair and CSR on the Yubikey HSM</h2>',5)),n("p",null,[e[1]||(e[1]=s("Easiest way to manage your Yubikeys is using Yubikey Manager app that can be downloaded from ",-1)),n("a",m,[e[0]||(e[0]=s("https://www.yubico.com/products/services-software/download/yubikey-manager/",-1)),t(i)])]),e[5]||(e[5]=a('<p>There are OTP, FIDO2 and PIV applications. We are working with PIV (Personal Identity Verification)</p><p><img src="'+c+'" alt="yubico application download screenshot"></p><p>Once PIV application is selected then go to Digital Signature and click Generate. Choose “Certificate Signing Request (CSR)” and for algorithm RSA2048 if you order certificates from SK. Next you will be asked subject name, write there what you want to be most prominent in signed document. For example “Signed by My Company”</p><p><img src="'+p+'" alt="yubico application certificates management screenshot"></p><h2 id="_2-order-document-signing-e-seal-certificate" tabindex="-1"><a class="header-anchor" href="#_2-order-document-signing-e-seal-certificate" aria-hidden="true">#</a> 2. Order Document signing e-Seal certificate</h2><p>From previous step you got CSR file. Next step is to go to some eIDAS and AATL (Adobe Approved Trust List) trust service provider and order your digital stamp document signing certificate.</p><p>You will need to provide details about your company (or person, if you want personal signing certificate) and if trust service provider believes that you can represent this company then they will give you the certificate for some fee. Once you get the certificate then open Yubikey Manager and import the certificate to the Digital Signature (Slot 9c). With this your token is ready for use.</p><h2 id="_3-install-ubuntu-server-to-raspberry-pi-and-install-all-dependencies-using-cloud-init" tabindex="-1"><a class="header-anchor" href="#_3-install-ubuntu-server-to-raspberry-pi-and-install-all-dependencies-using-cloud-init" aria-hidden="true">#</a> 3. Install Ubuntu server to Raspberry PI and install all dependencies using Cloud Init</h2><p>Raspberry PI is perfect for eIDAS Qualified e-Seal appliance as you can keep it in your office in secure location and have full and sole control over it.</p><p>Install Raspberry PI imager that will help you flash the memory card. Unfortunately latest Ubuntu LTS 20.04.1 has issues when connecting to during first boot. If you are connecting Raspberry PI using Ethernet cable then choose this version. If you will c
1onnect wifi, then take Ubuntu 20.10.</p><p><img src="'+u+`" alt="raspberry pi setup screenshot"></p><p>After flashing the memory card you need to edit 2 files on system-boot partition on the memory card.</p><ul><li>user-data – will be used to create initial use, import your SSH key and installing needed packages.</li><li>network-config – this contains Netplan ethernet and WiFi configuration info. If only ethernet is used then it does not need to be modified.</li></ul><p>Minimal cloud-init config file looks like below. Make sure the “#cloud-config” is on top, otherwise the Cloud init config file will not be recognized.</p><div class="language-text line-numbers-mode" data-ext="text"><pre class="language-text"><code>#cloud-config
2
3## Create default user ubuntu with default password Ubuntu that needs to be changed during first login
4chpasswd:
5  list:
6    - ubuntu:ubuntu
7
8## Add this SSH key for logging in to the Raspberry
9ssh_authorized_keys:
10  - ssh-rsa AAAAB3Nz....FzDTkv6J my-admin-computer
11
12## Install docker on boot
13packages:
14  - docker.io
15</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>Once these configurations have been updated then insert the memory card to the Raspberry PI and boot it up.</p><h2 id="_4-examine-yubikey-and-identify-needed-hsm-token-parameters" tabindex="-1"><a class="header-anchor" href="#_4-examine-yubikey-and-identify-needed-hsm-token-parameters" aria-hidden="true">#</a> 4. Examine Yubikey and identify needed HSM token parameters</h2><p>We will be using opensc and pkcs11-tool for that. We need token label and object ID. You can do this in any machine. However it is not recommended to install opensc to the Rasberry host OS as it might create issues when using USB inside the docker machine.</p><p>For Yubikey PKCS#11 module you need to install yubiko-piv-tool</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code><span class="token function">sudo</span> <span class="token function">apt</span> <span class="token function">install</span> yubico-piv-tool
16</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div></div></div><p>pkcs11-tool -L gives us general details of the token. Here we see that the “token label” is “YubiKey PIV #13650870”</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code>$ pkcs11-tool <span class="token parameter variable">--module</span> /usr/lib/libykcs11.so <span class="token parameter variable">-L</span>
17Available slots:
18Slot <span class="token number">0</span> <span class="token punctuation">(</span>0x0<span class="token punctuation">)</span>: Yubico YubiKey OTP+FIDO+CCID 01 00
19  token label        <span class="token builtin class-name">:</span> YubiKey PIV <span class="token comment">#13650870</span>
20  token manufacturer <span class="token builtin class-name">:</span> Yubico <span class="token punctuation">(</span>www.yubico.com<span class="token punctuation">)</span>
21  token model        <span class="token builtin class-name">:</span> YubiKey YK5
22  token flags        <span class="token builtin class-name">:</span> login required, rng, token initialized, PIN initialized
23  hardware version   <span class="token builtin class-name">:</span> <span class="token number">1.0</span>
24  firmware version   <span class="token builtin class-name">:</span> <span class="token number">5.24</span>
25  serial num         <span class="token builtin class-name">:</span> <span class="token number">13650870</span>
26  pin min/max        <span class="token builtin class-name">:</span> <span class="token number">6</span>/48
27</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>We will find our the ID of the private key and the certificate, which in this case is “02”. There is another attestation key with same id, but we take only first certificate.</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code>$ pkcs11-tool <span class="token parameter variable">--module</span> /usr/lib/libykcs11.so --list-objects <span class="token parameter variable">--type</span> privkey <span class="token parameter variable">--login</span>
28Using slot <span class="token number">0</span> with a present token <span class="token punctuation">(</span>0x0<span class="token punctuation">)</span>
29Logging <span class="token keyword">in</span> to <span class="token string">&quot;YubiKey PIV #13650870&quot;</span><span class="token builtin class-name">.</span>
30Please enter User PIN: 
31Private Key Object<span class="token punctuation">;</span> RSA 
32  label:      Private key <span class="token keyword">
32for</span> Digital Signature
33  ID:         02
34  Usage:      decrypt, sign
35  Access:     always authenticate, sensitive, always sensitive, never extractable, <span class="token builtin class-name">local</span>
36Private Key Object<span class="token punctuation">;</span> RSA 
37  label:      Private key <span class="token keyword">for</span> PIV Attestation
38  ID:         <span class="token number">19</span>
39  Usage:      none
40  Access:     sensitive, always sensitive, never extractable
41
42$ pkcs11-tool <span class="token parameter variable">--module</span> /usr/lib/libykcs11.so --list-objects <span class="token parameter variable">--type</span> cert
43Using slot <span class="token number">0</span> with a present token <span class="token punctuation">(</span>0x0<span class="token punctuation">)</span>
44Certificate Object<span class="token punctuation">;</span> <span class="token builtin class-name">type</span> <span class="token operator">=</span> X.509 cert
45  label:      X.509 Certificate <span class="token keyword">for</span> Digital Signature
46  subject:    DN: <span class="token assign-left variable">organizationIdentifier</span><span class="token operator">=</span>NTREE-14080014/serialNumber<span class="token operator">=</span><span class="token number">14080014</span>, <span class="token assign-left variable">ST</span><span class="token operator">=</span>Harjumaa, <span class="token assign-left variable">L</span><span class="token operator">=</span>Tallinn, <span class="token assign-left variable">C</span><span class="token operator">=</span>EE, <span class="token assign-left variable">O</span><span class="token operator">=</span>EID Easy O<span class="token punctuation">\\</span>xC3<span class="token punctuation">\\</span>x9C, <span class="token assign-left variable">CN</span><span class="token operator">=</span>eID Easy <span class="token builtin class-name">test</span> seal
47  ID:         02
48Certificate Object<span class="token punctuation">;</span> <span class="token builtin class-name">type</span> <span class="token operator">=</span> X.509 cert
49  label:      X.509 Certificate <span class="token keyword">for</span> PIV Attestation
50  subject:    DN: <span class="token assign-left variable">CN</span><span class="token operator">=</span>Yubico PIV Attestation
51  ID:         <span class="token number">19</span>
52Certificate Object<span class="token punctuation">;</span> <span class="token builtin class-name">type</span> <span class="token operator">=</span> X.509 cert
53  label:      X.509 Certificate <span class="token keyword">for</span> PIV Attestation 9c
54  subject:    DN: <span class="token assign-left variable">CN</span><span class="token operator">=</span>YubiKey PIV Attestation 9c
55  ID:         02
56</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><h2 id="_5-configure-yubikey-environment-parameters-and-run-docker-machine" tabindex="-1"><a class="header-anchor" href="#_5-configure-yubikey-environment-parameters-and-run-docker-machine" aria-hidden="true">#</a> 5. Configure Yubikey environment parameters and run docker machine</h2><p>Now when the Raspberry PI has been booted up it has connected to network and most likely got the IP using DHCP. If you are in the same network then you can find the IP using arp command. We know that Raspberry PI 4 MAC address starts with dc:a6:32 . If the IP is known then we login to the PI configure docker environment variables and start the image.</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code>$ arp <span class="token parameter variable">-ne</span> <span class="token operator">|</span><span class="token function">grep</span> dc:a6:32
57<span class="token number">192.168</span>.8.251            ether   dc:a6:32:6a:d3:df   C                     enx3ce1a1c2a821
58$ <span class="token function">ssh</span> [email protected]
59</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>We can add all environment variables in one place, for example .env-eseal in the home folder. It could look something like that.</p><div class="language-dotenv line-numbers-mode" data-ext="dotenv"><pre class="language-dotenv"><code>key_id.card.hsm_implementation=pkcs11
60key_id.card.hmac_key=413140d54372f9baf481d4c54e2d5c7bcf28fd6087000280e07976121dd54af2
61key_id.card.pkcs11-path=/usr/lib/aarch64-linux-gnu/libykcs11.so 
62key_id.card.token-label=YubiKey PIV #13650853
63key_id.card.object-id=02
64key_id.card.password_url=https://example.com:5555/remote-pin?token=123456
65</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>Now download and start the docker machine using following command. It will take about 15 seconds to boot up and start listening to the port.</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code><span class="token function">sudo</span> <span class="token function">
65docker</span> run <span class="token parameter variable">-d</span> --env-file ~/.env-eseal <span class="token parameter variable">--device</span><span class="token operator">=</span>/dev/bus/usb <span class="token parameter variable">-p</span> <span class="token number">8080</span>:8082 <span class="token parameter variable">--name</span><span class="token operator">=</span>eideasy_eseal <span class="token parameter variable">--restart</span> always --log-driver syslog --log-opt <span class="token assign-left variable">tag</span><span class="token operator">=</span><span class="token string">&quot;{{.Name}}/{{.ID}}&quot;</span> eideasy/eseal
66</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div></div></div>`,31)),n("p",null,[e[3]||(e[3]=s("You can also build the docker machine from source ",-1)),n("a",v,[e[2]||(e[2]=s("https://github.com/eideasy/e-seal-digital-signature-service",-1)),t(i)])]),e[6]||(e[6]=a(`<p>Keep in mind that after you change environment variables then you need to recreate the docker machine. Easiest way for that is</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code><span class="token function">sudo</span> <span class="token function">docker</span> stop eideasy_eseal <span class="token parameter variable">-t</span> <span class="token number">0</span>
67<span class="token function">sudo</span> <span class="token function">docker</span> <span class="token function">rm</span> eideasy_eseal 
68<span class="token function">sudo</span> <span class="token function">docker</span> run <span class="token parameter variable">-d</span> --env-file ~/.env-eseal <span class="token parameter variable">--device</span><span class="token operator">=</span>/dev/bus/usb <span class="token parameter variable">-p</span> <span class="token number">8080</span>:8082 <span class="token parameter variable">--name</span><span class="token operator">=</span>eideasy_eseal <span class="token parameter variable">--restart</span> always --log-driver syslog --log-opt <span class="token assign-left variable">tag</span><span class="token operator">=</span><span class="token string">&quot;{{.Name}}/{{.ID}}&quot;</span> eideasy/eseal
69</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><h2 id="_6-configure-network-routing" tabindex="-1"><a class="header-anchor" href="#_6-configure-network-routing" aria-hidden="true">#</a> 6. Configure network routing</h2><p>Since eID Easy needs to send API calls from its server then you need to configure port forwarding and open the port in firewall. eID Easy IPv4 IPs are currently: 52.211.100.22, 52.16.77.106, 63.35.4.45, 63.34.102.230, 54.78.97.68, 52.212.172.233</p><p>Once this is done then forward e-Seal service access details to eID Easy team</p><p>E-Seal sample config file</p><div class="language-text line-numbers-mode" data-ext="text"><pre class="language-text"><code># Load passwords for these keyId-s during application boot
70# Especially useful if remote PIN loading is used and you run the remote PIN source only for limited time
71init_signers=card
72
73# Chooses the HSM protocol implementation, usually pkcs11 for local physical smart card or USB crypto token
74key_id.card.hsm_implementation=pkcs11
75
76# Agree this value with eID Easy
77key_id.card.hmac_key=413140d54372f9baf481d4c54e2d5c7bcf28fd6087000280e07976121dd54af2
78
79# Choose one correct PKCS #11 module for your HSM
80key_id.card.pkcs11-path=/usr/lib/x86_64-linux-gnu/opensc-pkcs11.so # ID card
81key_id.card.pkcs11-path=/usr/lib/x86_64-linux-gnu/libykcs11.so # Yubikey on PC
82key_id.card.pkcs11-path=/usr/lib/aarch64-linux-gnu/libykcs11.so # Yubikey on Raspberry PI
83key_id.card.pkcs11-path=/usr/lib/libIDPrimePKCS11.so # Gemalto Safenet 5110 CC eToken
84
85#Get these values from the token using pkcs11-tool
86key_id.card.token-label=&quot;YubiKey PIV #13650853&quot;
87key_id.card.object-id=02
88
89# Optional, default is slot 0. Might be needed with Gemalto Safenet eToken 5110
90key_id.card.slot=0x11
91
92# If the device is secure then you can set the token PIN here. If device is stolen then you need to revoke certificate immediately.
93key_id.card.password=123456
94
95# For added security you can keep the PIN on remote machine
96key_id.card.password_url=https://example.com:5555/remote-pin?token=123456
97
98# Config params if Google KMS is used
99key_id.eID-Easy-signing-1.hsm_implementation=gcloud_hsm
100key_id.eID-Easy-signing-1.hmac_key=
101key_id.eID-Easy-signing-1.password=
102key_id.eID-Easy-signing-1.projectId=
103key_id.eID-Easy-signing-1.locationId=
104key_id.eID-Easy-signing-1.keyRingId=
105key_id.eID-Easy-signing-1.keyId=
106key_id.eID-Easy-signing-1.keyVersionId=1
107</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div>`,7))])}const g=r(b,[["render",k],["__file","on-premises-eseal.html.vue"]]);export{g as default};

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.