1import{_ as r,r as l,o,c as d,e as a,b as n,d as s,a as t}from"./app-4488e322.js";const c="/assets/yubikey-1-205b4693.png",p="/assets/yubikey-certs-ccdf63db.png",u="/assets/raspberry-pi-setup-fe6468c6.png",b={},m={href:"https://www.yubico.com/products/services-software/download/yubikey-manager/",target:"_blank",rel:"noopener noreferrer"},v={href:"https://github.com/eideasy/e-seal-digital-signature-service",target:"_blank",rel:"noopener noreferrer"};function k(h,e){const i=l("ExternalLinkIcon");return o(),d("div",null,[e[4]||(e[4]=a('<h1 id="e-seal-on-premises-setup-guide" tabindex="-1"><a class="header-anchor" href="#e-seal-on-premises-setup-guide" aria-hidden="true">#</a> e-Seal on-premises setup guide</h1><p>eID Easy document signing e-Seal application is app that you can run in your own machine and in your own environment. This means that it is under your sole control as it is supposed to according to eIDAS regulation. Our reference appliance is built with Raspberry PI and Yubikey FIPS. This device does not need to run in the datacenter and it can even be located next to your WiFi router or in your locked switch cabinet.</p><p>Steps to get it running.</p><ol><li>Generate keypair and Certificate Signing Request</li><li>Order document signing certificat and import certificate to the Yubikey</li><li>Install Ubuntu server to Raspberry PI and install all dependencies using Cloud Init</li><li>Examine Yubikey and identify needed token parameters</li><li>Configure Yubikey environment parameters and run docker machine</li><li>Configure network routing</li></ol><h2 id="_1-generate-keypair-and-csr-on-the-yubikey-hsm" tabindex="-1"><a class="header-anchor" href="#_1-generate-keypair-and-csr-on-the-yubikey-hsm" aria-hidden="true">#</a> 1. Generate keypair and CSR on the Yubikey HSM</h2>',5)),n("p",null,[e[1]||(e[1]=s("Easiest way to manage your Yubikeys is using Yubikey Manager app that can be downloaded from ",-1)),n("a",m,[e[0]||(e[0]=s("https://www.yubico.com/products/services-software/download/yubikey-manager/",-1)),t(i)])]),e[5]||(e[5]=a('<p>There are OTP, FIDO2 and PIV applications. We are working with PIV (Personal Identity Verification)</p><p><img src="'+c+'" alt="yubico application download screenshot"></p><p>Once PIV application is selected then go to Digital Signature and click Generate. Choose âCertificate Signing Request (CSR)â and for algorithm RSA2048 if you order certificates from SK. Next you will be asked subject name, write there what you want to be most prominent in signed document. For example âSigned by My Companyâ</p><p><img src="'+p+'" alt="yubico application certificates management screenshot"></p><h2 id="_2-order-document-signing-e-seal-certificate" tabindex="-1"><a class="header-anchor" href="#_2-order-document-signing-e-seal-certificate" aria-hidden="true">#</a> 2. Order Document signing e-Seal certificate</h2><p>From previous step you got CSR file. Next step is to go to some eIDAS and AATL (Adobe Approved Trust List) trust service provider and order your digital stamp document signing certificate.</p><p>You will need to provide details about your company (or person, if you want personal signing certificate) and if trust service provider believes that you can represent this company then they will give you the certificate for some fee. Once you get the certificate then open Yubikey Manager and import the certificate to the Digital Signature (Slot 9c). With this your token is ready for use.</p><h2 id="_3-install-ubuntu-server-to-raspberry-pi-and-install-all-dependencies-using-cloud-init" tabindex="-1"><a class="header-anchor" href="#_3-install-ubuntu-server-to-raspberry-pi-and-install-all-dependencies-using-cloud-init" aria-hidden="true">#</a> 3. Install Ubuntu server to Raspberry PI and install all dependencies using Cloud Init</h2><p>Raspberry PI is perfect for eIDAS Qualified e-Seal appliance as you can keep it in your office in secure location and have full and sole control over it.</p><p>Install Raspberry PI imager that will help you flash the memory card. Unfortunately latest Ubuntu LTS 20.04.1 has issues when connecting to during first boot. If you are connecting Raspberry PI using Ethernet cable then choose this version. If you will c
1onnect wifi, then take Ubuntu 20.10.</p><p><img src="'+u+`" alt="raspberry pi setup screenshot"></p><p>After flashing the memory card you need to edit 2 files on system-boot partition on the memory card.</p><ul><li>user-data â will be used to create initial use, import your SSH key and installing needed packages.</li><li>network-config â this contains Netplan ethernet and WiFi configuration info. If only ethernet is used then it does not need to be modified.</li></ul><p>Minimal cloud-init config file looks like below. Make sure the â#cloud-configâ is on top, otherwise the Cloud init config file will not be recognized.</p><div class="language-text line-numbers-mode" data-ext="text"><pre class="language-text"><code>#cloud-config 2 3## Create default user ubuntu with default password Ubuntu that needs to be changed during first login 4chpasswd: 5 list: 6 - ubuntu:ubuntu 7 8## Add this SSH key for logging in to the Raspberry 9ssh_authorized_keys: 10 - ssh-rsa AAAAB3Nz....FzDTkv6J my-admin-computer 11 12## Install docker on boot 13packages: 14 - docker.io 15</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>Once these configurations have been updated then insert the memory card to the Raspberry PI and boot it up.</p><h2 id="_4-examine-yubikey-and-identify-needed-hsm-token-parameters" tabindex="-1"><a class="header-anchor" href="#_4-examine-yubikey-and-identify-needed-hsm-token-parameters" aria-hidden="true">#</a> 4. Examine Yubikey and identify needed HSM token parameters</h2><p>We will be using opensc and pkcs11-tool for that. We need token label and object ID. You can do this in any machine. However it is not recommended to install opensc to the Rasberry host OS as it might create issues when using USB inside the docker machine.</p><p>For Yubikey PKCS#11 module you need to install yubiko-piv-tool</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code><span class="token function">sudo</span> <span class="token function">apt</span> <span class="token function">install</span> yubico-piv-tool 16</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div></div></div><p>pkcs11-tool -L gives us general details of the token. Here we see that the âtoken labelâ is âYubiKey PIV #13650870â</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code>$ pkcs11-tool <span class="token parameter variable">--module</span> /usr/lib/libykcs11.so <span class="token parameter variable">-L</span> 17Available slots: 18Slot <span class="token number">0</span> <span class="token punctuation">(</span>0x0<span class="token punctuation">)</span>: Yubico YubiKey OTP+FIDO+CCID 01 00 19 token label <span class="token builtin class-name">:</span> YubiKey PIV <span class="token comment">#13650870</span> 20 token manufacturer <span class="token builtin class-name">:</span> Yubico <span class="token punctuation">(</span>www.yubico.com<span class="token punctuation">)</span> 21 token model <span class="token builtin class-name">:</span> YubiKey YK5 22 token flags <span class="token builtin class-name">:</span> login required, rng, token initialized, PIN initialized 23 hardware version <span class="token builtin class-name">:</span> <span class="token number">1.0</span> 24 firmware version <span class="token builtin class-name">:</span> <span class="token number">5.24</span> 25 serial num <span class="token builtin class-name">:</span> <span class="token number">13650870</span> 26 pin min/max <span class="token builtin class-name">:</span> <span class="token number">6</span>/48 27</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>We will find our the ID of the private key and the certificate, which in this case is â02â. There is another attestation key with same id, but we take only first certificate.</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code>$ pkcs11-tool <span class="token parameter variable">--module</span> /usr/lib/libykcs11.so --list-objects <span class="token parameter variable">--type</span> privkey <span class="token parameter variable">--login</span> 28Using slot <span class="token number">0</span> with a present token <span class="token punctuation">(</span>0x0<span class="token punctuation">)</span> 29Logging <span class="token keyword">in</span> to <span class="token string">"YubiKey PIV #13650870"</span><span class="token builtin class-name">.</span> 30Please enter User PIN: 31Private Key Object<span class="token punctuation">;</span> RSA 32 label: Private key <span class="token keyword">
32for</span> Digital Signature 33 ID: 02 34 Usage: decrypt, sign 35 Access: always authenticate, sensitive, always sensitive, never extractable, <span class="token builtin class-name">local</span> 36Private Key Object<span class="token punctuation">;</span> RSA 37 label: Private key <span class="token keyword">for</span> PIV Attestation 38 ID: <span class="token number">19</span> 39 Usage: none 40 Access: sensitive, always sensitive, never extractable 41 42$ pkcs11-tool <span class="token parameter variable">--module</span> /usr/lib/libykcs11.so --list-objects <span class="token parameter variable">--type</span> cert 43Using slot <span class="token number">0</span> with a present token <span class="token punctuation">(</span>0x0<span class="token punctuation">)</span> 44Certificate Object<span class="token punctuation">;</span> <span class="token builtin class-name">type</span> <span class="token operator">=</span> X.509 cert 45 label: X.509 Certificate <span class="token keyword">for</span> Digital Signature 46 subject: DN: <span class="token assign-left variable">organizationIdentifier</span><span class="token operator">=</span>NTREE-14080014/serialNumber<span class="token operator">=</span><span class="token number">14080014</span>, <span class="token assign-left variable">ST</span><span class="token operator">=</span>Harjumaa, <span class="token assign-left variable">L</span><span class="token operator">=</span>Tallinn, <span class="token assign-left variable">C</span><span class="token operator">=</span>EE, <span class="token assign-left variable">O</span><span class="token operator">=</span>EID Easy O<span class="token punctuation">\\</span>xC3<span class="token punctuation">\\</span>x9C, <span class="token assign-left variable">CN</span><span class="token operator">=</span>eID Easy <span class="token builtin class-name">test</span> seal 47 ID: 02 48Certificate Object<span class="token punctuation">;</span> <span class="token builtin class-name">type</span> <span class="token operator">=</span> X.509 cert 49 label: X.509 Certificate <span class="token keyword">for</span> PIV Attestation 50 subject: DN: <span class="token assign-left variable">CN</span><span class="token operator">=</span>Yubico PIV Attestation 51 ID: <span class="token number">19</span> 52Certificate Object<span class="token punctuation">;</span> <span class="token builtin class-name">type</span> <span class="token operator">=</span> X.509 cert 53 label: X.509 Certificate <span class="token keyword">for</span> PIV Attestation 9c 54 subject: DN: <span class="token assign-left variable">CN</span><span class="token operator">=</span>YubiKey PIV Attestation 9c 55 ID: 02 56</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><h2 id="_5-configure-yubikey-environment-parameters-and-run-docker-machine" tabindex="-1"><a class="header-anchor" href="#_5-configure-yubikey-environment-parameters-and-run-docker-machine" aria-hidden="true">#</a> 5. Configure Yubikey environment parameters and run docker machine</h2><p>Now when the Raspberry PI has been booted up it has connected to network and most likely got the IP using DHCP. If you are in the same network then you can find the IP using arp command. We know that Raspberry PI 4 MAC address starts with dc:a6:32 . If the IP is known then we login to the PI configure docker environment variables and start the image.</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code>$ arp <span class="token parameter variable">-ne</span> <span class="token operator">|</span><span class="token function">grep</span> dc:a6:32 57<span class="token number">192.168</span>.8.251 ether dc:a6:32:6a:d3:df C enx3ce1a1c2a821 58$ <span class="token function">ssh</span> [email protected] 59</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>We can add all environment variables in one place, for example .env-eseal in the home folder. It could look something like that.</p><div class="language-dotenv line-numbers-mode" data-ext="dotenv"><pre class="language-dotenv"><code>key_id.card.hsm_implementation=pkcs11 60key_id.card.hmac_key=413140d54372f9baf481d4c54e2d5c7bcf28fd6087000280e07976121dd54af2 61key_id.card.pkcs11-path=/usr/lib/aarch64-linux-gnu/libykcs11.so 62key_id.card.token-label=YubiKey PIV #13650853 63key_id.card.object-id=02 64key_id.card.password_url=https://example.com:5555/remote-pin?token=123456 65</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><p>Now download and start the docker machine using following command. It will take about 15 seconds to boot up and start listening to the port.</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code><span class="token function">sudo</span> <span class="token function">
65docker</span> run <span class="token parameter variable">-d</span> --env-file ~/.env-eseal <span class="token parameter variable">--device</span><span class="token operator">=</span>/dev/bus/usb <span class="token parameter variable">-p</span> <span class="token number">8080</span>:8082 <span class="token parameter variable">--name</span><span class="token operator">=</span>eideasy_eseal <span class="token parameter variable">--restart</span> always --log-driver syslog --log-opt <span class="token assign-left variable">tag</span><span class="token operator">=</span><span class="token string">"{{.Name}}/{{.ID}}"</span> eideasy/eseal 66</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div></div></div>`,31)),n("p",null,[e[3]||(e[3]=s("You can also build the docker machine from source ",-1)),n("a",v,[e[2]||(e[2]=s("https://github.com/eideasy/e-seal-digital-signature-service",-1)),t(i)])]),e[6]||(e[6]=a(`<p>Keep in mind that after you change environment variables then you need to recreate the docker machine. Easiest way for that is</p><div class="language-bash line-numbers-mode" data-ext="sh"><pre class="language-bash"><code><span class="token function">sudo</span> <span class="token function">docker</span> stop eideasy_eseal <span class="token parameter variable">-t</span> <span class="token number">0</span> 67<span class="token function">sudo</span> <span class="token function">docker</span> <span class="token function">rm</span> eideasy_eseal 68<span class="token function">sudo</span> <span class="token function">docker</span> run <span class="token parameter variable">-d</span> --env-file ~/.env-eseal <span class="token parameter variable">--device</span><span class="token operator">=</span>/dev/bus/usb <span class="token parameter variable">-p</span> <span class="token number">8080</span>:8082 <span class="token parameter variable">--name</span><span class="token operator">=</span>eideasy_eseal <span class="token parameter variable">--restart</span> always --log-driver syslog --log-opt <span class="token assign-left variable">tag</span><span class="token operator">=</span><span class="token string">"{{.Name}}/{{.ID}}"</span> eideasy/eseal 69</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div><h2 id="_6-configure-network-routing" tabindex="-1"><a class="header-anchor" href="#_6-configure-network-routing" aria-hidden="true">#</a> 6. Configure network routing</h2><p>Since eID Easy needs to send API calls from its server then you need to configure port forwarding and open the port in firewall. eID Easy IPv4 IPs are currently: 52.211.100.22, 52.16.77.106, 63.35.4.45, 63.34.102.230, 54.78.97.68, 52.212.172.233</p><p>Once this is done then forward e-Seal service access details to eID Easy team</p><p>E-Seal sample config file</p><div class="language-text line-numbers-mode" data-ext="text"><pre class="language-text"><code># Load passwords for these keyId-s during application boot 70# Especially useful if remote PIN loading is used and you run the remote PIN source only for limited time 71init_signers=card 72 73# Chooses the HSM protocol implementation, usually pkcs11 for local physical smart card or USB crypto token 74key_id.card.hsm_implementation=pkcs11 75 76# Agree this value with eID Easy 77key_id.card.hmac_key=413140d54372f9baf481d4c54e2d5c7bcf28fd6087000280e07976121dd54af2 78 79# Choose one correct PKCS #11 module for your HSM 80key_id.card.pkcs11-path=/usr/lib/x86_64-linux-gnu/opensc-pkcs11.so # ID card 81key_id.card.pkcs11-path=/usr/lib/x86_64-linux-gnu/libykcs11.so # Yubikey on PC 82key_id.card.pkcs11-path=/usr/lib/aarch64-linux-gnu/libykcs11.so # Yubikey on Raspberry PI 83key_id.card.pkcs11-path=/usr/lib/libIDPrimePKCS11.so # Gemalto Safenet 5110 CC eToken 84 85#Get these values from the token using pkcs11-tool 86key_id.card.token-label="YubiKey PIV #13650853" 87key_id.card.object-id=02 88 89# Optional, default is slot 0. Might be needed with Gemalto Safenet eToken 5110 90key_id.card.slot=0x11 91 92# If the device is secure then you can set the token PIN here. If device is stolen then you need to revoke certificate immediately. 93key_id.card.password=123456 94 95# For added security you can keep the PIN on remote machine 96key_id.card.password_url=https://example.com:5555/remote-pin?token=123456 97 98# Config params if Google KMS is used 99key_id.eID-Easy-signing-1.hsm_implementation=gcloud_hsm 100key_id.eID-Easy-signing-1.hmac_key= 101key_id.eID-Easy-signing-1.password= 102key_id.eID-Easy-signing-1.projectId= 103key_id.eID-Easy-signing-1.locationId= 104key_id.eID-Easy-signing-1.keyRingId= 105key_id.eID-Easy-signing-1.keyId= 106key_id.eID-Easy-signing-1.keyVersionId=1 107</code></pre><div class="line-numbers" aria-hidden="true"><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div><div class="line-number"></div></div></div>`,7))])}const g=r(b,[["render",k],["__file","on-premises-eseal.html.vue"]]);export{g as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.