To configure smart card redirection on a RHEL 9.x/8.x virtual machine (VM), install the libraries on which the feature depends and the root Certificate Authority (CA) certificate to support the trusted authentication of smart cards.
Prerequisites
- Integrate a RHEL 9.x/8.x Virtual Machine with Active Directory for Smart Card Redirection
- To use the smart card single sign-on (SSO) feature in FIPS mode, ensure that you have completed all the steps described in Configure a FIPS-compliant Linux Virtual Machine. You must add the trusted CA certificate for BlastServer to
ssl/rui.crtand add the key paired withrui.crttossl/rui.key.
Procedure
-
Install the required libraries.
yum install -y opensc pcsc-lite pcsc-lite-libs pcsc-lite-ccid nss-tools -
Enable the
pcscdservice.systemctl enable pcscd systemctl start pcscd -
Make sure that the
/etc/sssd/sssd.confconfiguration file contains the following lines, which enable smart card authentication.[pam] pam_cert_auth = True -
Copy the required CA certificate to
/etc/sssd/pki/sssd_auth_ca_db.pem.openssl x509 -inform der -in certificate.cer -out certificate.pem cp certificate.pem /etc/sssd/pki/sssd_auth_ca_db.pem -
To verify the status of the smart card, run the following
pkcs11-toolcommands and confirm that they return the correct output.pkcs11-tool -L pkcs11-tool --login -O pkcs11-tool --test --login -
Copy the required drivers and add the necessary library files to the
nssdbdirectory.-
Run commands similar to the following example.
These example commands show how to add
libcmP11.so, the driver file for the Gemalto PIV 2.0 card, to thenssdbdirectory. In place oflibcmP11.so, you can substitute the driver file for your smart card.cp libcmP11.so /usr/lib64/ mkdir -p /etc/pki/nssdb certutil -N -d /etc/pki/nssdb certutil -A -n rootca -i certificate.pem -t "CT,CT,CT" -d /etc/pki/nssdb modutil -dbdir /etc/pki/nssdb/ -add "piv card 2.0" -libfile /usr/lib64/libcmP11.so -
Verify that the expected certificate is loaded successfully by running the following command.
# certutil -L -d /etc/pki/nssdbVerify that the command returns output similar to the following example.
Certificate Nickname rootca -
Verify that the expected libraries are added successfully by running the following command.
modutil -dbdir /etc/pki/nssdb -listVerify that the command returns output similar to the following example.
Listing of PKCS #11 Modules –----------------------------------------------------------- 1. NSS Internal PKCS #11 Module slots: 2 slots attached status: loaded slot: NSS Internal Cryptographic Services token: NSS Generic Crypto Services slot: NSS User Private Key and Certificate Services token: NSS Certificate DB 2. piv card 2.0 library name: /usr/lib/libcmP11.so slots: There are no slots attached to this module status: loaded –-----------------------------------------------------------
-
-
Create the
/usr/share/p11-kit/modules/libcmP11.modulefile. Add the following content to the file.# This file describes how to load the opensc module # See: http://p11-glue.freedesktop.org/doc/p11-kit/config.html # This is a relative path, which means it will be loaded from # the p11-kit default path which is usually $(libdir)/pkcs11. # Doing it this way allows for packagers to package opensc for # 32-bit and 64-bit and make them parallel installable module: /usr/lib64/libcmP11.so priority: 99Note: (RHEL 9.x) You must also remove the
/usr/share/p11-kit/modules/p11-kit-trust.modulefile from the system. In addition, if you are not usingopensc, you must remove the/usr/share/p11-kit/modules/opensc.modulefile. -
To support the smart card SSO feature, configure the
viewagent-greeter.conffile. See Setting Options in Configuration Files on a Linux Desktop. -
Install the Horizon Agent package, with smart card redirection enabled.
-
If using the
.rpminstaller:-
Run the installer to install Horizon Agent with the default feature options.
-
To add the smart card redirection feature, run the
ViewSetup.shscript.
-
-
If using the
.tar.gzinstaller, run the installer with the parameter to enable smart card redirection:
Note: If you get an error message instructing you to install the default PC/SC Lite library, uninstall the custom PC/SC Lite library that is currently present on the machine and install the default PC/SC Lite library using the following command.
yum reinstall pcsc-lite-libs pcsc-liteYou can then run the Horizon Agent installer.
-
-
If you are using a custom PC/SC Lite library, configure the pcscd.maxReaderContext and pcscd.readBody options in the
configfile.See Setting Options in Configuration Files on a Linux Desktop.
-
Restart the virtual machine and log back in.
Was this page helpful?