большое спасибо, теперь понятна кобинация :)
Другая проблема возникла, при генерации и подписывания ключей:
CryptoPro CSP: Set password on produced container "IPsecB".
# sudo cryptcp -creatcert -CA 'http://www.cryptopro.ru/certsrv' -dn CN=IPsecB -certusage 1.3.6.1.5.5.8.2.2 -provtype 75 -both -cont '\\.\HDIMAGE\IPsecB' -exprt -ku
CryptCP 3.32 (Debug version) (c) "Crypto-Pro", 2002-2009.
Command prompt Utility for data protection.
Параметры: -creatcert -CA
http://www.cryptopro.ru/certsrv -dn CN=IPsecB -certusage 1.3.6.1.5.5.8.2.2 -provtype
X11 connection rejected because of wrong authentication.
X11 connection rejected because of wrong authentication.
X11 connection rejected because of wrong authentication.
X11 connection rejected because of wrong authentication.
CryptoPro CSP: Set password on produced container "IPsecB".
Password:
Retype password:
Sending request to CA...
* About to connect() to
www.cryptopro.ru port 80 (#0)
* Trying 195.133.54.251... * connected
* Connected to
www.cryptopro.ru (195.133.54.251) port 80 (#0)
> POST /certsrv/certfnsh.asp HTTP/1.1
User-Agent: UrlRetriever {Mozilla MSIE 6 Win 2000}
Host:
www.cryptopro.ruAccept: */*
Content-Length: 1144
Content-Type: application/x-www-form-urlencoded
Expect: 100-continue
* Done waiting for 100-continue
< HTTP/1.1 100 Continue
< Via: 1.1 CRYPTO
* Empty reply from server
* Connection #0 to host
www.cryptopro.ru left intact
* Server returned nothing (no headers, no data)
* Closing connection #0
Error: Incorrect response from the server. (0x200002BE)
[ErrorCode: 0x200002be]
#
Для чего cryptcp понадобился доступ к X11? Я, вроде, не ставил графического интерфейса:
# rpm -qa | grep lsb-cprocsp
lsb-cprocsp-base-3.6.1-4.noarch
lsb-cprocsp-devel-3.6.1-4.noarch
lsb-cprocsp-3.6.1-4.i486
lsb-cprocsp-ipsec-ike-3.6.1-4.i486
lsb-cprocsp-ipsec-devel-3.6.1-4.noarch
lsb-cprocsp-rdr-3.6.1-4.i486
lsb-cprocsp-drv-devel-3.6.1-4.noarch
lsb-cprocsp-capilite-3.6.1-4.i486
lsb-cprocsp-ipsec-genpsk-3.6.1-4.i486
#