[Opendnssec-user] ods-enforcerd: [engine] Initialization: CKR_GENERAL_ERROR

Alarig Le Lay alarig at swordarmor.fr
Wed Dec 20 18:54:51 UTC 2017


On lun.  4 déc. 16:46:04 2017, Yuri Schaeffer wrote:
> It seems like the Enforcer can't properly connect to your HSM. Please
> review the HSM settings in conf.xml. Also raise the verbosity for the
> enforcer in that file when retrying.
> 
> If you are using SoftHSM consider that the HSM files might not be
> writable for the user opendnssec runs on. The SoftHSM configuration will
> allow for enabling more logging.

You were right, this was because of the migration from SoftHSM v1 to the
v2.

But, there is no example or explanation of the migration between the
versions on
https://wiki.opendnssec.org/display/SoftHSMDOCS/SoftHSM+Documentation+v2
or on
https://wiki.opendnssec.org/display/SoftHSMDOCS/SoftHSM+Documentation+v1

I found the command by browsing the git repo.

Thanks for the hint,
-- 
alarig
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: not available
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20171220/38dfb931/attachment.bin>


More information about the Opendnssec-user mailing list