# Zk\_pkcs11 support for Raspberry PI 2B 32 bit

**URL:** <https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800>\
**Category:** ZYMKEY4\
**Created:** [June 15, 2020, 4:07pm UTC](https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800 "2020-06-15T16:07:27Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![aasayed](https://avatars.discourse-cdn.com/v4/letter/a/ac91a4/32.png) [@aasayed](https://community.zymbit.com/u/aasayed)\
**Post date:** [June 15, 2020, 4:07pm UTC](https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800/1 "2020-06-15T16:07:27Z")

</div>

Hi,

I’ve just recently got my Zymbit 4I and starting to play around with it. I am running it on a Raspberry PI 2B (yes I know, it’s old). I’m getting “OverflowError: Python int too large to convert to C long” errors on running some simple Python code. I suspect that it’s becuase zkpkcs11 library only supports 64bit. Do I need to upgrade my Raspberry PI or is there a 32bit support for zkpkcs11 libs.

Thanks in advance

Sayed

---

<div class="post-metadata">

**Author:** ![Bob\_of\_Zymbit](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@Bob\_of\_Zymbit](https://community.zymbit.com/u/Bob_of_Zymbit)\
**Post date:** [June 15, 2020, 5:55pm UTC](https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800/2 "2020-06-15T17:55:03Z")

</div>

Hi Sayed,

The zkpcs11 libraries are built for the platform and should be 32-bit. Can you explain in a little more detail what you are trying to do? Maybe include the python code that caused the error?

Bob

---

<div class="post-metadata">

**Author:** ![aasayed](https://avatars.discourse-cdn.com/v4/letter/a/ac91a4/32.png) [@aasayed](https://community.zymbit.com/u/aasayed)\
**Post date:** [June 15, 2020, 8:26pm UTC](https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800/3 "2020-06-15T20:26:12Z")

</div>

Hi Bob,

Thanks for your response. So, running the code below I get the following error:

_import zymkey_

_data = bytearray(‘hello world!’)_  
_encrypted\_payload = zymkey.client.lock(data)_  
_payload\_sig = zymkey.client.sign(encrypted\_payload)_

I get the following error:

_Traceback (most recent call last):_  
_File “encrypt\_test.py”, line 5, in_   
_payload\_sig = zymkey.client.sign(encrypted\_payload)_  
_File “/usr/local/lib/python2.7/dist-packages/zymkey/module.py”, line 340, in sign_  
_sha256.update(src.encode(‘utf-8’))_  
_AttributeError: ‘bytearray’ object has no attribute ‘encode’_

_When I change the var ‘data’ to just a string, I get the following error:_

_File “encrypt\_test.py”, line 4, in_   
_encrypted\_payload = zymkey.client.lock(data)_  
_File “/usr/local/lib/python2.7/dist-packages/zymkey/module.py”, line 213, in lock_  
_raise AssertionError(‘bad return code %d’ % ret)_  
_AssertionError: bad return code -2_

_Also running the below code I found on the community website,_

_import zkpkcs11_

_# Initialise our PKCS#11 library_  
_lib = pkcs11.lib(os.environ[‘PKCS11\_MODULE’])_  
_token = lib.get\_token(token\_label=‘Zymkey’)_

_data = b’INPUT DATA’_

_# Open a session on our token_  
_with token.open(user\_pin=‘123456’) as session:_  
_# Generate an AES key in this session_  
_key = session.generate\_key(pkcs11.KeyType.AES, 256)_

_# Get an initialisation vector_  
_iv = session.generate\_random(128) # AES blocks are fixed at 128 bits_  
_# Encrypt our data_  
_crypttext = key.encrypt(data, mechanism\_param=iv)_

I get the following error:

Traceback (most recent call last):  
File “aes\_gen.py”, line 1, in   
import zkpkcs11  
ImportError: No module named zkpkcs11

I’m quite familiar with Python, but cannot understanding the errors.

Thanks and regards

Abdul

---

<div class="post-metadata">

**Author:** ![Bob\_of\_Zymbit](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@Bob\_of\_Zymbit](https://community.zymbit.com/u/Bob_of_Zymbit)\
**Post date:** [June 16, 2020, 4:55am UTC](https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800/4 "2020-06-16T04:55:06Z")

</div>

You are getting the first error because sign() is expecting a digest as a hex string. You can turn your encoded data into a hex string with binascii.hexlify before passing to sign(),

_import zymkey_  
_ **import binascii** _

_data = bytearray(‘hello world’)_  
_encrypted\_payload = **binascii.hexlify(**zymkey.client.lock(data)**)**_  
_payload\_sig = zymkey.client.sign(encrypted\_payload)_

Your second attempt error is because if you give lock() a string, it assumes that is an absolute path to a file to lock(). If you give it data like you did in the first try, it will encrypt the data.

I’m going to have to get back to you on the zkpkcs11 module not found.

Bob

---

<div class="post-metadata">

**Author:** ![Bob\_of\_Zymbit](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@Bob\_of\_Zymbit](https://community.zymbit.com/u/Bob_of_Zymbit)\
**Post date:** [June 17, 2020, 3:35pm UTC](https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800/5 "2020-06-17T15:35:01Z")

</div>

Hi Abdul,

I did some research and Zymbit has never released a zkpkcs Python module. No wonder you can’t find it! You mentioned you found the PKCS#11 code on the community website. Can you provide a link to that? I am not familiar with that example.

Bob

---

<div class="post-metadata">

**Author:** ![aasayed](https://avatars.discourse-cdn.com/v4/letter/a/ac91a4/32.png) [@aasayed](https://community.zymbit.com/u/aasayed)\
**Post date:** [June 17, 2020, 4:53pm UTC](https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800/6 "2020-06-17T16:53:05Z")

</div>

Hi Bob,

Sorry, my bad. The example is for the Python pics#11 wrapper API found on this website

[https://python-pkcs11.readthedocs.io/en/latest/](https://python-pkcs11.readthedocs.io/en/latest/)

I installed the wrapper and set the environment variable:

PKCS11\_MODULE=/home/pi/.local/lib/python2.7/site-packages/pkcs11

This is the code and I’m running python 3

_import pkcs11_

_# Initialise our PKCS#11 library_  
_lib = pkcs11.lib(os.environ[‘PKCS11\_MODULE’])_  
_token = lib.get\_token(token\_label=‘Zymkey’)_

_data = b’INPUT DATA’_

_# Open a session on our token_  
_with token.open(user\_pin=‘123456’) as session:_  
_# Generate an AES key in this session_  
_key = session.generate\_key(pkcs11.KeyType.AES, 256)_

_# Get an initialisation vector_  
_iv = session.generate\_random(128) # AES blocks are fixed at 128 bits_  
_# Encrypt our data_  
crypttext = key.encrypt(data, mechanism\_param=iv)

The error I get is:

Traceback (most recent call last):  
File “aes\_gen.py”, line 1, in   
import pkcs11  
ModuleNotFoundError: No module named ‘pkcs11’

I suspect that zymkey does not support that library module?

Hope this is clearer now. Again apologise for the wrong info

Abdul

---

<div class="post-metadata">

**Author:** ![Bob\_of\_Zymbit](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@Bob\_of\_Zymbit](https://community.zymbit.com/u/Bob_of_Zymbit)\
**Post date:** [June 18, 2020, 12:21am UTC](https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800/7 "2020-06-18T00:21:26Z")

</div>

Abdul,  
Python3 is telling you that it can’t find the package ‘pkcs11’. You need to install this with pip.  
`python3 -m pip install python-pkcs11`

Next, you need to export the environment variable `PKCS11_MODULE` and point it to the zymkey PKCS#11 library.  
`export PKCS11_MODULE=/usr/lib/libzk_pkcs11.so`

Try this and let us know how it goes.

---

<div class="post-metadata">

**Author:** ![aasayed](https://avatars.discourse-cdn.com/v4/letter/a/ac91a4/32.png) [@aasayed](https://community.zymbit.com/u/aasayed)\
**Post date:** [June 18, 2020, 5:39pm UTC](https://community.zymbit.com/t/zk-pkcs11-support-for-raspberry-pi-2b-32-bit/800/8 "2020-06-18T17:39:19Z")

</div>

Hi Scott,

Yes. I made the changes and it worked fine. Thank you. On a separate note, can Zymkey be used in a BYOK scenario? A typical BYOK use case will be to generate a key using Zymkey and securely transport the key in into, say the KMS in AWS cloud? That way, although I am using the AWS native encryption platform, I am generating the keys and this use case will allow more control over the creation, lifecycle, and durability of my keys keys.

Thanks once again

Abdul
