1.登录客户SSL VPN设备,查看并记录已经配置的动态链接库路径如下,如下:
%homedrive%\Program Files (x86)\BJCAClient\CertAppEnvV2.15.01.1445\Driver\x86\EsecuKey_KGM_API_sheca.dll
%homedrive%\Program Files (x86)\BJCAClient\CertAppEnvV2.15.01.1445\Driver\x86\EsecuDrv04_sheca.dll
%homedrive%\Program Files (x86)\BJCAClient\CertAppEnvV2.15.01.1445\Driver\x64\EsecuKey_KGM_API_sheca_x64.dll
%homedrive%\Program Files (x86)\BJCAClient\CertAppEnvV2.15.01.1445\Driver\x64\EsecuDrv04_sheca_x64.dll
%systemroot%\sysWOW64\shca_1ea8.dll
%homedrive%\BJCAClient\CertAppEnvV2.15.01.1445\Driver\x86\EsecuKey_KGM_API_sheca.dll
%homedrive%\BJCAClient\CertAppEnvV2.15.01.1445\BjcaCertAide\libscpb_yzt.dll
%homedrive%\BJCAClient\CertAppEnvV2.15.01.1445\Driver\x86\EsecuDrv04_sheca.dll
%homedrive%\BJCAClient\CertAppEnvV2.15.01.1445\BjcaCertAide\DuiLib_u.dll
%homedrive%\BJCAClient\CertAppEnvV2.15.01.1445\BjcaCertAide\MsgNoticeBusiness.dll
%homedrive%\BJCAClient\CertAppEnvV2.15.01.1445\BjcaCertAide\XTXLogLib.dll
%homedrive%\BJCAClient\CertAppEnvV2.15.01.1445\BjcaCertAide\ZLibWrap.dll
2. 发现动态链接库路径中包含版本信息(V2.15.01.1445),若客户自行更新驱动程序,有可能导致之前配置的路径失效;
3. 咨询得知客户使用的数字证书发放单位为上海市数字证书认证中心,该国内数字证书支持使用北京证书中心或者上海的协卡助手驱动软件;
5. 使用工具ProcessExplorer查看协卡助手运行时调用了哪些dll动态链接库
6. 插上USB-KEY,启动协卡助手和ProcessExplorer,点击view--->Lower Pane View,勾选DLLs,表示查看软件运行时依赖的dll文件,这里我们选择协卡助手客户端“UniClient.exe”;
选择按“Company Name”排序dll,暂时忽略Sangfor Technologies以及Microsoft的,如下:
完整地把所有dll文件梳理出来,如下:
C:\Windows\SysWOW64\ecc_readcert.dll
C:\Windows\SysWOW64\ecc_se.dll
C:\Windows\SysWOW64\SESeal.dll
C:\Windows\SysWOW64\ReadCert.dll
C:\Windows\SysWOW64\SafeEngine.dll
C:\Windows\System32\EsecuAPI_sheca.dll
C:\Windows\SysWOW64\EsecuAPI_sheca.dll
C:\Windows\System32\EsecuKey_KGM_API_sheca.dll
C:\Windows\SysWOW64\EsecuKey_KGM_API_sheca.dll
C:\Windows\System32\EsecuDrv04_sheca.dll
C:\Windows\SysWOW64\EsecuDrv04_sheca.dll
C:\Windows\System32\shca_1ea8.dll
C:\Windows\SysWOW64\shca_1ea8.dll
C:\Program Files (x86)\Sheca\UniClient\DuiLib.dll
C:\Program Files (x86)\Sheca\UniClient\SSK_Service.dll
7.将上述dll路径重新填写到SSL VPN的动态链接库路径中,PC插上USB-KEY,启动easyconnect客户端,不再出现红色报错,输入PIN码******后,认证成功。