Hi Jaipaul,

Please avoid top-posting, this is not appropriate etiquette for interacting on mailing lists, c.f. https://www.kernel.org/doc/html/latest/process/submitting-patches.html#use-trimmed-interleaved-replies-in-email-discussions

On 8/22/26 4:02 PM, Jaipaul Cheernam wrote:
Hi Quentin,

Thanks for pointing out to correct patch link.

Yes — the upstream patch unconditionally loads the pkcs11 provider and atally 
errors if it's not installed.
Fixed by making the load non-fatal: default provider loads first (mandatory), 
pkcs11 is attempted but ERR_clear_error() on failure so file-based signing 
works without it.


I actually meant something else, but this too apparently was an issue as highlighted by Richard in https://lore.kernel.org/openembedded-core/9a98b9099e927565c0ed867b7598ccea9afdbfe4.ca...@linuxfoundation.org/.

What I was worried about is what I reported here (https://lore.kernel.org/u-boot/[email protected]/) in the paragraph starting with "This is sneaky here"). I don't think pkcs11 URI are supported at all because we currently (well, in v4 of the patch) always check if the key exists on the local filesystem, which cannot happen for PKCS11 URI (and if it does, it means nothing anyway as it won't be used). I don't know if anyone's using PKCS11 signing for U-Boot in Yocto but it'd be broken for them then I believe.

Sent a reply to the u-boot ML thread noting this is needed for OE-Core and 
sharing our workaround, though it's currently held for moderator approval (!!).


It'll eventually make it to the mailing list once moderators have approved it (can take a few days/weeks). Alternatively, you can subscribe to the mailing list and resend.

Cheers,
Quentin
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244084): 
https://lists.openembedded.org/g/openembedded-core/message/244084
Mute This Topic: https://lists.openembedded.org/mt/120850409/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to