Public bug reported:
Regression introduced between 0.4.12-1.1build2 → 0.4.12-1.1ubuntu1 .
The ubuntu1 patch added a fix for a segfault during signing on OpenSSL
3.0.12–3.0.13 (cherry-picked from 0.4.13). This appears to have broken
the TPM2 auth session setup path.
Key log (wpa_supplicant):
tls_connection_set_params: Clearing pending SSL error: error:43000005:PKCS#11
module::General Error
tls_connection_set_params: Clearing pending SSL error: error:13000080:engine
routines::failed loading private key
ERROR:esys_crypto:src/tss2-esys/esys_crypto_ossl.c:723:iesys_cryptossl_pk_encrypt()
ErrorCode (0x00070001) Could not create rsa key.
ERROR: Esys_StartAuthSession: esapi:Catch all for all errors not otherwise
specified
ERROR: Could not start Auth Session with the TPM.
ERROR: Error unsealing wrapping key
ENGINE: cannot load private key with id
'pkcs11:token=scep-client;object=client-key;type=private'
[error:03000096:digital envelope routines::operation not supported for this
keytype]
EAP-TLS: Failed to initialize SSL.
Steps to reproduce:
1. Ubuntu 24.04 with TPM2-backed SCEP certificate in PKCS#11 (via
opensc-pkcs11.so, STMicro TPM)
2. Configure WPA2-Enterprise EAP-TLS using a pkcs11: URI for the private key
3. Upgrade libengine-pkcs11-openssl from 0.4.12-1.1build2 →
0.4.12-1.1ubuntu1
4. Attempt Wi-Fi connection → fails as above
Workaround: downgrade to 0.4.12-1.1build2
(sudo apt install libengine-pkcs11-openssl=0.4.12-1.1build2)
Environment:
- Ubuntu 24.04 Noble, OpenSSL 3.0.13
- wpa_supplicant + NetworkManager EAP-TLS
- TPM2 (STMicro), tpm2-tss 4.0.1, opensc 0.25.0~rc1
** Affects: libp11 (Ubuntu)
Importance: Undecided
Status: New
** Description changed:
- wpa_supplicant fails: "Esys_StartAuthSession: Could not create rsa key
(0x00070001)"
- EAP-TLS fails: "ENGINE: cannot load private key ... operation not supported
for this keytype"
- Affects TPM2-backed PKCS#11 certificates via opensc-pkcs11.so (STMicro TPM)
- Workaround: downgrade to 0.4.12-1.1build2
+ Workaround: downgrade to 0.4.12-1.1build2
+ (sudo apt install libengine-pkcs11-openssl=0.4.12-1.1build2)
Environment:
- Ubuntu 24.04 Noble, OpenSSL 3.0.13
- wpa_supplicant + NetworkManager EAP-TLS
- TPM2 (STMicro), tpm2-tss 4.0.1, opensc 0.25.0~rc1
** Description changed:
- wpa_supplicant fails: "Esys_StartAuthSession: Could not create rsa key
(0x00070001)"
- EAP-TLS fails: "ENGINE: cannot load private key ... operation not supported
for this keytype"
- Affects TPM2-backed PKCS#11 certificates via opensc-pkcs11.so (STMicro TPM)
- Workaround: downgrade to 0.4.12-1.1build2
+ Workaround: downgrade to 0.4.12-1.1build2
(sudo apt install libengine-pkcs11-openssl=0.4.12-1.1build2)
Environment:
- Ubuntu 24.04 Noble, OpenSSL 3.0.13
- wpa_supplicant + NetworkManager EAP-TLS
- TPM2 (STMicro), tpm2-tss 4.0.1, opensc 0.25.0~rc1
** Description changed:
- - wpa_supplicant fails: "Esys_StartAuthSession: Could not create rsa key
(0x00070001)"
- - EAP-TLS fails: "ENGINE: cannot load private key ... operation not supported
for this keytype"
- - Affects TPM2-backed PKCS#11 certificates via opensc-pkcs11.so (STMicro TPM)
+ Regression introduced between 0.4.12-1.1build2 → 0.4.12-1.1ubuntu1 .
+ The ubuntu1 patch added a fix for a segfault during signing on OpenSSL
+ 3.0.12–3.0.13 (cherry-picked from 0.4.13). This appears to have broken
+ the TPM2 auth session setup path.
+
+ Key log (wpa_supplicant):
+
+ tls_connection_set_params: Clearing pending SSL error: error:43000005:PKCS#11
module::General Error
+ tls_connection_set_params: Clearing pending SSL error: error:13000080:engine
routines::failed loading private key
+
ERROR:esys_crypto:src/tss2-esys/esys_crypto_ossl.c:723:iesys_cryptossl_pk_encrypt()
ErrorCode (0x00070001) Could not create rsa key.
+ ERROR: Esys_StartAuthSession: esapi:Catch all for all errors not otherwise
specified
+ ERROR: Could not start Auth Session with the TPM.
+ ERROR: Error unsealing wrapping key
+ ENGINE: cannot load private key with id
'pkcs11:token=scep-client;object=client-key;type=private'
[error:03000096:digital envelope routines::operation not supported for this
keytype]
+ EAP-TLS: Failed to initialize SSL.
+
+ Steps to reproduce:
+
+ 1. Ubuntu 24.04 with TPM2-backed SCEP certificate in PKCS#11 (via
opensc-pkcs11.so, STMicro TPM)
+ 2. Configure WPA2-Enterprise EAP-TLS using a pkcs11: URI for the private key
+ 3. Upgrade libengine-pkcs11-openssl from 0.4.12-1.1build2 →
0.4.12-1.1ubuntu1
+ 4. Attempt Wi-Fi connection → fails as above
Workaround: downgrade to 0.4.12-1.1build2
(sudo apt install libengine-pkcs11-openssl=0.4.12-1.1build2)
Environment:
- Ubuntu 24.04 Noble, OpenSSL 3.0.13
- wpa_supplicant + NetworkManager EAP-TLS
- TPM2 (STMicro), tpm2-tss 4.0.1, opensc 0.25.0~rc1
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163152
Title:
EAP-TLS Wi-Fi broken with TPM-backed PKCS#11 keys after upgrade to
0.4.12-1.1ubuntu1
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libp11/+bug/2163152/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs