Public bug reported:

Regression introduced between  0.4.12-1.1build2  →  0.4.12-1.1ubuntu1 .
The  ubuntu1  patch added a fix for a segfault during signing on OpenSSL
3.0.12–3.0.13 (cherry-picked from 0.4.13). This appears to have broken
the TPM2 auth session setup path.

Key log (wpa_supplicant):

tls_connection_set_params: Clearing pending SSL error: error:43000005:PKCS#11 
module::General Error
tls_connection_set_params: Clearing pending SSL error: error:13000080:engine 
routines::failed loading private key
ERROR:esys_crypto:src/tss2-esys/esys_crypto_ossl.c:723:iesys_cryptossl_pk_encrypt()
 ErrorCode (0x00070001) Could not create rsa key.
ERROR: Esys_StartAuthSession: esapi:Catch all for all errors not otherwise 
specified
ERROR: Could not start Auth Session with the TPM.
ERROR: Error unsealing wrapping key
ENGINE: cannot load private key with id 
'pkcs11:token=scep-client;object=client-key;type=private' 
[error:03000096:digital envelope routines::operation not supported for this 
keytype]
EAP-TLS: Failed to initialize SSL.

Steps to reproduce:

1. Ubuntu 24.04 with TPM2-backed SCEP certificate in PKCS#11 (via 
opensc-pkcs11.so, STMicro TPM)
2. Configure WPA2-Enterprise EAP-TLS using a  pkcs11:  URI for the private key
3. Upgrade  libengine-pkcs11-openssl  from  0.4.12-1.1build2  →  
0.4.12-1.1ubuntu1 
4. Attempt Wi-Fi connection → fails as above 

Workaround: downgrade to 0.4.12-1.1build2
(sudo apt install libengine-pkcs11-openssl=0.4.12-1.1build2)

Environment:
- Ubuntu 24.04 Noble, OpenSSL 3.0.13
- wpa_supplicant + NetworkManager EAP-TLS
- TPM2 (STMicro), tpm2-tss 4.0.1, opensc 0.25.0~rc1

** Affects: libp11 (Ubuntu)
     Importance: Undecided
         Status: New

** Description changed:

  - wpa_supplicant fails: "Esys_StartAuthSession: Could not create rsa key 
(0x00070001)"
  - EAP-TLS fails: "ENGINE: cannot load private key ... operation not supported 
for this keytype"
  - Affects TPM2-backed PKCS#11 certificates via opensc-pkcs11.so (STMicro TPM)
  
- Workaround: downgrade to 0.4.12-1.1build2
+ Workaround: downgrade to 0.4.12-1.1build2 
+ (sudo apt install libengine-pkcs11-openssl=0.4.12-1.1build2)
  
  Environment:
  - Ubuntu 24.04 Noble, OpenSSL 3.0.13
  - wpa_supplicant + NetworkManager EAP-TLS
  - TPM2 (STMicro), tpm2-tss 4.0.1, opensc 0.25.0~rc1

** Description changed:

  - wpa_supplicant fails: "Esys_StartAuthSession: Could not create rsa key 
(0x00070001)"
  - EAP-TLS fails: "ENGINE: cannot load private key ... operation not supported 
for this keytype"
  - Affects TPM2-backed PKCS#11 certificates via opensc-pkcs11.so (STMicro TPM)
  
- Workaround: downgrade to 0.4.12-1.1build2 
+ Workaround: downgrade to 0.4.12-1.1build2
  (sudo apt install libengine-pkcs11-openssl=0.4.12-1.1build2)
  
  Environment:
  - Ubuntu 24.04 Noble, OpenSSL 3.0.13
  - wpa_supplicant + NetworkManager EAP-TLS
  - TPM2 (STMicro), tpm2-tss 4.0.1, opensc 0.25.0~rc1

** Description changed:

- - wpa_supplicant fails: "Esys_StartAuthSession: Could not create rsa key 
(0x00070001)"
- - EAP-TLS fails: "ENGINE: cannot load private key ... operation not supported 
for this keytype"
- - Affects TPM2-backed PKCS#11 certificates via opensc-pkcs11.so (STMicro TPM)
+ Regression introduced between  0.4.12-1.1build2  →  0.4.12-1.1ubuntu1 .
+ The  ubuntu1  patch added a fix for a segfault during signing on OpenSSL
+ 3.0.12–3.0.13 (cherry-picked from 0.4.13). This appears to have broken
+ the TPM2 auth session setup path.
+ 
+ Key log (wpa_supplicant):
+ 
+ tls_connection_set_params: Clearing pending SSL error: error:43000005:PKCS#11 
module::General Error
+ tls_connection_set_params: Clearing pending SSL error: error:13000080:engine 
routines::failed loading private key
+ 
ERROR:esys_crypto:src/tss2-esys/esys_crypto_ossl.c:723:iesys_cryptossl_pk_encrypt()
 ErrorCode (0x00070001) Could not create rsa key.
+ ERROR: Esys_StartAuthSession: esapi:Catch all for all errors not otherwise 
specified
+ ERROR: Could not start Auth Session with the TPM.
+ ERROR: Error unsealing wrapping key
+ ENGINE: cannot load private key with id 
'pkcs11:token=scep-client;object=client-key;type=private' 
[error:03000096:digital envelope routines::operation not supported for this 
keytype]
+ EAP-TLS: Failed to initialize SSL.
+ 
+ Steps to reproduce:
+ 
+ 1. Ubuntu 24.04 with TPM2-backed SCEP certificate in PKCS#11 (via 
opensc-pkcs11.so, STMicro TPM)
+ 2. Configure WPA2-Enterprise EAP-TLS using a  pkcs11:  URI for the private key
+ 3. Upgrade  libengine-pkcs11-openssl  from  0.4.12-1.1build2  →  
0.4.12-1.1ubuntu1 
+ 4. Attempt Wi-Fi connection → fails as above 
  
  Workaround: downgrade to 0.4.12-1.1build2
  (sudo apt install libengine-pkcs11-openssl=0.4.12-1.1build2)
  
  Environment:
  - Ubuntu 24.04 Noble, OpenSSL 3.0.13
  - wpa_supplicant + NetworkManager EAP-TLS
  - TPM2 (STMicro), tpm2-tss 4.0.1, opensc 0.25.0~rc1

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163152

Title:
  EAP-TLS Wi-Fi broken with TPM-backed PKCS#11 keys after upgrade to
  0.4.12-1.1ubuntu1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libp11/+bug/2163152/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to