Skip to content

test: test OpenSSL provider and engine if available - #950

Open
moritzbuhl wants to merge 8 commits into
tpm2-software:masterfrom
moritzbuhl:mbuhl-run-engine-and-provider
Open

moritzbuhl wants to merge 8 commits into
tpm2-software:masterfrom
moritzbuhl:mbuhl-run-engine-and-provider

Conversation

@moritzbuhl

Copy link
Copy Markdown
Member

I hope this can detect what is reported in #948.

@moritzbuhl
moritzbuhl force-pushed the mbuhl-run-engine-and-provider branch from b013470 to 8fcd058 Compare September 18, 2026 11:19
OpenSSL from 4.0 only supports providers.
OpenSSL between 3.0 and 3.5 can support engines and providers.
OpenSSL before 3.0 only supports engines.

So to test both providers and engines, add a dynamic check if engines
are supported and run the commands twice, once with the provider, once
with the engine.

Signed-off-by: Moritz Buhl <moritz.buhl@infineon.com>
We observe this error, specifically when trying to run with
tpm2-tss-engine:

ERROR: EVP_PKEY_fromdata_init: error:03000096:digital envelope routines::operation not supported for this keytype
40B7BEF79B7F0000:error:41800002:PKCS#11 module:ERR_CKR_error:Host memory error:p11_rsa.c:153:
40B7BEF79B7F0000:error:06880006:asn1 encoding routines:ASN1_item_sign_ctx:EVP lib:../crypto/asn1/a_sign.c:274:

The sign operation does not need the EVP pkey field as the TPM is
responsible for it.

Signed-off-by: Moritz Buhl <moritz.buhl@infineon.com>
@moritzbuhl
moritzbuhl force-pushed the mbuhl-run-engine-and-provider branch from 8fcd058 to ee197d4 Compare September 19, 2026 08:40
drencrom and others added 5 commits September 19, 2026 10:47
Signed-off-by: Jorge Merlino <jorge.merlino@canonical.com>
Fallback: EVP_PKEY_fromdata_init() requires ctx->keymgmt to be set,
which OpenSSL populates via EVP_KEYMGMT_fetch() -- but that fetch is
SKIPPED whenever some other component sharing this process (e.g. an
ENGINE such as libp11's engine_pkcs11, loaded via "-engine pkcs11"
for smartcard support) has registered itself as the process-wide
default EVP_PKEY_METHOD provider for RSA via ENGINE_set_default().
That is normal, expected ENGINE usage and not specific to this
caller, but it leaves ctx->keymgmt NULL here, and
EVP_PKEY_fromdata_init() (unlike OpenSSL releases before the
"foreign key" fix was reverted in PR #23063) no longer falls back
to a legacy pmeth-based path in that case, so it errors out even
though nothing is actually wrong with these e/n values.

Since this has nothing to do with providers/keymgmt at all, build
the EVP_PKEY directly via the classic RSA_set0_key() +
EVP_PKEY_assign_RSA() APIs instead (the same technique used by the
pre-OpenSSL-3.0 code path below, and by libp11 itself for wrapping
its own "foreign" keys), which sidesteps ENGINE/provider defaults
entirely.
@moritzbuhl
moritzbuhl force-pushed the mbuhl-run-engine-and-provider branch from e61a99a to 376db15 Compare September 21, 2026 11:52
@moritzbuhl

Copy link
Copy Markdown
Member Author

Now CI is failing with this error:

ERROR:esys_crypto:src/tss2-esys/esys_crypto_ossl.c:751:iesys_cryptossl_pk_encrypt() ErrorCode (0x00070001) Could not create rsa key. 
ERROR:esys:src/tss2-esys/esys_iutil.c:406:iesys_compute_encrypted_salt() During encryption. ErrorCode (0x00070001) 
ERROR:esys:src/tss2-esys/api/Esys_StartAuthSession.c:225:Esys_StartAuthSession_Async() Error in parameter encryption. ErrorCode (0x00070001) 
ERROR:esys:src/tss2-esys/api/Esys_StartAuthSession.c:117:Esys_StartAuthSession() Error in async function ErrorCode (0x00070001) 
ERROR: Esys_StartAuthSession: esapi:Catch all for all errors not otherwise specified
ERROR: Could not start Auth Session with the TPM.
ERROR: Error unsealing wrapping key

I already created tpm2-software/tpm2-tss#3151

@moritzbuhl

Copy link
Copy Markdown
Member Author

Once tpm2-software/tpm2-tss#3161 is in, the tests should pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants