Re: OpenSSL3/libp11 RSA keygen
Alexandre Gonzalo via Opensc-devel <[email protected]> Fri, 18 Nov 2022 12:48:39 +0000
| Newsgroups | gmane.comp.encryption.opensc.devel |
|---|---|
| Message-ID | <CWXP123MB41361639E92AAC3E91B036F8F6099@CWXP123MB4136.GBRP123.PROD.OUTLOOK.COM> |
--===============6043066555383993904== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_CWXP123MB41361639E92AAC3E91B036F8F6099CWXP123MB4136GBRP_" --_000_CWXP123MB41361639E92AAC3E91B036F8F6099CWXP123MB4136GBRP_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hi Jakub, Thanks for your feedback. I will have a look at the provider and start to play with it. Best Regards, Alexandre. ________________________________ From: Jakub Jelen <[email protected]> Sent: Friday, November 18, 2022 12:01 PM To: [email protected] <[email protected]> Subject: Re: [Opensc-devel] OpenSSL3/libp11 RSA keygen On 11/15/22 15:55, Alexandre Gonzalo via Opensc-devel wrote: > Hi All, > > I'd like to know if the libp11 engine officially supports OpenSSL v3. > I am trying to generate an RSA key with the following command and I have > an error: > openssl genrsa -out dummy 4096 > Error setting RSA length > F85455EE79000000:error:03000093:digital envelope > routines:evp_pkey_ctx_ctrl_int:command not > supported:crypto/evp/pmeth_lib.c:1324: > > It is working fine when I don't use the engine. > > I initially thought that it was a bug in OpenSSL and reported the issue: > https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fgithu= b.com%2Fopenssl%2Fopenssl%2Fissues%2F19680&data=3D05%7C01%7Calexandre.g= onzalo%40trustonic.com%7Cf6469657171b4589a26308dac9544253%7C923aa3d7d8884cf= 2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown%7CTWFpbGZsb3d8eyJW= IjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C= %7C&sdata=3Dbs6DP%2BPd6VcepeAgfs9FgenS8C7m%2BhDBrLD1VzR%2BTcE%3D&re= served=3D0 > <https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fgith= ub.com%2Fopenssl%2Fopenssl%2Fissues%2F19680&data=3D05%7C01%7Calexandre.= gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac9544253%7C923aa3d7d8884c= f2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown%7CTWFpbGZsb3d8eyJ= WIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7= C%7C&sdata=3Dbs6DP%2BPd6VcepeAgfs9FgenS8C7m%2BhDBrLD1VzR%2BTcE%3D&r= eserved=3D0> The OpenSSL 3.0 deprecated engines and libp11 is an openssl engine so they might keep working, but they will be phased out. The libp11 engine to my understanding does not support key generation unless the following pull request will be merged: https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fgithub.= com%2FOpenSC%2Flibp11%2Fpull%2F474&data=3D05%7C01%7Calexandre.gonzalo%4= 0trustonic.com%7Cf6469657171b4589a26308dac9544253%7C923aa3d7d8884cf2a36a9a9= c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4w= LjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&= sdata=3D25RJIcrErB8LMgqO7BAvACYdaXc%2FRgrV0N0tCHkpu3o%3D&reserved=3D0 On the other hand, there is a pkcs11 provider implementation in progress and I AFAIK the key generation is part of the testsuite already and that part should work: https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fgithub.= com%2Flatchset%2Fpkcs11-provider&data=3D05%7C01%7Calexandre.gonzalo%40t= rustonic.com%7Cf6469657171b4589a26308dac9544253%7C923aa3d7d8884cf2a36a9a9c3= c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLj= AwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sd= ata=3DLi%2FPIMbjORYAyHxr0ASxOqqz%2BWCAaUvX%2FwDqCobxlBs%3D&reserved=3D0 But keep in mind that this is still in development so it might not have all the corner cases resolved, but any feedback would be welcomed. Regards, -- Jakub Jelen Crypto Team, Security Engineering Red Hat, Inc. _______________________________________________ Opensc-devel mailing list [email protected] https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Flists.s= ourceforge.net%2Flists%2Flistinfo%2Fopensc-devel&data=3D05%7C01%7Calexa= ndre.gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac9544253%7C923aa3d7d= 8884cf2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown%7CTWFpbGZsb3= d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000= %7C%7C%7C&sdata=3DsSgRDXiFcU%2F%2FIKMGJC8snz6jofhpyXLKHbzkrMie3ZY%3D&am= p;reserved=3D0 CAUTION: This email originated from outside of Trustonic. The message might= not be safe, be cautious of attachments and links herein. If in doubt, con= tact the sender by other means or discard this message, especially if the o= rigin is unexpected and the sender is unknown. Trustonic SAS - 535 route de Lucioles, Les Aqueducs Batiment 2, Sophia Anti= polis 06560 Valbonne, France - SAS au capital de 3 038 000EUR - RCS Grasse = - SIRET 480 011 998 00055 - TVA intracommunautaire : FR02 480 011 998 --_000_CWXP123MB41361639E92AAC3E91B036F8F6099CWXP123MB4136GBRP_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > <style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo= ttom:0;} </style> </head> <body dir=3D"ltr"> <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class= =3D"elementToProof"> Hi Jakub,</div> <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class= =3D"elementToProof"> <br> </div> <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class= =3D"elementToProof"> Thanks for your feedback.</div> <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class= =3D"elementToProof"> I will have a look at the provider and start to play with it.</div> <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class= =3D"elementToProof"> <br> </div> <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class= =3D"elementToProof"> Best Regards,</div> <div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class= =3D"elementToProof"> Alexandre.</div> <div id=3D"appendonsend"></div> <hr style=3D"display:inline-block;width:98%" tabindex=3D"-1"> <div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st= yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> Jakub Jelen <jjele= [email protected]><br> <b>Sent:</b> Friday, November 18, 2022 12:01 PM<br> <b>To:</b> [email protected] <[email protected]= forge.net><br> <b>Subject:</b> Re: [Opensc-devel] OpenSSL3/libp11 RSA keygen</font> <div> </div> </div> <div class=3D"BodyFragment"><font size=3D"2"><span style=3D"font-size:11pt;= "> <div class=3D"PlainText">On 11/15/22 15:55, Alexandre Gonzalo via Opensc-de= vel wrote:<br> > Hi All,<br> ><br> > I'd like to know if the libp11 engine officially supports OpenSSL v3.<= br> > I am trying to generate an RSA key with the following command and I ha= ve<br> > an error:<br> > openssl genrsa -out dummy 4096<br> > Error setting RSA length<br> > F85455EE79000000:error:03000093:digital envelope<br> > routines:evp_pkey_ctx_ctrl_int:command not<br> > supported:crypto/evp/pmeth_lib.c:1324:<br> ><br> > It is working fine when I don't use the engine.<br> ><br> > I initially thought that it was a bug in OpenSSL and reported the issu= e:<br> > <a href=3D"https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps= %3A%2F%2Fgithub.com%2Fopenssl%2Fopenssl%2Fissues%2F19680&amp;data=3D05%= 7C01%7Calexandre.gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac9544253= %7C923aa3d7d8884cf2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown%= 7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6M= n0%3D%7C3000%7C%7C%7C&amp;sdata=3Dbs6DP%2BPd6VcepeAgfs9FgenS8C7m%2BhDBr= LD1VzR%2BTcE%3D&amp;reserved=3D0"> https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fgithub.= com%2Fopenssl%2Fopenssl%2Fissues%2F19680&amp;data=3D05%7C01%7Calexandre= .gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac9544253%7C923aa3d7d8884= cf2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown%7CTWFpbGZsb3d8ey= JWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%= 7C%7C&amp;sdata=3Dbs6DP%2BPd6VcepeAgfs9FgenS8C7m%2BhDBrLD1VzR%2BTcE%3D&= amp;amp;reserved=3D0</a><br> > <<a href=3D"https://gbr01.safelinks.protection.outlook.com/?url=3Dh= ttps%3A%2F%2Fgithub.com%2Fopenssl%2Fopenssl%2Fissues%2F19680&amp;data= =3D05%7C01%7Calexandre.gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac9= 544253%7C923aa3d7d8884cf2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUn= known%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJ= XVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=3Dbs6DP%2BPd6VcepeAgfs9FgenS8C7m%= 2BhDBrLD1VzR%2BTcE%3D&amp;reserved=3D0">https://gbr01.safelinks.protect= ion.outlook.com/?url=3Dhttps%3A%2F%2Fgithub.com%2Fopenssl%2Fopenssl%2Fissue= s%2F19680&amp;data=3D05%7C01%7Calexandre.gonzalo%40trustonic.com%7Cf646= 9657171b4589a26308dac9544253%7C923aa3d7d8884cf2a36a9a9c3c53e9ae%7C0%7C0%7C6= 38043660973489085%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luM= zIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=3Dbs6DP%2BP= d6VcepeAgfs9FgenS8C7m%2BhDBrLD1VzR%2BTcE%3D&amp;reserved=3D0</a>><br= > <br> The OpenSSL 3.0 deprecated engines and libp11 is an openssl engine so<br> they might keep working, but they will be phased out. The libp11 engine<br> to my understanding does not support key generation unless the following<br= > pull request will be merged:<br> <br> <a href=3D"https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2= F%2Fgithub.com%2FOpenSC%2Flibp11%2Fpull%2F474&amp;data=3D05%7C01%7Calex= andre.gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac9544253%7C923aa3d7= d8884cf2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown%7CTWFpbGZsb= 3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C300= 0%7C%7C%7C&amp;sdata=3D25RJIcrErB8LMgqO7BAvACYdaXc%2FRgrV0N0tCHkpu3o%3D= &amp;reserved=3D0">https://gbr01.safelinks.protection.outlook.com/?url= =3Dhttps%3A%2F%2Fgithub.com%2FOpenSC%2Flibp11%2Fpull%2F474&amp;data=3D0= 5%7C01%7Calexandre.gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac95442= 53%7C923aa3d7d8884cf2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknow= n%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI= 6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=3D25RJIcrErB8LMgqO7BAvACYdaXc%2FRgrV0= N0tCHkpu3o%3D&amp;reserved=3D0</a><br> <br> On the other hand, there is a pkcs11 provider implementation in progress<br= > and I AFAIK the key generation is part of the testsuite already and that<br= > part should work:<br> <br> <a href=3D"https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2= F%2Fgithub.com%2Flatchset%2Fpkcs11-provider&amp;data=3D05%7C01%7Calexan= dre.gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac9544253%7C923aa3d7d8= 884cf2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown%7CTWFpbGZsb3d= 8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%= 7C%7C%7C&amp;sdata=3DLi%2FPIMbjORYAyHxr0ASxOqqz%2BWCAaUvX%2FwDqCobxlBs%= 3D&amp;reserved=3D0">https://gbr01.safelinks.protection.outlook.com/?ur= l=3Dhttps%3A%2F%2Fgithub.com%2Flatchset%2Fpkcs11-provider&amp;data=3D05= %7C01%7Calexandre.gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac954425= 3%7C923aa3d7d8884cf2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnknown= %7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6= Mn0%3D%7C3000%7C%7C%7C&amp;sdata=3DLi%2FPIMbjORYAyHxr0ASxOqqz%2BWCAaUvX= %2FwDqCobxlBs%3D&amp;reserved=3D0</a><br> <br> But keep in mind that this is still in development so it might not have<br> all the corner cases resolved, but any feedback would be welcomed.<br> <br> Regards,<br> --<br> Jakub Jelen<br> Crypto Team, Security Engineering<br> Red Hat, Inc.<br> <br> <br> <br> _______________________________________________<br> Opensc-devel mailing list<br> [email protected]<br> <a href=3D"https://gbr01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2= F%2Flists.sourceforge.net%2Flists%2Flistinfo%2Fopensc-devel&amp;data=3D= 05%7C01%7Calexandre.gonzalo%40trustonic.com%7Cf6469657171b4589a26308dac9544= 253%7C923aa3d7d8884cf2a36a9a9c3c53e9ae%7C0%7C0%7C638043660973489085%7CUnkno= wn%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVC= I6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=3DsSgRDXiFcU%2F%2FIKMGJC8snz6jofhpyX= LKHbzkrMie3ZY%3D&amp;reserved=3D0">https://gbr01.safelinks.protection.o= utlook.com/?url=3Dhttps%3A%2F%2Flists.sourceforge.net%2Flists%2Flistinfo%2F= opensc-devel&amp;data=3D05%7C01%7Calexandre.gonzalo%40trustonic.com%7Cf= 6469657171b4589a26308dac9544253%7C923aa3d7d8884cf2a36a9a9c3c53e9ae%7C0%7C0%= 7C638043660973489085%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2= luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=3DsSgRDX= iFcU%2F%2FIKMGJC8snz6jofhpyXLKHbzkrMie3ZY%3D&amp;reserved=3D0</a><br> CAUTION: This email originated from outside of Trustonic. The message might= not be safe, be cautious of attachments and links herein. If in doubt, con= tact the sender by other means or discard this message, especially if the o= rigin is unexpected and the sender is unknown.<br> <br> </div> </span></font></div> <br> <div style=3D"font-size:9pt; font-family: 'Calibri',sans-serif;"> <p style=3D"font-size:7pt; line-height:9pt; color:#bebebe; font-family: 'Ca= libri', Arial, Verdana, serif;"> Trustonic SAS - 535 route de Lucioles, Les Aqueducs Batiment 2, Sophia Anti= polis 06560 Valbonne, France – SAS au capital de 3 038 000€ - R= CS Grasse – SIRET 480 011 998 00055 - TVA intracommunautaire : FR02 4= 80 011 998</p> </div> </body> </html> --_000_CWXP123MB41361639E92AAC3E91B036F8F6099CWXP123MB4136GBRP_-- --===============6043066555383993904== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============6043066555383993904== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Opensc-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/opensc-devel --===============6043066555383993904==--