[tpm2] Re: TPM for SSH authentication

Roberts, William C <william.c.roberts at intel.com>
Newsgroups dev.linux.lists.tpm2
Message-ID <SN6PR11MB3437F8CC917EF93CFA4765ECB8E39@SN6PR11MB3437.namprd11.prod.outlook.com>
The tpm2-pkcs11 project supports two backends:
  - The original backend (sqlite3)
  - The FAPI backend (file system stores)

Their is a document describing how to set up SSH using the original backend:
https://github.com/tpm2-software/tpm2-pkcs11/blob/master/docs/SSH.md

If you really want to use the FAPI backend, you need to get tss2_provision to work, not exactly sure what the error is there.
But perhaps others will know.


________________________________
From: scott.r.eisele(a)gmail.com <scott.r.eisele(a)gmail.com>
Sent: Monday, July 19, 2021 10:36 PM
To: tpm2(a)lists.01.org <tpm2(a)lists.01.org>
Subject: [tpm2] TPM for SSH authentication

Hi everyone!
I'm trying to use a TPM to secure ssh keys, following the example here: https://incenp.org/notes/2020/tpm-based-ssh-key.html
First, is this a standard way to secure ssh keys? Or is there another method that is preferred?

Assuming this method is acceptable, I made it to the point of extracting the public key from the PKCS11 token but ran into an issue.

$ ssh-keygen -vvv -D /usr/local/lib/libtpm2_pkcs11.so > tpm2key1.pub
WARNING:fapi:src/tss2-fapi/api/Fapi_List.c:226:Fapi_List_Finish() Profile of path not provisioned: /HS/SRK
ERROR:fapi:src/tss2-fapi/api/Fapi_List.c:81:Fapi_List() ErrorCode (0x00060034) Entities_List
ERROR: Listing FAPI token objects failed.
debug1: provider /usr/local/lib/libtpm2_pkcs11.so: manufacturerID <tpm2-software.github.io> cryptokiVersion 2.40 libraryDescription <TPM2.0 Cryptoki> libraryVersion 0.0
debug1: provider /usr/local/lib/libtpm2_pkcs11.so slot 0: label <firstToken> manufacturerID <Infineon> model <SLB9670> serial <000000000000000> flags 0x40d
debug1: have 1 keys
debug2: pkcs11_register_provider: ignoring uninitialised token in provider /usr/local/lib/libtpm2_pkcs11.so slot 1
debug1: pkcs11_k11_free: parent 0xaaaaf0703630 ptr 0xaaaaf06ed350 idx 1
debug1: pkcs11_provider_unref: 0xaaaaf0692300 refcount 2
debug1: pkcs11_provider_finalize: 0xaaaaf0692300 refcount 1 valid 1
debug1: pkcs11_provider_unref: 0xaaaaf0692300 refcount 1

I then tried running Fapi_List() directly:

$ sudo tss2_list
WARNING:fapi:src/tss2-fapi/api/Fapi_List.c:216:Fapi_List_Finish() Path not found:
ERROR:fapi:src/tss2-fapi/api/Fapi_List.c:81:Fapi_List() ErrorCode (0x00060034) Entities_List
Fapi_List(0x60034) - fapi:Provisioning was not executed.

And assumed that provisioning was required. So I attempted that:

$ sudo tss2_provision
ERROR:fapi:src/tss2-fapi/api/Fapi_Provision.c:520:Fapi_Provision_Finish() ErrorCode (0x0006000b) SRK persistent handle already defined
ERROR:fapi:src/tss2-fapi/api/Fapi_Provision.c:168:Fapi_Provision() ErrorCode (0x0006000b) Provision
Fapi_Provision(0x6000B) - fapi:A parameter has a bad value

At this point, I'm at a loss as to what the state of the TPM is and how to properly provision it and establish the Storage Hierarchy.
I've looked at https://trustedcomputinggroup.org/wp-content/uploads/TCG-TPM-v2.0-Provisioning-Guidance-Published-v1r1.pdf
but it's not clear to me how to apply it.

Any help would be great. Thanks!

My platform configuration is:
raspberry pi 3b+
Infineon OPTIGA™ TPM SLx 9670
ubuntu 20.04
tpm2-tss-3.1.0
tpm2-tools-5.1.1
tpm2-abrmd-2.4.0
tpm2-pkcs11-1.6.0
_______________________________________________
tpm2 mailing list -- tpm2(a)lists.01.org
To unsubscribe send an email to tpm2-leave(a)lists.01.org
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
attachment.htm (text/html, 5.4 KB)
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The tpm2-pkcs11 project supports two backends:</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
&nbsp; - The original backend (sqlite3)</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
&nbsp; - The FAPI backend (file system stores)</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Their is a document describing how to set up SSH using the original backend:</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<a href="https://github.com/tpm2-software/tpm2-pkcs11/blob/master/docs/SSH.md" id="LPlnk">https://github.com/tpm2-software/tpm2-pkcs11/blob/master/docs/SSH.md</a><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div>If you really want to use the FAPI backend, you need to get tss2_provision to work, not exactly sure what the error is there.</div>
<div>But perhaps others will know.</div>
<div class="_Entity _EType_OWALinkPreview _EId_OWALinkPreview _EReadonly_1"></div>
<br>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> [email protected] &lt;[email protected]&gt;<br>
<b>Sent:</b> Monday, July 19, 2021 10:36 PM<br>
<b>To:</b> [email protected] &lt;[email protected]&gt;<br>
<b>Subject:</b> [tpm2] TPM for SSH authentication</font>
<div>&nbsp;</div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">Hi everyone!<br>
I'm trying to use a TPM to secure ssh keys, following the example here: <a href="https://incenp.org/notes/2020/tpm-based-ssh-key.html">
https://incenp.org/notes/2020/tpm-based-ssh-key.html</a><br>
First, is this a standard way to secure ssh keys? Or is there another method that is preferred?
<br>
<br>
Assuming this method is acceptable, I made it to the point of extracting the public key from the PKCS11 token but ran into an issue.<br>
<br>
$ ssh-keygen -vvv -D /usr/local/lib/libtpm2_pkcs11.so &gt; tpm2key1.pub<br>
WARNING:fapi:src/tss2-fapi/api/Fapi_List.c:226:Fapi_List_Finish() Profile of path not provisioned: /HS/SRK
<br>
ERROR:fapi:src/tss2-fapi/api/Fapi_List.c:81:Fapi_List() ErrorCode (0x00060034) Entities_List
<br>
ERROR: Listing FAPI token objects failed.<br>
debug1: provider /usr/local/lib/libtpm2_pkcs11.so: manufacturerID &lt;tpm2-software.github.io&gt; cryptokiVersion 2.40 libraryDescription &lt;TPM2.0 Cryptoki&gt; libraryVersion 0.0<br>
debug1: provider /usr/local/lib/libtpm2_pkcs11.so slot 0: label &lt;firstToken&gt; manufacturerID &lt;Infineon&gt; model &lt;SLB9670&gt; serial &lt;000000000000000&gt; flags 0x40d<br>
debug1: have 1 keys<br>
debug2: pkcs11_register_provider: ignoring uninitialised token in provider /usr/local/lib/libtpm2_pkcs11.so slot 1<br>
debug1: pkcs11_k11_free: parent 0xaaaaf0703630 ptr 0xaaaaf06ed350 idx 1<br>
debug1: pkcs11_provider_unref: 0xaaaaf0692300 refcount 2<br>
debug1: pkcs11_provider_finalize: 0xaaaaf0692300 refcount 1 valid 1<br>
debug1: pkcs11_provider_unref: 0xaaaaf0692300 refcount 1<br>
<br>
I then tried running Fapi_List() directly:<br>
<br>
$ sudo tss2_list<br>
WARNING:fapi:src/tss2-fapi/api/Fapi_List.c:216:Fapi_List_Finish() Path not found:&nbsp;
<br>
ERROR:fapi:src/tss2-fapi/api/Fapi_List.c:81:Fapi_List() ErrorCode (0x00060034) Entities_List
<br>
Fapi_List(0x60034) - fapi:Provisioning was not executed.<br>
<br>
And assumed that provisioning was required. So I attempted that:<br>
<br>
$ sudo tss2_provision <br>
ERROR:fapi:src/tss2-fapi/api/Fapi_Provision.c:520:Fapi_Provision_Finish() ErrorCode (0x0006000b) SRK persistent handle already defined
<br>
ERROR:fapi:src/tss2-fapi/api/Fapi_Provision.c:168:Fapi_Provision() ErrorCode (0x0006000b) Provision
<br>
Fapi_Provision(0x6000B) - fapi:A parameter has a bad value<br>
<br>
At this point, I'm at a loss as to what the state of the TPM is and how to properly provision it and establish the Storage Hierarchy.
<br>
I've looked at <a href="https://trustedcomputinggroup.org/wp-content/uploads/TCG-TPM-v2.0-Provisioning-Guidance-Published-v1r1.pdf">
https://trustedcomputinggroup.org/wp-content/uploads/TCG-TPM-v2.0-Provisioning-Guidance-Published-v1r1.pdf</a><br>
but it's not clear to me how to apply it. <br>
<br>
Any help would be great. Thanks!<br>
<br>
My platform configuration is: <br>
raspberry pi 3b+<br>
Infineon OPTIGA™ TPM SLx 9670<br>
ubuntu 20.04<br>
tpm2-tss-3.1.0<br>
tpm2-tools-5.1.1<br>
tpm2-abrmd-2.4.0<br>
tpm2-pkcs11-1.6.0<br>
_______________________________________________<br>
tpm2 mailing list -- [email protected]<br>
To unsubscribe send an email to [email protected]<br>
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s</div>
</span></font></div>
</body>
</html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.