[tpm2] Re: {External} Re: OpenSSL 3 and tpm2 provider... / openssl cms

Sievert, James <james.sievert at bsci.com> Thu, 28 Apr 2022 15:07:55 +0000
Newsgroups dev.linux.lists.tpm2
Message-ID < <DS7PR03MB55766301B4D6369D582181AD9AFD9@DS7PR03MB5576.namprd03.prod.outlook.com>>
I also tried this:  

openssl cms -encrypt -provider tpm2 -provider base -propquery ?provider=tpm2,tpm2.cipher!=yes -in file.txt -recip handle:0x01000013 -aes128

Same result...

-----Original Message-----
From: Petr Gotthard <petr.gotthard(a)centrum.cz> 
Sent: Wednesday, April 27, 2022 1:38 PM
To: tpm2(a)lists.01.org
Subject: [tpm2] Re: {External} Re: OpenSSL 3 and tpm2 provider... / openssl cms

>CMS encryption fails as follows:
>
>$ openssl cms -encrypt -provider tpm2 -provider base -in file.txt 
>-recip handle:0x01000013
>WARNING:esys:src/tss2-esys/api/Esys_CreateLoaded.c:368:Esys_CreateLoade
>d_Finish() Received TPM Error
>ERROR:esys:src/tss2-esys/api/Esys_CreateLoaded.c:129:Esys_CreateLoaded(
>) Esys Finish ErrorCode (0x000b0143) 
>40FCFCC0017F0000:error:4000000B:tpm2::cannot create key::-1:721219 
>rmt:error(2.0): command code not supported
>
>This looks like https://github.com/tpm2-software/tpm2-openssl/issues/29.
> For my use case, support for TPMs without the CreateLoaded command will be essential.  My machines have an OPTIGA TPM2.

The CreateLoaded issue should be fixed now (in the latest master branch).


Petr
_______________________________________________
tpm2 mailing list -- tpm2(a)lists.01.org
To unsubscribe send an email to tpm2-leave(a)lists.01.org %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s