[tpm2] Re: {External} Re: OpenSSL 3 and tpm2 provider... / openssl cms
Sievert, James <james.sievert at bsci.com> Thu, 28 Apr 2022 15:07:55 +0000
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | < <DS7PR03MB55766301B4D6369D582181AD9AFD9@DS7PR03MB5576.namprd03.prod.outlook.com>> |
I also tried this:
openssl cms -encrypt -provider tpm2 -provider base -propquery ?provider=tpm2,tpm2.cipher!=yes -in file.txt -recip handle:0x01000013 -aes128
Same result...
-----Original Message-----
From: Petr Gotthard <petr.gotthard(a)centrum.cz>
Sent: Wednesday, April 27, 2022 1:38 PM
To: tpm2(a)lists.01.org
Subject: [tpm2] Re: {External} Re: OpenSSL 3 and tpm2 provider... / openssl cms
>CMS encryption fails as follows:
>
>$ openssl cms -encrypt -provider tpm2 -provider base -in file.txt
>-recip handle:0x01000013
>WARNING:esys:src/tss2-esys/api/Esys_CreateLoaded.c:368:Esys_CreateLoade
>d_Finish() Received TPM Error
>ERROR:esys:src/tss2-esys/api/Esys_CreateLoaded.c:129:Esys_CreateLoaded(
>) Esys Finish ErrorCode (0x000b0143)
>40FCFCC0017F0000:error:4000000B:tpm2::cannot create key::-1:721219
>rmt:error(2.0): command code not supported
>
>This looks like https://github.com/tpm2-software/tpm2-openssl/issues/29.
> For my use case, support for TPMs without the CreateLoaded command will be essential. My machines have an OPTIGA TPM2.
The CreateLoaded issue should be fixed now (in the latest master branch).
Petr
_______________________________________________
tpm2 mailing list -- tpm2(a)lists.01.org
To unsubscribe send an email to tpm2-leave(a)lists.01.org %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s