[tpm2] Need help: Nginx and TPM2 Connection Problem

Rajkumar K Sivasamy <rajkumar.k.sivasamy at gmail.com> Tue, 19 Jul 2022 20:32:01 +0530
Newsgroups dev.linux.lists.tpm2
Message-ID <CADu5HqycgfoU-6nF6M=3Az_7O4ten+B0e7nj5D6e9QEKkG=zEg@mail.gmail.com>
Team

We are running Ngnix which uses TPM 2.0 Engine through Ngnix config option
"ssl_engine tpm2tss"; now when Ngnix trying to make use of the *tpm2tss *engine
it is hitting following error:

   - The 'nginx' worker process is unable to access the 'dbus' exposed by
   the 'tabrmd' process. Looking into the 'nginx' error log, the following
   errors are seen:

** (process:8020): CRITICAL **: failed to allocate dbus proxy object:
Timeout was reached

ERROR:tcti:src/tss2-tcti/tctildr-dl.c:154:tcti_from_file() Could not
initialize TCTI file: libtss2-tcti-tabrmd.so.0



   - ‘dbus’ shows warnings with the following logs:

dbus[1928]: [system] Connection has not authenticated soon enough, closing
it (auth_timeout=30000ms, elapsed: 30001ms)



   - Whenever 'nginx' is trying to connect to backend server, it is closing
   the connection. In the logs, SSL handshake failure messages are seen. The
   SSL connection is not working, it is getting closed.

nginx: [info] 8020#0: *2 peer closed connection in SSL handshake while SSL
handshaking, client: <IP_Address>, server: 0.0.0.0:443



Version of packages:

kernel 4.14.76

nginx 1.14.0

openssl 1.1.1

tpm2-abrmd 2.3.2

Note that the openssl when executed directly it is able to make use of
TPM2.0 engine and we have other processes which makes use of tpm2tss and
they are all working fine, the problem is only with Ngnix. We would need
your help here, can you let us know how to resolve this "*failed to
allocate dbus proxy object*" error?

Thanks
Raj
attachment.htm (text/html, 5 KB)
<div dir="ltr"><div>Team</div><div><br></div><div>We are running Ngnix which uses TPM 2.0 Engine through Ngnix config option &quot;ssl_engine tpm2tss&quot;; now when N<span style="font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif;color:black">gnix trying to make use of the <i>tpm2tss </i>engine it is hitting following error:</span></div><div><ul style="margin-top:0in;margin-bottom:0in" type="disc"><li class="gmail-MsoListParagraph" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span>The &#39;nginx&#39; worker process is unable to access the &#39;dbus&#39; exposed by the
     &#39;tabrmd&#39; process. Looking into the &#39;nginx&#39; error log, the following errors
     are seen:<span></span></span></li></ul>

<p class="MsoNormal" style="margin:0in 0in 0in 40px;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;">**
(process:8020): CRITICAL **: failed to allocate dbus proxy object: Timeout was
reached<span></span></span></p><div style="margin-left:40px">

</div><p class="MsoNormal" style="margin:0in 0in 0in 40px;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;">ERROR:tcti:src/tss2-tcti/tctildr-dl.c:154:tcti_from_file()
Could not initialize TCTI file: libtss2-tcti-tabrmd.so.0</span></p><p class="MsoNormal" style="margin:0in 0in 0in 40px;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;"><br></span></p><p class="MsoNormal" style="margin:0in 0in 0in 40px;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;">


















</span></p><ul style="margin-top:0in;margin-bottom:0in" type="disc"><li class="gmail-MsoListParagraph" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span>‘dbus’ shows warnings
     with the following logs:<span></span></span></li></ul>

<p class="MsoNormal" style="margin:0in 0in 0in 40px;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;">dbus[1928]:
[system] Connection has not authenticated soon enough, closing it
(auth_timeout=30000ms, elapsed: 30001ms)<span></span></span></p>





<p class="MsoNormal" style="margin:0in 0in 0in 40px;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;"><span></span></span></p><div style="margin-left:40px">





</div></div><div><br></div><div>


















<ul style="margin-top:0in;margin-bottom:0in" type="disc"><li class="gmail-MsoListParagraph" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span>Whenever &#39;nginx&#39; is
     trying to connect to backend server, it is closing the connection. In the
     logs, SSL handshake failure messages are seen. The SSL connection is not
     working, it is getting closed.<span></span></span></li></ul>

<p class="MsoNormal" style="margin:0in 0in 0in 40px;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;">nginx:
[info] 8020#0: *2 peer closed connection in SSL handshake while SSL
handshaking, client: &lt;IP_Address&gt;, server: <a href="http://0.0.0.0:443">0.0.0.0:443</a><span></span></span></p>

<p class="MsoNormal" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span> </span></p><p class="MsoNormal" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span>Version of packages:</span></p><p class="MsoNormal" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span>


















</span></p><p class="MsoNormal" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;">kernel
4.14.76<span></span></span></p>

<p class="MsoNormal" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;">nginx
1.14.0<span></span></span></p>

<p class="MsoNormal" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;">openssl
1.1.1<span></span></span></p>

<p class="MsoNormal" style="margin:0in;font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"><span style="font-size:10pt;font-family:&quot;Courier New&quot;">tpm2-abrmd
2.3.2<span></span></span></p>





</div><div><br></div><div>Note that the openssl when executed directly it is able to make use of TPM2.0 engine and we have other processes which makes use of tpm2tss and they are all working fine, the problem is only with Ngnix. We would need your help here, can you let us know how to resolve this &quot;<i>failed to allocate dbus proxy object</i>&quot; error?</div><div><br></div><div>Thanks</div><div>Raj<br>





</div></div>