-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
GCP HSM SSL Key not working for the web servers for ubuntu OS. #38
Comments
Some initial thoughts:
I guess as a starting point, a couple questions:
We'll also try to reproduce on our end |
Hi tdbhacks , Please find the response The current version of PKCS 11 library I am using is libkmsp11-1.0-linux-amd64 and i have tried using libkmsp11-1.6-linux-amd64 Current openssl version is OpenSSL 3.0.13 30 Jan 2024 (Library: OpenSSL 3.0.13 30 Jan 2024) |
Thank you for providing this information. We tried to reproduce the error on our end but, unfortunately, we were unsuccessful so far. To further investigate the issue, can you please provide:
|
Hi Iontzialla,
0: C_GetInterface 1: C_Initialize 2: C_GetSlotList 3: C_GetSlotList 4: C_GetSlotInfo 5: C_OpenSession 6: C_FindObjectsInit 7: C_FindObjects 8: C_GetAttributeValue 9: C_GetAttributeValue 10: C_GetAttributeValue 11: C_GetAttributeValue 12: C_GetAttributeValue 13: C_GetAttributeValue 14: C_GetAttributeValue 15: C_GetAttributeValue 16: C_GetAttributeValue 17: C_GetAttributeValue 18: C_GetAttributeValue 19: C_GetAttributeValue 20: C_GetAttributeValue 21: C_GetAttributeValue 22: C_GetAttributeValue 23: C_GetAttributeValue 24: C_FindObjects 25: C_GetAttributeValue 26: C_GetAttributeValue 27: C_GetAttributeValue 28: C_GetAttributeValue 29: C_GetAttributeValue 30: C_GetAttributeValue 31: C_GetAttributeValue 32: C_GetAttributeValue 33: C_GetAttributeValue 34: C_GetAttributeValue 35: C_GetAttributeValue 36: C_GetAttributeValue 37: C_GetAttributeValue 38: C_GetAttributeValue 39: C_GetAttributeValue 40: C_GetAttributeValue 41: C_GetAttributeValue 42: C_GetAttributeValue 43: C_GetAttributeValue 44: C_GetAttributeValue 45: C_FindObjects 46: C_GetAttributeValue 47: C_GetAttributeValue 48: C_GetAttributeValue 49: C_GetAttributeValue 50: C_GetAttributeValue 51: C_GetAttributeValue 52: C_GetAttributeValue 53: C_GetAttributeValue 54: C_GetAttributeValue 55: C_GetAttributeValue 56: C_GetAttributeValue 57: C_GetAttributeValue 58: C_GetAttributeValue 59: C_GetAttributeValue 60: C_GetAttributeValue 61: C_GetAttributeValue 62: C_FindObjects 63: C_GetAttributeValue 64: C_GetAttributeValue 65: C_GetAttributeValue 66: C_GetAttributeValue 67: C_GetAttributeValue 68: C_GetAttributeValue 69: C_GetAttributeValue 70: C_GetAttributeValue 71: C_GetAttributeValue 72: C_GetAttributeValue 73: C_GetAttributeValue 74: C_GetAttributeValue 75: C_GetAttributeValue 76: C_GetAttributeValue 77: C_GetAttributeValue 78: C_GetAttributeValue 79: C_GetAttributeValue 80: C_GetAttributeValue 81: C_GetAttributeValue 82: C_GetAttributeValue 83: C_FindObjects 84: C_FindObjectsFinal 85: C_CloseSession 86: C_Finalize *************** OpenSC PKCS#11 spy ***************** 0: C_GetInterface 1: C_Initialize 2: C_GetSlotList 3: C_GetSlotList 4: C_GetSlotInfo *************** OpenSC PKCS#11 spy ***************** 0: C_GetInterface 1: C_Initialize 2: C_GetSlotList 3: C_GetSlotList 4: C_GetSlotInfo 5: C_OpenSession 6: C_FindObjectsInit 7: C_FindObjects 8: C_GetAttributeValue 9: C_GetAttributeValue 10: C_GetAttributeValue 11: C_GetAttributeValue 12: C_GetAttributeValue 13: C_GetAttributeValue 14: C_GetAttributeValue 15: C_GetAttributeValue 16: C_GetAttributeValue 17: C_GetAttributeValue 18: C_GetAttributeValue 19: C_GetAttributeValue 20: C_GetAttributeValue 21: C_GetAttributeValue 22: C_GetAttributeValue 23: C_GetAttributeValue 24: C_FindObjects 25: C_GetAttributeValue 26: C_GetAttributeValue 27: C_GetAttributeValue 28: C_GetAttributeValue 29: C_GetAttributeValue 30: C_GetAttributeValue 31: C_GetAttributeValue 32: C_GetAttributeValue 33: C_GetAttributeValue 34: C_GetAttributeValue 35: C_GetAttributeValue 36: C_GetAttributeValue 37: C_GetAttributeValue 38: C_GetAttributeValue 39: C_GetAttributeValue 40: C_GetAttributeValue 41: C_GetAttributeValue 42: C_GetAttributeValue 43: C_GetAttributeValue 44: C_GetAttributeValue 45: C_FindObjects 46: C_FindObjectsFinal 47: C_CloseSession 48: C_Finalize *************** OpenSC PKCS#11 spy ***************** 0: C_GetInterface 1: C_Initialize 2: C_GetSlotList 3: C_GetSlotList 4: C_GetSlotInfo 5: C_GetTokenInfo 6: C_Finalize *************** OpenSC PKCS#11 spy ***************** 0: C_GetInterface 1: C_Initialize 2: C_GetSlotList 3: C_GetSlotList 4: C_GetSlotInfo 5: C_OpenSession 6: C_FindObjectsInit 7: C_FindObjects 8: C_GetAttributeValue 9: C_GetAttributeValue 10: C_GetAttributeValue 11: C_GetAttributeValue 12: C_GetAttributeValue 13: C_GetAttributeValue 14: C_GetAttributeValue 15: C_GetAttributeValue 16: C_GetAttributeValue 17: C_GetAttributeValue 18: C_GetAttributeValue 19: C_GetAttributeValue 20: C_GetAttributeValue 21: C_GetAttributeValue 22: C_GetAttributeValue 23: C_GetAttributeValue 24: C_FindObjects 25: C_GetAttributeValue 26: C_GetAttributeValue 27: C_GetAttributeValue 28: C_GetAttributeValue 29: C_GetAttributeValue 30: C_GetAttributeValue 31: C_GetAttributeValue 32: C_GetAttributeValue 33: C_GetAttributeValue 34: C_GetAttributeValue 35: C_GetAttributeValue 36: C_GetAttributeValue 37: C_GetAttributeValue 38: C_GetAttributeValue 39: C_GetAttributeValue 40: C_GetAttributeValue 41: C_GetAttributeValue 42: C_GetAttributeValue 43: C_GetAttributeValue 44: C_GetAttributeValue 45: C_FindObjects 46: C_FindObjectsFinal 47: C_CloseSession 48: C_Finalize *************** OpenSC PKCS#11 spy ***************** 0: C_GetInterface 1: C_Initialize 2: C_GetSlotList 3: C_GetSlotList 4: C_GetSlotInfo 5: C_OpenSession 6: C_FindObjectsInit 7: C_FindObjects 8: C_GetAttributeValue 9: C_GetAttributeValue 10: C_GetAttributeValue 11: C_GetAttributeValue 12: C_GetAttributeValue 13: C_GetAttributeValue 14: C_GetAttributeValue 15: C_GetAttributeValue 16: C_GetAttributeValue 17: C_GetAttributeValue 18: C_GetAttributeValue 19: C_GetAttributeValue 20: C_GetAttributeValue 21: C_GetAttributeValue 22: C_GetAttributeValue 23: C_GetAttributeValue 24: C_FindObjects 25: C_GetAttributeValue 26: C_GetAttributeValue 27: C_GetAttributeValue 28: C_GetAttributeValue 29: C_GetAttributeValue 30: C_GetAttributeValue 31: C_GetAttributeValue 32: C_GetAttributeValue 33: C_GetAttributeValue 34: C_GetAttributeValue 35: C_GetAttributeValue 36: C_GetAttributeValue 37: C_GetAttributeValue 38: C_GetAttributeValue 39: C_GetAttributeValue 40: C_GetAttributeValue 41: C_GetAttributeValue 42: C_GetAttributeValue 43: C_GetAttributeValue 44: C_GetAttributeValue 45: C_FindObjects 46: C_FindObjectsFinal 47: C_CloseSession 48: C_Finalize *************** OpenSC PKCS#11 spy ***************** 0: C_GetInterface 1: C_Initialize 2: C_GetSlotList 3: C_GetSlotList 4: C_GetSlotInfo 5: C_GetTokenInfo 6: C_Finalize *************** OpenSC PKCS#11 spy ***************** 0: C_GetFunctionList 1: C_Initialize 2: C_GetInfo 3: C_GetSlotList 4: C_GetSlotList 5: C_GetSlotInfo 6: C_GetTokenInfo 7: C_OpenSession 8: C_FindObjectsInit 9: C_FindObjects 10: C_GetAttributeValue 11: C_GetAttributeValue 12: C_GetAttributeValue 13: C_GetAttributeValue 14: C_GetAttributeValue 15: C_GetAttributeValue 16: C_FindObjects 17: C_FindObjectsFinal 18: C_GetAttributeValue 19: C_GetAttributeValue 20: C_GetAttributeValue 21: C_GetAttributeValue *************** OpenSC PKCS#11 spy ***************** 0: C_GetFunctionList 1: C_Initialize 2: C_GetInfo 3: C_GetSlotList 4: C_GetSlotList 5: C_GetSlotInfo 6: C_GetTokenInfo 7: C_OpenSession 8: C_FindObjectsInit 9: C_FindObjects 10: C_GetAttributeValue 11: C_GetAttributeValue 12: C_GetAttributeValue 13: C_GetAttributeValue 14: C_GetAttributeValue 15: C_GetAttributeValue 16: C_FindObjects 17: C_FindObjectsFinal 18: C_GetAttributeValue 19: C_GetAttributeValue 20: C_GetAttributeValue 21: C_GetAttributeValue *************** OpenSC PKCS#11 spy ***************** 0: C_GetFunctionList 1: C_Initialize 2: C_GetInfo 3: C_GetSlotList 4: C_GetSlotList 5: C_GetSlotInfo 6: C_GetTokenInfo 7: C_OpenSession 8: C_FindObjectsInit 9: C_FindObjects 10: C_GetAttributeValue 11: C_GetAttributeValue 12: C_GetAttributeValue 13: C_GetAttributeValue 14: C_GetAttributeValue 15: C_GetAttributeValue 16: C_FindObjects 17: C_FindObjectsFinal 18: C_GetAttributeValue 19: C_GetAttributeValue 20: C_GetAttributeValue 21: C_GetAttributeValue
tokens:
|
Hmm, it's a bit surprising that the pkcs11-spy logs don't include any Given the mix of key versions with multiple states, have you tried using NOTE: this will sadly only work if the resource name is less than 100 characters (#35) |
we have renewed the SSL Key on Sep 15th 10.00 PM. After that the new key is working fine for 2 days without any issues. Yesterday suddenly our web servers stopped working due to an ssl key serving issue from HSM.
We have tried pointing the HSM key in testing web server. We got the below errors
Kindly help ASAP , our business is impacted.
The text was updated successfully, but these errors were encountered: