Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fedora project will be dropping openssl engine support #126

Open
traxtopel opened this issue Sep 28, 2024 · 4 comments
Open

Fedora project will be dropping openssl engine support #126

traxtopel opened this issue Sep 28, 2024 · 4 comments
Labels
question Further information is requested

Comments

@traxtopel
Copy link

traxtopel commented Sep 28, 2024

You are probably aware that the Fedora project will be dropping engine support in OpenSSL and wpa_supplicant. This will of course impact tpm2-pkcs11.
Are there any plans to add support for the tpm2-openssl provider to wpa_supplicant?

https://fedoraproject.org/wiki/Changes/OpensslDeprecateEngine

@gotthardp
Copy link
Contributor

Not in this project. You should ask the wpa_supplicant folks.

@gotthardp gotthardp added the question Further information is requested label Oct 6, 2024
@tomoveu
Copy link

tomoveu commented Dec 2, 2024

@traxtopel I would be happy to take a look because I am trying to gather more tpm2-openssl experience. My work involves using the TPM2 directly through the TPM software stack, however this has started to change and now I am forced to user openssl like it or not.

My timeline for looking at tpm2-pkcs would be beginning of next year. The fedora announcement does not say when is this change into effect. Is it immediate?

Thanks,
Dimi

@traxtopel
Copy link
Author

I've been informed by the developer [email protected] that the OpenSSL maintainers have confirmed the engine API will be deprecated in a few months, which affects both TPM2 and PKCS11 implementations. Red Hat is shifting towards the pkcs11-provider as an alternative solution. However, I've encountered difficulties using this provider, even when using a patched wpa_supplicant (https://github.com/dcaratti/hostap-ctest/tree/pkcs11-use-provider-in-place-of-engine). In light of this, it would be beneficial patching wpa_supplicant to support the TPM2-openssl provider. Let me know if I can assist in testing.

@tomoveu
Copy link

tomoveu commented Dec 2, 2024

@traxtopel please send me an email at [email protected] to stay in touch. I will look into tpm2-provider support for wpa-supplicant for sure. Thank you for the good information.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

3 participants