* Re: [BUILD] Unable to sign drivers on Ubuntu 22.04 LTS desktop
[not found] <bb89a720-b1b2-18fc-7f89-44267885700d@alu.unizg.hr>
@ 2023-05-05 13:46 ` Bagas Sanjaya
2023-05-05 20:07 ` Mirsad Goran Todorovac
0 siblings, 1 reply; 2+ messages in thread
From: Bagas Sanjaya @ 2023-05-05 13:46 UTC (permalink / raw)
To: Mirsad Goran Todorovac
Cc: Linux Kernel Mailing List, Peter Zijlstra, Ingo Molnar,
Arnaldo Carvalho de Melo, Mark Rutland, Alexander Shishkin,
Jiri Olsa, Namhyung Kim, Ian Rogers, Adrian Hunter,
Thomas Gleixner, Borislav Petkov, Dave Hansen,
Linux x86 Architecture, H. Peter Anvin, Linux perf users,
Linux Kernel Build System, Masahiro Yamada
[-- Attachment #1: Type: text/plain, Size: 974 bytes --]
On Thu, May 04, 2023 at 07:02:57PM +0200, Mirsad Goran Todorovac wrote:
> Hi Bagas,
>
> I seem to have run into a dead end with this.
>
> OpenSSL 3.0.2 refuses to cooperate, despite enabling legacy ciphers:
>
> BTF [M] net/nsh/nsh.ko
> BTF [M] net/hsr/hsr.ko
> make -f ./Makefile ARCH=x86 KERNELRELEASE=6.3.0+ intdeb-pkg
> sh ./scripts/package/builddeb
> INSTALL debian/linux-image/lib/modules/6.3.0+/kernel/arch/x86/events/intel/intel-cstate.ko
> SIGN debian/linux-image/lib/modules/6.3.0+/kernel/arch/x86/events/intel/intel-cstate.ko
> At main.c:170:
> - SSL error:1E08010C:DECODER routines::unsupported:
> ../crypto/encode_decode/decoder_lib.c:101
I didn't find any errors using self-compiled OpenSSL 3.1.0. I installed the
library to `/tmp/openssl` and specify
`KCFLAGS=-L/tmp/openssl/lib -I/tmp/openssl/include` when building bindeb-pkgs.
Am I missing something?
--
An old man doll... just what I always wanted! - Clara
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [BUILD] Unable to sign drivers on Ubuntu 22.04 LTS desktop
2023-05-05 13:46 ` [BUILD] Unable to sign drivers on Ubuntu 22.04 LTS desktop Bagas Sanjaya
@ 2023-05-05 20:07 ` Mirsad Goran Todorovac
0 siblings, 0 replies; 2+ messages in thread
From: Mirsad Goran Todorovac @ 2023-05-05 20:07 UTC (permalink / raw)
To: Bagas Sanjaya, Mirsad Goran Todorovac
Cc: Linux Kernel Mailing List, Peter Zijlstra, Ingo Molnar,
Arnaldo Carvalho de Melo, Mark Rutland, Alexander Shishkin,
Jiri Olsa, Namhyung Kim, Ian Rogers, Adrian Hunter,
Thomas Gleixner, Borislav Petkov, Dave Hansen,
Linux x86 Architecture, H. Peter Anvin, Linux perf users,
Linux Kernel Build System, Masahiro Yamada
On 05. 05. 2023. 15:46, Bagas Sanjaya wrote:
> On Thu, May 04, 2023 at 07:02:57PM +0200, Mirsad Goran Todorovac wrote:
>> Hi Bagas,
>>
>> I seem to have run into a dead end with this.
>>
>> OpenSSL 3.0.2 refuses to cooperate, despite enabling legacy ciphers:
>>
>> BTF [M] net/nsh/nsh.ko
>> BTF [M] net/hsr/hsr.ko
>> make -f ./Makefile ARCH=x86 KERNELRELEASE=6.3.0+ intdeb-pkg
>> sh ./scripts/package/builddeb
>> INSTALL debian/linux-image/lib/modules/6.3.0+/kernel/arch/x86/events/intel/intel-cstate.ko
>> SIGN debian/linux-image/lib/modules/6.3.0+/kernel/arch/x86/events/intel/intel-cstate.ko
>> At main.c:170:
>> - SSL error:1E08010C:DECODER routines::unsupported:
>> ../crypto/encode_decode/decoder_lib.c:101
> I didn't find any errors using self-compiled OpenSSL 3.1.0. I installed the
> library to `/tmp/openssl` and specify
> `KCFLAGS=-L/tmp/openssl/lib -I/tmp/openssl/include` when building bindeb-pkgs.
> Am I missing something?
Dear Mr. Bagas,
I have mistakenly deleted the
CONFIG_MODULE_SIG_KEY="certs/signing_key.pem"
to
CONFIG_MODULE_SIG_KEY=""
so I got these strange errors, which made me believe that OpenSSL 3.0.1
disabled some encryptions and hashes.
I suspected it was the problem with the FIPS mode not installed in the
stock Ubuntu 22.04 LTS library, but I have to admit before so many
people that it was this stupid mistake which I found out by looking up
Debian config.
IOW, false alarm.
Ubuntu config with FIPS mode OpenSSL 3.1.0 works, however, I have
rebuilt with the default OpenSSL 3.0.1 and the error was bisected to the
missing .PEM.
Best regards,
Mirsad
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2023-05-05 20:07 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <bb89a720-b1b2-18fc-7f89-44267885700d@alu.unizg.hr>
2023-05-05 13:46 ` [BUILD] Unable to sign drivers on Ubuntu 22.04 LTS desktop Bagas Sanjaya
2023-05-05 20:07 ` Mirsad Goran Todorovac
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).