Hi Chris,
that's great to hear. Thanks for all the testing!
In general I am interested in feedback (both bugs and improvement suggestions) from testing of real-life scenarios, so if you did test all you need and everything worked as you want it to work then I am happy and don't need anything else.
Thanks again,
Petr
______________________________________________________________
> Od: "Chris Newman" <chris@mode51.software>
> Komu: "Petr Gotthard" <petr.gotthard@centrum.cz>, tpm2@lists.01.org
> Datum: 06.10.2021 01:08
> Předmět: [tpm2] Re: CMP error: cannot duplicate context:2306 tpm:warn(2.0): out of memory for object contexts
>
Hi Petr,
I've tried abrmd and it works fine for the ir:
openssl cmp -config /opt/sdk/openssl/current/ssl/openssl.cnf -provider tpm2 -provider default -propquery ?provider=tpm2 -cmd ir -server https://demo.one.digicert.com/iot/api/v1/cmp/IOT_1234 -ref 1234 -secret pass:1234 -recipient "/CN=mode51.software" -key handle:0x81010002 -subject "/CN=TestTest" -cacertsout ./capubs.pem -certout ./cl_cert.pem -tls_used -verbosity 8
Also works with the cr:
/opt/sdk/openssl/current/bin/openssl cmp -config /opt/sdk/openssl/current/ssl/openssl.cnf -provider tpm2 -provider default -propquery ?provider=tpm2 -cmd cr -server https://demo.one.digicert.com/iot/api/v1/cmp/IOT_1234 -ref 1234 -key handle:0x81010002 -certout ./cl_cert2.pem -cert ./cl_cert.pem -tls_used -verbosity 8 -trusted ./capubs.pem -unprotected_errors
Is there anything you want me to test with the DigiCert CMPv2 responder?
Many thanks for the really great software.
Thanks Petr,
I'm using in-kernel. I'll try abrmd and report back.
On 04/10/2021 08:31, Petr Gotthard wrote:Hello,
this sounds like a known limitation of the openssl provider: https://github.com/tpm2-software/tpm2-openssl/issues/4
Some applications (like CMP) are too greedy and consume more resources than the TPM has. The resource managers (to my best knowledge) cannot swap resources from the same user.
Are you using the tpm2-abrmd resource manager, or the in-kernel manager? The tpm2-abrmd behaves much better.
Petr
______________________________________________________________
> Od: "Chris Newman" <chris@mode51.software>
> Komu: tpm2@lists.01.org
> Datum: 04.10.2021 01:41
> Předmět: [tpm2] CMP error: cannot duplicate context:2306 tpm:warn(2.0): out of memory for object contexts
>Hi,
I create an EK and AK using tpm2_createek, tpm2_createak and tpm2_evictcontrol to persist the AK in 0x81010002. The I use the following command with DigiCert's CMPv2 server:
openssl cmp -config /opt/sdk/openssl/current/ssl/openssl.cnf -provider tpm2 -provider default -propquery ?provider=tpm2,tpm2.digest!=yes -cmd ir -server https://demo.one.digicert.com/iot/api/v1/cmp/IOT_1234 -ref 1234 -secret pass:1234 -recipient "/CN=mode51.software" -key handle:0x81010002 -subject "/CN=TestTest" -cacertsout ./capubs.pem -certout ./cl_cert.pem -tls_used -verbosity 8
I get the following error:
DIGEST NEW
DIGEST INIT
DIGEST UPDATE
DIGEST DUP
DIGEST FINAL
DIGEST FREE
DIGEST NEW
DIGEST INIT
DIGEST UPDATE
DIGEST NEW
DIGEST INIT
DIGEST UPDATE
DIGEST DUP
WARNING:esys:src/tss2-esys/api/Esys_ContextLoad.c:279:Esys_ContextLoad_Finish() Received TPM Error
ERROR:esys:src/tss2-esys/api/Esys_ContextLoad.c:93:Esys_ContextLoad() Esys Finish ErrorCode (0x00000902)
DIGEST FREE
DIGEST FREE
DIGEST FREE
CMP DEBUG: disconnected from CMP server
CMP error: cannot duplicate context:2306 tpm:warn(2.0): out of memory for object contexts
CMP error: not able to copy ctx
CMP error: internal error
CMP error: error sending
CMP error: shutdown while in init
CMP error: transfer error:request sent: IR, expected response: IP
RSA FREE
RAND FREE
RAND FREE
RAND FREE
PROVIDER TEARDOWN
I've tried tpm2_flushcontext -t.
I recompiled tpm2-openssl with the following option and that appears to have worked around the issue:
--disable-op-digest
Is this what "?provider=tpm2,tpm2.digest!=yes" should effectively do?