# PKCS11 not working on mender client with TPM

**URL:** <https://hub.mender.io/t/pkcs11-not-working-on-mender-client-with-tpm/4541>\
**Category:** General Discussions\
**Created:** [January 26, 2022, 5:25pm UTC](https://hub.mender.io/t/pkcs11-not-working-on-mender-client-with-tpm/4541 "2022-01-26T17:25:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sandevins](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/sandevins/32/1439_2.png) [@sandevins](https://hub.mender.io/u/sandevins)\
**Post date:** [January 26, 2022, 5:25pm UTC](https://hub.mender.io/t/pkcs11-not-working-on-mender-client-with-tpm/4541/1 "2022-01-26T17:25:11Z")

</div>

I tried to configure a client to use a private key stored inside a TPM. In order to get the URI of the private key, I used p11tool. The result is the following.

```auto
root@nano-iot:~/tpm2_ptool/tpm2-pkcs11/tools# p11tool --provider='/usr/local/lib/libtpm2_pkcs11.so' --list-all "$token" --login
Token 'my first token' with URL 'pkcs11:model=Intel%00%00%00%00%00%00%00%00%00%00%00;manufacturer=Intel;serial=0000000000000000;token=my%20first%20token' requires user PIN
Enter PIN: 
WARNING: Needed CKA_VALUE but didn't find encrypted blob
Object 0:
	URL: pkcs11:model=Intel%00%00%00%00%00%00%00%00%00%00%00;manufacturer=Intel;serial=0000000000000000;token=my%20first%20token;id=%22%24;object=myrsakey;type=public
	Type: Public key (RSA-2048)
	Label: myrsakey
	Flags: CKA_NEVER_EXTRACTABLE; 
	ID: 22:24

Object 1:
	URL: pkcs11:model=Intel%00%00%00%00%00%00%00%00%00%00%00;manufacturer=Intel;serial=0000000000000000;token=my%20first%20token;id=%22%24;object=myrsakey;type=private
	Type: Private key (RSA-2048)
	Label: myrsakey
	Flags: CKA_PRIVATE; CKA_NEVER_EXTRACTABLE; CKA_SENSITIVE; 
	ID: 22:24

```

With this URL I edit the mender.conf file located in /etc/mender the following way.

```auto
{
  "ServerURL": "https://my_server.org",
  "ServerCertificate": "/etc/mender/server.crt",
  "HttpsClient": {
        "Certificate": "/etc/mender/Nano.pem",
        "Key": "pkcs11:model=Intel%00%00%00%00%00%00%00%00%00%00%00;manufacturer=Intel;serial=0000000000000000;token=my%20first%20token;id=%22%24;object=myrsakey;type=private;pin-value=myuserpin",
        "SSLEngine": "pkcs11"
    }
}

```

Then I restart the mender client using service mender-client restart and the client doesn’t connect. In the journalctl the following can be seen.

```auto
ene 26 18:20:09 nano-iot mender[5176]: PKCS11_get_private_key returned NULL
ene 26 18:20:09 nano-iot mender[5176]: Failed to enumerate slots
ene 26 18:20:09 nano-iot mender[5176]: Failed to enumerate slots

```

I then try with the following mender.conf.

```auto
{
  "ServerURL": "https://my_server.org",
  "ServerCertificate": "/etc/mender/server.crt",
  "HttpsClient": {
        "Certificate": "/etc/mender/Nano.pem",
        "Key": "pkcs11:module-path=/usr/local/lib/libtpm2_pkcs11.so;model=Intel%00%00%00%00%00%00%00%00%00%00%00;manufacturer=Intel;serial=0000000000000000;slot-id=0;token=my%20first%20token;id=%22%24;object=myrsakey;type=private;pin-value=myuserpin",
        "SSLEngine": "pkcs11"
    }
}

```

And I get exactly the same result.

Is there anything that I’m missing?

Best,

---

<div class="post-metadata">

**Author:** ![sandevins](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/sandevins/32/1439_2.png) [@sandevins](https://hub.mender.io/u/sandevins)\
**Post date:** [February 3, 2022, 4:07pm UTC](https://hub.mender.io/t/pkcs11-not-working-on-mender-client-with-tpm/4541/2 "2022-02-03T16:07:52Z")

</div>

I found something interesting on this. After a lot of investigation, I’ve seen that the issue should be on how the daemon is launched by systemd. If I launch the mender client manually the error does not appear.

Do you have any insight on this or how to solve it?

Best,

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [November 27, 2023, 1:50pm UTC](https://hub.mender.io/t/pkcs11-not-working-on-mender-client-with-tpm/4541/3 "2023-11-27T13:50:52Z")

</div>

Hi @sandevins were you able to resolve this?

---

<div class="post-metadata">

**Author:** ![sandevins](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/sandevins/32/1439_2.png) [@sandevins](https://hub.mender.io/u/sandevins)\
**Post date:** [November 27, 2023, 3:29pm UTC](https://hub.mender.io/t/pkcs11-not-working-on-mender-client-with-tpm/4541/4 "2023-11-27T15:29:38Z")

</div>

Hi @oleorhagen,

Yes, the problem is related to the environment variable OPENSSL\_CONF when the process is launched by systemd.

You have to add a line in the `/usr/lib/systemd/system/mender-client.service` file under the [Service] section with the following content.

```auto
Environment="OPENSSL_CONF=<PATH_TO_OPENSSL_CONF"

```

I hope this helps.

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [November 28, 2023, 11:38am UTC](https://hub.mender.io/t/pkcs11-not-working-on-mender-client-with-tpm/4541/5 "2023-11-28T11:38:07Z")

</div>

Yes, systemd’s evnironment is clean by default 😸

I’m glad you were able to resolve it.

I’m I’m still curious. Which version of OpenSSL are you using. And which pkcs11 provider?

---

<div class="post-metadata">

**Author:** ![sandevins](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/sandevins/32/1439_2.png) [@sandevins](https://hub.mender.io/u/sandevins)\
**Post date:** [November 28, 2023, 2:25pm UTC](https://hub.mender.io/t/pkcs11-not-working-on-mender-client-with-tpm/4541/6 "2023-11-28T14:25:29Z")

</div>

I’m pretty sure the OPENSSL version is 1.1.1k. The PKCS#11 provider we used was KeyConnect by Gradiant to provide some cryptoagility to the architecture.
