<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ERR_SSL_PROTOCOL_ERROR using nginx with SE05x in Secure Authentication</title>
    <link>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1749637#M1419</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/221468"&gt;@CristianeBP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your issue has been reported to our NXP Internal Blob.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will let you know when it will be processed.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Rodolfo&lt;/P&gt;</description>
    <pubDate>Tue, 31 Oct 2023 15:35:37 GMT</pubDate>
    <dc:creator>rodolfoveltrigo</dc:creator>
    <dc:date>2023-10-31T15:35:37Z</dc:date>
    <item>
      <title>ERR_SSL_PROTOCOL_ERROR using nginx with SE05x</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1749624#M1418</link>
      <description>&lt;P&gt;Good night,&lt;/P&gt;&lt;P&gt;we are facing the following problem:&lt;/P&gt;&lt;P&gt;when the secure element is accessed using the terminal, the web communication no longer works. The same problem can see verified performing multiple web accesses.&lt;/P&gt;&lt;P&gt;In the log I can see this messages:&lt;/P&gt;&lt;P&gt;2023-10-31 14:19:14 nginx: 2023/10/31 14:19:14 [crit] 525#525: *41 SSL_do_handshake() failed (SSL: error:14209044:SSL routines:tls_early_post_process_client_hello:internal error) while SSL handshaking, client: 192.168.1.5, server: 0.0.0.0:443&lt;/P&gt;&lt;P&gt;and in the browser I can see the message: "&lt;SPAN&gt;ERR_SSL_PROTOCOL_ERROR" (image.png in attached).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When I restart nginx, everything works again.&lt;/P&gt;&lt;P&gt;How to reproduce the problem:&lt;/P&gt;&lt;P&gt;1 - start nginx;&lt;/P&gt;&lt;P&gt;2 - open the browser and check that the communication works;&lt;/P&gt;&lt;P&gt;3 - in the terminal execute an openssl command or application that accesses the SE;&lt;/P&gt;&lt;P&gt;4 - refresh the browser (with clean cookies);&lt;/P&gt;&lt;P&gt;(in this point the comunication with the browser do not work anymore)&lt;/P&gt;&lt;P&gt;5 - restart nginx;&lt;/P&gt;&lt;P&gt;6 -&amp;nbsp;refresh the browser (with clean cookies);&lt;/P&gt;&lt;P&gt;(in this point the communication restart to work).&lt;/P&gt;&lt;P&gt;In attached our yocto recipe used to build SE, openssl and nginx configuration (renamed to .txt, becouse the real extention are not supported by the forum).&lt;/P&gt;&lt;P&gt;[root@ABB-da-51-60-aa-06-e3 bin]# nginx -version&lt;BR /&gt;nginx version: nginx/1.22.0&lt;/P&gt;&lt;P&gt;[root@ABB-da-51-60-aa-06-e3 bin]# openssl version&lt;BR /&gt;OpenSSL 1.1.1l 24 Aug 2021&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Cristiane Bellenzier Piaia&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 15:08:05 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1749624#M1418</guid>
      <dc:creator>CristianeBP</dc:creator>
      <dc:date>2023-10-31T15:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: ERR_SSL_PROTOCOL_ERROR using nginx with SE05x</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1749637#M1419</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/221468"&gt;@CristianeBP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your issue has been reported to our NXP Internal Blob.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will let you know when it will be processed.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Rodolfo&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 15:35:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1749637#M1419</guid>
      <dc:creator>rodolfoveltrigo</dc:creator>
      <dc:date>2023-10-31T15:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: ERR_SSL_PROTOCOL_ERROR using nginx with SE05x</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1751765#M1420</link>
      <description>&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/221468"&gt;@CristianeBP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reply from NXP CAS2:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Please check whether ABB is using the Access Manager.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Only the&amp;nbsp;Access&amp;nbsp;Manager&amp;nbsp;supports concurrent&amp;nbsp;access&amp;nbsp;from multiple linux processes to an SE05x IoT applet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Please see MW docu&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;5.4.3.&amp;nbsp;Access&amp;nbsp;Manager: Manage access from multiple (Linux) processes to an SE05x IoT Applet (see attachment).&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&amp;nbsp;Another question:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Is nginx using the SE05x via OpenSSL?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Rodolfo&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 08:18:37 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1751765#M1420</guid>
      <dc:creator>rodolfoveltrigo</dc:creator>
      <dc:date>2023-11-03T08:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: ERR_SSL_PROTOCOL_ERROR using nginx with SE05x</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1752822#M1427</link>
      <description>&lt;P&gt;Good morning Rodolfo,&lt;/P&gt;&lt;P&gt;thank you very much, you are right, this is the problem, sorry for that, with the access manager, everything works fine.&lt;/P&gt;&lt;P&gt;But without the SCP/auth enabled.&lt;/P&gt;&lt;P&gt;I did 3 tests:&lt;/P&gt;&lt;P&gt;1 - access manager and applications with&amp;nbsp;SCP/auth: NOK.&lt;/P&gt;&lt;P&gt;But if I understood correctly, this is not needed because the access manager will be handle with the authentication/SCP.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="458af8ab-cfe5-45dd-8e8c-dd4b9845800c.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/248619iA3DB6F8C2A364560/image-size/medium?v=v2&amp;amp;px=400" role="button" title="458af8ab-cfe5-45dd-8e8c-dd4b9845800c.png" alt="458af8ab-cfe5-45dd-8e8c-dd4b9845800c.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 612px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/248620iDC5DC45947AC5CAF/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7aa06177-5cee-43f1-a7a1-b66d38d9e379.png" style="width: 400px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/248624iA33D51543E824DF5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="7aa06177-5cee-43f1-a7a1-b66d38d9e379.png" alt="7aa06177-5cee-43f1-a7a1-b66d38d9e379.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 617px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/248622i006B19274AEC0BF7/image-dimensions/617x540?v=v2" width="617" height="540" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;2 - access manager with&amp;nbsp;SCP/auth and applications auth=none: NOK.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/248625iDA3D78420E5A81AC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 836px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/248633i604AA49AA2711C51/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3 -&amp;nbsp;access manager with&amp;nbsp;SCP/auth, but started without scp enabled and applications auth=none: OK.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 727px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/248630iC0CCAC6EA9505241/image-dimensions/727x380?v=v2" width="727" height="380" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How can I enabled the SCP/Auth properly?&lt;/P&gt;&lt;P&gt;Another problem is that&amp;nbsp;the getInfo application does not work properly (even&amp;nbsp;if it build accessManager whithout auth/SCP).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 678px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/248637iB19ABF894A31B2FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 12:01:40 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1752822#M1427</guid>
      <dc:creator>CristianeBP</dc:creator>
      <dc:date>2023-11-06T12:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: ERR_SSL_PROTOCOL_ERROR using nginx with SE05x</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1755667#M1434</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/221468"&gt;@CristianeBP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Cristiane,&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;attached a plain and SCP03 communication screen shot as well text files containing the I2C bytes in text from (captured with the help of a logic analyzer). It shows that the communication between the SE and the host is encrypted in case of using Platform SCP for the access manager.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;In case ABB would like also to protect the communication to the access manger they would need to use an authenticated session.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;In this case only two sessions are supported by the Secure Element! This may not be sufficient for ABB's use case.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&amp;nbsp;cheers&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Rodolfo on behalf of CAS2 team in Austria&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 14:54:09 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/ERR-SSL-PROTOCOL-ERROR-using-nginx-with-SE05x/m-p/1755667#M1434</guid>
      <dc:creator>rodolfoveltrigo</dc:creator>
      <dc:date>2023-11-10T14:54:09Z</dc:date>
    </item>
  </channel>
</rss>

