<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic pkcs11-tool generates 2 private keys for keypairgen in Secure Authentication</title>
    <link>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1855553#M1597</link>
    <description>&lt;P&gt;I'm expecting to have a public and a private key pair when I execute pkcs11-tool command with --keypairgen option, but the outputs says generated 2 private keys.&lt;/P&gt;&lt;P&gt;Is that an expected behavior of se050? If not, am I missing something important?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Environment&amp;gt;&lt;/P&gt;&lt;P&gt;platform: Debian (bullseye)&lt;/P&gt;&lt;P&gt;module variant: SE050C1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Outputs&amp;gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# pkcs11-tool --module $PKCS11_MODULE --keypairgen --key-type rsa:2048 --label "sss:20202020"
Using slot 0 with a present token (0x1)
smCom :WARN :Invalid conn_ctx
App   :INFO :Using PortName='/dev/i2c-1:0x48' (ENV: EX_SSS_BOOT_SSS_PORT=/dev/i2c-1:0x48)
sss   :INFO :atr (Len=35)
      00 A0 00 00    03 96 04 03    E8 00 FE 02    0B 03 E8 08 
      01 00 00 00    00 64 00 00    0A 4A 43 4F    50 34 20 41 
      54 50 4F 
sss   :WARN :Communication channel is Plain.
sss   :WARN :!!!Not recommended for production use.!!!
Key pair generated:
Private Key Object; RSA 
  label:      sss:20202020
  ID:         20202020
  Usage:      decrypt, sign
  Access:     sensitive, always sensitive
  Allowed mechanisms: RSA-PKCS,SHA1-RSA-PKCS,SHA224-RSA-PKCS,SHA256-RSA-PKCS,SHA384-RSA-PKCS,SHA512-RSA-PKCS,RSA-PKCS-PSS,SHA1-RSA-PKCS-PSS,SHA224-RSA-PKCS-PSS,SHA256-RSA-PKCS-PSS,SHA384-RSA-PKCS-PSS,SHA512-RSA-PKCS-PSS,RSA-PP
Private Key Object; RSA 
  label:      sss:20202020
  ID:         20202020
  Usage:      decrypt, sign
  Access:     sensitive, always sensitive
  Allowed mechanisms: RSA-PKCS,SHA1-RSA-PKCS,SHA224-RSA-PKCS,SHA256-RSA-PKCS,SHA384-RSA-PKCS,SHA512-RSA-PKCS,RSA-PKCS-PSS,SHA1-RSA-PKCS-PSS,SHA224-RSA-PKCS-PSS,SHA256-RSA-PKCS-PSS,SHA384-RSA-PKCS-PSS,SHA512-RSA-PKCS-PSS,RSA-PP&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Apr 2024 09:39:46 GMT</pubDate>
    <dc:creator>user4</dc:creator>
    <dc:date>2024-04-26T09:39:46Z</dc:date>
    <item>
      <title>pkcs11-tool generates 2 private keys for keypairgen</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1855553#M1597</link>
      <description>&lt;P&gt;I'm expecting to have a public and a private key pair when I execute pkcs11-tool command with --keypairgen option, but the outputs says generated 2 private keys.&lt;/P&gt;&lt;P&gt;Is that an expected behavior of se050? If not, am I missing something important?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Environment&amp;gt;&lt;/P&gt;&lt;P&gt;platform: Debian (bullseye)&lt;/P&gt;&lt;P&gt;module variant: SE050C1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Outputs&amp;gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# pkcs11-tool --module $PKCS11_MODULE --keypairgen --key-type rsa:2048 --label "sss:20202020"
Using slot 0 with a present token (0x1)
smCom :WARN :Invalid conn_ctx
App   :INFO :Using PortName='/dev/i2c-1:0x48' (ENV: EX_SSS_BOOT_SSS_PORT=/dev/i2c-1:0x48)
sss   :INFO :atr (Len=35)
      00 A0 00 00    03 96 04 03    E8 00 FE 02    0B 03 E8 08 
      01 00 00 00    00 64 00 00    0A 4A 43 4F    50 34 20 41 
      54 50 4F 
sss   :WARN :Communication channel is Plain.
sss   :WARN :!!!Not recommended for production use.!!!
Key pair generated:
Private Key Object; RSA 
  label:      sss:20202020
  ID:         20202020
  Usage:      decrypt, sign
  Access:     sensitive, always sensitive
  Allowed mechanisms: RSA-PKCS,SHA1-RSA-PKCS,SHA224-RSA-PKCS,SHA256-RSA-PKCS,SHA384-RSA-PKCS,SHA512-RSA-PKCS,RSA-PKCS-PSS,SHA1-RSA-PKCS-PSS,SHA224-RSA-PKCS-PSS,SHA256-RSA-PKCS-PSS,SHA384-RSA-PKCS-PSS,SHA512-RSA-PKCS-PSS,RSA-PP
Private Key Object; RSA 
  label:      sss:20202020
  ID:         20202020
  Usage:      decrypt, sign
  Access:     sensitive, always sensitive
  Allowed mechanisms: RSA-PKCS,SHA1-RSA-PKCS,SHA224-RSA-PKCS,SHA256-RSA-PKCS,SHA384-RSA-PKCS,SHA512-RSA-PKCS,RSA-PKCS-PSS,SHA1-RSA-PKCS-PSS,SHA224-RSA-PKCS-PSS,SHA256-RSA-PKCS-PSS,SHA384-RSA-PKCS-PSS,SHA512-RSA-PKCS-PSS,RSA-PP&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 09:39:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1855553#M1597</guid>
      <dc:creator>user4</dc:creator>
      <dc:date>2024-04-26T09:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: pkcs11-tool generates 2 private keys for keypairgen</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1856536#M1598</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/232787"&gt;@user4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May I have the MW version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day,&lt;BR /&gt;Kan&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;BR /&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 07:54:59 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1856536#M1598</guid>
      <dc:creator>Kan_Li</dc:creator>
      <dc:date>2024-04-29T07:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: pkcs11-tool generates 2 private keys for keypairgen</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1857078#M1600</link>
      <description>&lt;P&gt;Hi Kan,&lt;/P&gt;&lt;P&gt;Thank you for responding.&lt;/P&gt;&lt;P&gt;Unfortunately, I don't know the specific version of MW because this environment was built by another company, but guessing it might be 4.2.0:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# dpkg -L plug-and-trust
/.
/etc
/etc/plug-and-trust
/etc/plug-and-trust/openssl11_sss_se050.cnf
/usr
/usr/lib
/usr/lib/arm-linux-gnueabihf
/usr/lib/arm-linux-gnueabihf/engines-1.1
/usr/lib/arm-linux-gnueabihf/engines-1.1/e4sss.so
/usr/lib/arm-linux-gnueabihf/libsssapisw.so.4.2.0
/usr/lib/arm-linux-gnueabihf/plug-and-trust
/usr/lib/arm-linux-gnueabihf/plug-and-trust/libsss_pkcs11.so
/usr/share
/usr/share/doc
/usr/share/doc/plug-and-trust
/usr/share/doc/plug-and-trust/changelog.Debian.gz
/usr/share/doc/plug-and-trust/copyright
/usr/lib/arm-linux-gnueabihf/libsssapisw.so.4&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 01:08:47 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1857078#M1600</guid>
      <dc:creator>user4</dc:creator>
      <dc:date>2024-04-30T01:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: pkcs11-tool generates 2 private keys for keypairgen</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1859378#M1601</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/232787"&gt;@user4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the information! I have tied the same with MW ver 4.5.1 , it just works as expected. Maybe you have to update the MW to the latest. Please kindly refer to the following for details.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Kan_Li_0-1714972873727.png" style="width: 539px;"&gt;&lt;img src="https://community.nxp.com/t5/image/serverpage/image-id/277157i5E72F8A6E9A37C13/image-dimensions/539x248?v=v2" width="539" height="248" role="button" title="Kan_Li_0-1714972873727.png" alt="Kan_Li_0-1714972873727.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day,&lt;BR /&gt;Kan&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;BR /&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 05:21:46 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1859378#M1601</guid>
      <dc:creator>Kan_Li</dc:creator>
      <dc:date>2024-05-06T05:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: pkcs11-tool generates 2 private keys for keypairgen</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1860031#M1602</link>
      <description>&lt;P&gt;Hi Kan,&lt;/P&gt;&lt;P&gt;Thank you for the inputs. I've also verified that using the libraries in that version does solve the problem, so will consider to ask the package provider to update the MW.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 00:38:52 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/pkcs11-tool-generates-2-private-keys-for-keypairgen/m-p/1860031#M1602</guid>
      <dc:creator>user4</dc:creator>
      <dc:date>2024-05-07T00:38:52Z</dc:date>
    </item>
  </channel>
</rss>

