EdgeLock SE051: se05x_Minimal fails with SCP03 errors after loading OpenSSL Provider

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

EdgeLock SE051: se05x_Minimal fails with SCP03 errors after loading OpenSSL Provider

Jump to solution
455 Views
Uc_S
Contributor I

Hello,

I am trying to use the OpenSSL Provider with the EdgeLock SE051 and SCP03 on Linux. I have run into an issue where the se05x_Minimal example works perfectly at first, but fails with SCP03 authentication errors after I install the shared libraries for the OpenSSL Provider.

Could you please advise on what might be causing this conflict?

Environment:

  • Board: MCIMX8M-WEVK and OM-SE051ARD

  • SoC: i.MX 8M

  • Linux version: 6.1.151-cip46

  • OpenSSL version: 3.0.20

  • Plug & Trust MW version: 04.07.01

Steps Taken:

  1. Built the Plug & Trust MW with the following CMake configuration:

    cmake ../simw-top \
    -DPTMW_Applet=SE05X_C \
    -DPTMW_SE05X_Ver=07_02 \
    -DPTMW_Host=iMXLinux \
    -DPTMW_SMCOM=T1oI2C \
    -DPTMW_HostCrypto=OPENSSL \
    -DPTMW_RTOS=Default \
    -DPTMW_mbedTLS_ALT=None \
    -DPTMW_SCP=SCP03_SSS \
    -DPTMW_FIPS=None \
    -DPTMW_SBL=None \
    -DPTMW_SE05X_Auth=PlatfSCP03 \
    -DPTMW_Log=Default \
    -DCMAKE_BUILD_TYPE=Release \
    -DPTMW_SE_RESET_LOGIC=1
  2. Copied simw-top/demos/linux/common/openssl30_sss_se050.cnf from the Plug & Trust MW directory to /root on the i.MX 8M.

  3. Exported the configuration environment variable:

    export OPENSSL_CONF=/root/openssl30_sss_se050.cnf
  4. Executed se05x_Minimal to confirm that the SE051 with SCP03 works correctly. It succeeded.

    App   :INFO :Running bin/se05x_Minimal
    App   :INFO :If you want to over-ride the selection, use ENV=EX_SSS_BOOT_SSS_PORT or pass in command line arguments.
    App   :INFO :PlugAndTrust_v04.07.01_20250519
    App   :INFO :Using default PlatfSCP03 keys. You can use keys from file using ENV=EX_SSS_BOOT_SCP03_PATH
    sss   :INFO :atr (Len=35)
          (snip)
    App   :INFO :mem=17196
    App   :INFO :se05x_Minimal Example Success !!!...
    App   :INFO :ex_sss Finished
  5. Copied libsssapisw.so, libsss_pkcs11.so, and libsssProvider.so to /usr/local/lib/. (Note: /usr/local/lib/ is the path specified in the [nxp_prov_sec] section of /root/openssl30_sss_se050.cnf)

  6. Executed se05x_Minimal again. This time, it failed with the following errors:

Error Output:

App   :INFO :Running bin/se05x_Minimal
App   :INFO :If you want to over-ride the selection, use ENV=EX_SSS_BOOT_SSS_PORT or pass in command line arguments.
App   :INFO :PlugAndTrust_v04.07.01_20250519
App   :INFO :Using default PlatfSCP03 keys. You can use keys from file using ENV=EX_SSS_BOOT_SCP03_PATH
sss   :INFO :atr (Len=35)
      (snip)
App   :INFO :If you want to over-ride the selection, use ENV=EX_SSS_BOOT_SSS_PORT or pass in command line arguments.
App   :INFO :Using default PlatfSCP03 keys. You can use keys from file using ENV=EX_SSS_BOOT_SCP03_PATH
sss   :INFO :atr (Len=35)
      (snip)
sss   :ERROR:Error in RAND_pseudo_bytes 
scp   :WARN :nxEnsure:'status == kStatus_SSS_Success' failed. At Line:121 Function:nxScp03_AuthenticateChannel
sss   :ERROR:Could not set SCP03 Secure Channel
App   :ERROR:sss_session_open failed
App   :WARN :nxEnsure:'kStatus_SSS_Success == status' failed. At Line:240 Function:OSSL_provider_init
smCom :ERROR:phNxpEseProto7816_DecodeFrame Max retry count reached!!! 
smCom :ERROR:phNxpEseProto7816_Transceive Transceive failed, hard reset to proceed 
smCom :ERROR: phNxpEse_Transceive phNxpEseProto7816_Transceive- Failed 
smCom :ERROR: Transcive Failed 
sss   :WARN :nxEnsure:'retStatus == SM_OK' failed. At Line:7977 Function:sss_se05x_channel_txn
sss   :WARN :nxEnsure:'ret == SM_OK' failed. At Line:7839 Function:sss_se05x_TXn
sss   :WARN :APDU Transaction Error: Error (0xFFFF)

scp   :ERROR:GP_InitializeUpdate Failure on communication Link FFFF
scp   :ERROR:nxScp03_GP_InitializeUpdate fails with Status 3C3C0000
sss   :ERROR:Could not set SCP03 Secure Channel
App   :ERROR:sss_session_open failed
App   :ERROR:ex_sss_session_open Failed
App   :ERROR:!ERROR! ret != 0.

It seems that once the OpenSSL provider is successfully loaded by the configuration, something (possibly related to RAND_pseudo_bytes) breaks the SCP03 channel establishment.

Has anyone encountered this or knows what additional configurations might be missing?

Thank you in advance for your help.

0 Kudos
Reply
1 Solution
412 Views
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @Uc_S ,

 

Did you set up the proper openssl version?  Please use the following option:

-DPTMW_OpenSSL=3_0

BTW, for test purpose, please enable verbose log to have more debug info. 

-DPTMW_Log=Verbose

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

View solution in original post

0 Kudos
Reply
2 Replies
413 Views
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @Uc_S ,

 

Did you set up the proper openssl version?  Please use the following option:

-DPTMW_OpenSSL=3_0

BTW, for test purpose, please enable verbose log to have more debug info. 

-DPTMW_Log=Verbose

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 Kudos
Reply
401 Views
Uc_S
Contributor I

Thank you very much for your advice. You were exactly right.

The root cause of the issue was indeed the missing "-DPTMW_OpenSSL=3_0" option in my CMake configuration.

After adding "-DPTMW_OpenSSL=3_0 -DPTMW_Log=Verbose" and rebuilding the MW, the problem was completely resolved. Here are the results:

Executing Step 6 no longer throws any errors. It successfully outputs "App :INFO :mem=17196" as expected.

I also confirmed that even when setting the log level back to my originally intended configuration ("-DPTMW_Log=Default"  instead of Verbose), the application still executes perfectly and outputs "App :INFO :mem=17196".

I will mark this topic as resolved.

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2383849%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EEdgeLock%20SE051%3A%20se05x_Minimal%20fails%20with%20SCP03%20errors%20after%20loading%20OpenSSL%20Provider%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2383849%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EI%20am%20trying%20to%20use%20the%20OpenSSL%20Provider%20with%20the%20EdgeLock%20SE051%20and%20SCP03%20on%20Linux.%20I%20have%20run%20into%20an%20issue%20where%20the%20se05x_Minimal%20example%20works%20perfectly%20at%20first%2C%20but%20fails%20with%20SCP03%20authentication%20errors%20%3CI%3Eafter%3C%2FI%3E%20I%20install%20the%20shared%20libraries%20for%20the%20OpenSSL%20Provider.%3C%2FP%3E%3CP%3ECould%20you%20please%20advise%20on%20what%20might%20be%20causing%20this%20conflict%3F%3C%2FP%3E%3CP%3E%3CSTRONG%3EEnvironment%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CUL%3E%3CLI%3E%3CP%3E%3CSTRONG%3EBoard%3A%3C%2FSTRONG%3E%20MCIMX8M-WEVK%20and%20OM-SE051ARD%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3E%3CSTRONG%3ESoC%3A%3C%2FSTRONG%3E%20i.MX%208M%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3E%3CSTRONG%3ELinux%20version%3A%3C%2FSTRONG%3E%206.1.151-cip46%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3E%3CSTRONG%3EOpenSSL%20version%3A%3C%2FSTRONG%3E%203.0.20%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3E%3CSTRONG%3EPlug%20%26amp%3B%20Trust%20MW%20version%3A%3C%2FSTRONG%3E%2004.07.01%3C%2FP%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%3CSTRONG%3ESteps%20Taken%3A%3C%2FSTRONG%3E%3C%2FP%3E%3COL%3E%3CLI%3E%3CP%3EBuilt%20the%20Plug%20%26amp%3B%20Trust%20MW%20with%20the%20following%20CMake%20configuration%3A%3C%2FP%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CPRE%3Ecmake%20..%2Fsimw-top%20%5C%0A-DPTMW_Applet%3DSE05X_C%20%5C%0A-DPTMW_SE05X_Ver%3D07_02%20%5C%0A-DPTMW_Host%3DiMXLinux%20%5C%0A-DPTMW_SMCOM%3DT1oI2C%20%5C%0A-DPTMW_HostCrypto%3DOPENSSL%20%5C%0A-DPTMW_RTOS%3DDefault%20%5C%0A-DPTMW_mbedTLS_ALT%3DNone%20%5C%0A-DPTMW_SCP%3DSCP03_SSS%20%5C%0A-DPTMW_FIPS%3DNone%20%5C%0A-DPTMW_SBL%3DNone%20%5C%0A-DPTMW_SE05X_Auth%3DPlatfSCP03%20%5C%0A-DPTMW_Log%3DDefault%20%5C%0A-DCMAKE_BUILD_TYPE%3DRelease%20%5C%0A-DPTMW_SE_RESET_LOGIC%3D1%3C%2FPRE%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLI%3E%3CLI%3E%3CP%3ECopied%20simw-top%2Fdemos%2Flinux%2Fcommon%2Fopenssl30_sss_se050.cnf%20from%20the%20Plug%20%26amp%3B%20Trust%20MW%20directory%20to%20%2Froot%20on%20the%20i.MX%208M.%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3EExported%20the%20configuration%20environment%20variable%3A%3C%2FP%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CPRE%3E%3CSPAN%20class%3D%22%22%3Eexport%3C%2FSPAN%3E%20OPENSSL_CONF%3D%2Froot%2Fopenssl30_sss_se050.cnf%3C%2FPRE%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLI%3E%3CLI%3E%3CP%3EExecuted%20se05x_Minimal%20to%20confirm%20that%20the%20SE051%20with%20SCP03%20works%20correctly.%20%3CSTRONG%3EIt%20succeeded.%3C%2FSTRONG%3E%3C%2FP%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CPRE%3EApp%20%20%20%3AINFO%20%3ARunning%20bin%2Fse05x_Minimal%0AApp%20%20%20%3AINFO%20%3AIf%20you%20want%20to%20over-ride%20the%20selection%2C%20use%20ENV%3DEX_SSS_BOOT_SSS_PORT%20or%20pass%20in%20command%20line%20arguments.%0AApp%20%20%20%3AINFO%20%3APlugAndTrust_v04.07.01_20250519%0AApp%20%20%20%3AINFO%20%3AUsing%20default%20PlatfSCP03%20keys.%20You%20can%20use%20keys%20from%20file%20using%20ENV%3DEX_SSS_BOOT_SCP03_PATH%0Asss%20%20%20%3AINFO%20%3Aatr%20(Len%3D35)%0A%20%20%20%20%20%20(snip)%0AApp%20%20%20%3AINFO%20%3Amem%3D17196%0AApp%20%20%20%3AINFO%20%3Ase05x_Minimal%20Example%20Success%20!!!...%0AApp%20%20%20%3AINFO%20%3Aex_sss%20Finished%3C%2FPRE%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLI%3E%3CLI%3E%3CP%3ECopied%20libsssapisw.so%2C%20libsss_pkcs11.so%2C%20and%20libsssProvider.so%20to%20%2Fusr%2Flocal%2Flib%2F.%20%3CI%3E(Note%3A%20%2Fusr%2Flocal%2Flib%2F%20is%20the%20path%20specified%20in%20the%20%5Bnxp_prov_sec%5D%20section%20of%20%2Froot%2Fopenssl30_sss_se050.cnf)%3C%2FI%3E%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3EExecuted%20se05x_Minimal%20again.%20This%20time%2C%20%3CSTRONG%3Eit%20failed%3C%2FSTRONG%3E%20with%20the%20following%20errors%3A%3C%2FP%3E%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%3CSTRONG%3EError%20Output%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CDIV%20class%3D%22%22%3E%3CPRE%3EApp%20%20%20%3AINFO%20%3ARunning%20bin%2Fse05x_Minimal%0AApp%20%20%20%3AINFO%20%3AIf%20you%20want%20to%20over-ride%20the%20selection%2C%20use%20ENV%3DEX_SSS_BOOT_SSS_PORT%20or%20pass%20in%20command%20line%20arguments.%0AApp%20%20%20%3AINFO%20%3APlugAndTrust_v04.07.01_20250519%0AApp%20%20%20%3AINFO%20%3AUsing%20default%20PlatfSCP03%20keys.%20You%20can%20use%20keys%20from%20file%20using%20ENV%3DEX_SSS_BOOT_SCP03_PATH%0Asss%20%20%20%3AINFO%20%3Aatr%20(Len%3D35)%0A%20%20%20%20%20%20(snip)%0AApp%20%20%20%3AINFO%20%3AIf%20you%20want%20to%20over-ride%20the%20selection%2C%20use%20ENV%3DEX_SSS_BOOT_SSS_PORT%20or%20pass%20in%20command%20line%20arguments.%0AApp%20%20%20%3AINFO%20%3AUsing%20default%20PlatfSCP03%20keys.%20You%20can%20use%20keys%20from%20file%20using%20ENV%3DEX_SSS_BOOT_SCP03_PATH%0Asss%20%20%20%3AINFO%20%3Aatr%20(Len%3D35)%0A%20%20%20%20%20%20(snip)%0Asss%20%20%20%3AERROR%3AError%20in%20RAND_pseudo_bytes%20%0Ascp%20%20%20%3AWARN%20%3AnxEnsure%3A'status%20%3D%3D%20kStatus_SSS_Success'%20failed.%20At%20Line%3A121%20Function%3AnxScp03_AuthenticateChannel%0Asss%20%20%20%3AERROR%3ACould%20not%20set%20SCP03%20Secure%20Channel%0AApp%20%20%20%3AERROR%3Asss_session_open%20failed%0AApp%20%20%20%3AWARN%20%3AnxEnsure%3A'kStatus_SSS_Success%20%3D%3D%20status'%20failed.%20At%20Line%3A240%20Function%3AOSSL_provider_init%0AsmCom%20%3AERROR%3AphNxpEseProto7816_DecodeFrame%20Max%20retry%20count%20reached!!!%20%0AsmCom%20%3AERROR%3AphNxpEseProto7816_Transceive%20Transceive%20failed%2C%20hard%20reset%20to%20proceed%20%0AsmCom%20%3AERROR%3A%20phNxpEse_Transceive%20phNxpEseProto7816_Transceive-%20Failed%20%0AsmCom%20%3AERROR%3A%20Transcive%20Failed%20%0Asss%20%20%20%3AWARN%20%3AnxEnsure%3A'retStatus%20%3D%3D%20SM_OK'%20failed.%20At%20Line%3A7977%20Function%3Asss_se05x_channel_txn%0Asss%20%20%20%3AWARN%20%3AnxEnsure%3A'ret%20%3D%3D%20SM_OK'%20failed.%20At%20Line%3A7839%20Function%3Asss_se05x_TXn%0Asss%20%20%20%3AWARN%20%3AAPDU%20Transaction%20Error%3A%20Error%20(0xFFFF)%0A%0Ascp%20%20%20%3AERROR%3AGP_InitializeUpdate%20Failure%20on%20communication%20Link%20FFFF%0Ascp%20%20%20%3AERROR%3AnxScp03_GP_InitializeUpdate%20fails%20with%20Status%203C3C0000%0Asss%20%20%20%3AERROR%3ACould%20not%20set%20SCP03%20Secure%20Channel%0AApp%20%20%20%3AERROR%3Asss_session_open%20failed%0AApp%20%20%20%3AERROR%3Aex_sss_session_open%20Failed%0AApp%20%20%20%3AERROR%3A!ERROR!%20ret%20!%3D%200.%3C%2FPRE%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CP%3EIt%20seems%20that%20once%20the%20OpenSSL%20provider%20is%20successfully%20loaded%20by%20the%20configuration%2C%20something%20(possibly%20related%20to%20RAND_pseudo_bytes)%20breaks%20the%20SCP03%20channel%20establishment.%3C%2FP%3E%3CP%3EHas%20anyone%20encountered%20this%20or%20knows%20what%20additional%20configurations%20might%20be%20missing%3F%3C%2FP%3E%3CP%3EThank%20you%20in%20advance%20for%20your%20help.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2384812%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20EdgeLock%20SE051%3A%20se05x_Minimal%20fails%20with%20SCP03%20errors%20after%20loading%20OpenSSL%20Provider%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2384812%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F259681%22%20target%3D%22_blank%22%3E%40Uc_S%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EDid%20you%20set%20up%20the%20proper%20openssl%20version%3F%26nbsp%3B%20Please%20use%20the%20following%20option%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E-DPTMW_OpenSSL%3D3_0%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EBTW%2C%20for%20test%20purpose%2C%20please%20enable%20verbose%20log%20to%20have%20more%20debug%20info.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E-DPTMW_Log%3DVerbose%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EHave%20a%20great%20day%2C%3CBR%20%2F%3EKan%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E-------------------------------------------------------------------------------%3CBR%20%2F%3ENote%3A%3CBR%20%2F%3E-%20If%20this%20post%20answers%20your%20question%2C%20please%20click%20the%20%22Mark%20Correct%22%20button.%20Thank%20you!%3CBR%20%2F%3E-%20We%20are%20following%20threads%20for%207%20weeks%20after%20the%20last%20post%2C%20later%20replies%20are%20ignored%3CBR%20%2F%3EPlease%20open%20a%20new%20thread%20and%20refer%20to%20the%20closed%20one%2C%20if%20you%20have%20a%20related%20question%20at%20a%20later%20point%20in%20time.%3CBR%20%2F%3E-------------------------------------------------------------------------------%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2385344%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20EdgeLock%20SE051%3A%20se05x_Minimal%20fails%20with%20SCP03%20errors%20after%20loading%20OpenSSL%20Provider%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2385344%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EThank%20you%20very%20much%20for%20your%20advice.%20You%20were%20exactly%20right.%3C%2FP%3E%3CP%3EThe%20root%20cause%20of%20the%20issue%20was%20indeed%20the%20missing%20%22-DPTMW_OpenSSL%3D3_0%22%20option%20in%20my%20CMake%20configuration.%3C%2FP%3E%3CP%3EAfter%20adding%26nbsp%3B%22-DPTMW_OpenSSL%3D3_0%20%3CSPAN%3E-DPTMW_Log%3DVerbose%3C%2FSPAN%3E%22%20and%20rebuilding%20the%20MW%2C%20the%20problem%20was%20completely%20resolved.%20Here%20are%20the%20results%3A%3C%2FP%3E%3CP%3EExecuting%20Step%206%20no%20longer%20throws%20any%20errors.%20It%20successfully%20outputs%20%22App%20%3AINFO%20%3Amem%3D17196%22%20as%20expected.%3C%2FP%3E%3CP%3EI%20also%20confirmed%20that%20even%20when%20setting%20the%20log%20level%20back%20to%20my%20originally%20intended%20configuration%20(%22-DPTMW_Log%3DDefault%22%26nbsp%3B%20instead%20of%20Verbose)%2C%20the%20application%20still%20executes%20perfectly%20and%20outputs%20%22App%20%3AINFO%20%3Amem%3D17196%22.%3C%2FP%3E%3CP%3EI%20will%20mark%20this%20topic%20as%20resolved.%3C%2FP%3E%3C%2FLINGO-BODY%3E