Repository navigation
pam-pkcs11: authenticate through pam_pkcs11 with pamtester - #505
Open
yosuke-wolfssl wants to merge 1 commit into
Open
yosuke-wolfssl wants to merge 1 commit into
yosuke-wolfssl wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The authentication coverage is sound; only the workflow documentation needs minor synchronization.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Reworks PAM PKCS#11 CI to perform genuine certificate-based authentication and meaningful failure checks.
Changes:
- Creates valid, unknown-CA, and mismatched-key SoftHSM tokens.
- Authenticates through a dedicated
pamtesterservice. - Handles force-fail validation within the test script.
| File | Description |
|---|---|
.github/workflows/pam-pkcs11.yml |
Uses the script’s result directly. |
.github/scripts/pam-pkcs11-test.sh |
Implements complete positive and negative authentication tests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- pam-pkcs11-test.sh puts CA-issued, unknown-CA and mismatched-key credentials on SoftHSM tokens and authenticates through a pam_pkcs11-only PAM service via pamtester, in place of su. - The valid token must pass the signature check; a wrong PIN, the unknown CA and the mismatched key must each fail. Under force fail only the second authentication runs with it set. - check-workflow-result.sh has a pam_pkcs11 branch that requires one successful authentication and "Error 2320" in the log. - Unused packages and the pcscd start are dropped.
yosuke-wolfssl
force-pushed
the
fix/ci-pam
branch
from
October 7, 2026 10:27
c6b3756 to
e994414
Compare
Contributor
Author
|
Jenkins retest this please |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Problem
The pam-pkcs11 job passed in every cell without ever running
pam_pkcs11.so:su testuserran as root, sopam_rootokaccepted it before the module was asked.pam_pkcs11was also onlysufficientincommon-auth, withpam_unixbehind it.softhsmmodule block that does not exist, the token held no private key, the user cert was self-signed instead of issued by the CA, and no mapper read the mapping file.WOLFPROV_FORCE_FAIL=1beforesofthsm2-util --init-token, which failed during setup. The shared check counted that as "failed as expected".Fix (
.github/scripts/pam-pkcs11-test.sh)mktempworkspace. It creates a CA and a user cert it issues, and puts the key and cert on a SoftHSM token under one ID.softhsmmodule block,cert_policy = ca,signature, and thecnmapper.pam_pkcs11_testservice (pam_pkcs11, thenpam_deny) viapamtester, so the result does not depend on running as root.pam-pkcs11.ymlgates on the script's exit status and no longer callscheck-workflow-result.sh.Checking signature, thensuccessfully authenticatedError 2320Error 2328: Certificate signature invalidError 2342: Verifying signature failedError 2320with itUnder force fail, SoftHSM's PIN hashing fails first (
EVP_DigestInit failed) and pam_pkcs11 reports it as a wrong PIN. Running the same PIN without force fail first rules out a real wrong PIN.Verification
wolfprovider-test-deps:bookwormwith this repo's master replace-default packages: all 4 cells pass (non-FIPS and FIPS, normal and force-fail).wp_rsa_digest_verify_finaland the signature check viawp_rsa_verify, which returns 0 with the wrong key. SoftHSM's SHA-256 and AES go through wolfProvider too.Not in this PR
SoftHSM 2.6.1 signs with OpenSSL 3.0's legacy
RSA_private_encrypt/RSA_sign, so the token's private-key operation never reaches wolfProvider. In FIPS cells it runs outside the FIPS boundary. Same kind of gap as OpenSSH's; it goes in the audit doc's replace-default FIPS item.