Skip to content

pam-pkcs11: authenticate through pam_pkcs11 with pamtester - #505

Open
yosuke-wolfssl wants to merge 1 commit into
wolfSSL:masterfrom
yosuke-wolfssl:fix/ci-pam
Open

yosuke-wolfssl wants to merge 1 commit into
wolfSSL:masterfrom
yosuke-wolfssl:fix/ci-pam

Conversation

@yosuke-wolfssl

Copy link
Copy Markdown
Contributor

Problem

The pam-pkcs11 job passed in every cell without ever running pam_pkcs11.so:

  • su testuser ran as root, so pam_rootok accepted it before the module was asked. pam_pkcs11 was also only sufficient in common-auth, with pam_unix behind it.
  • The setup could not have authenticated anyway. The config named a softhsm module block that does not exist, the token held no private key, the user cert was self-signed instead of issued by the CA, and no mapper read the mapping file.
  • The force-fail cell exported WOLFPROV_FORCE_FAIL=1 before softhsm2-util --init-token, which failed during setup. The shared check counted that as "failed as expected".

Fix (.github/scripts/pam-pkcs11-test.sh)

  • Setup runs without force fail in a mktemp workspace. It creates a CA and a user cert it issues, and puts the key and cert on a SoftHSM token under one ID.
  • pam_pkcs11.conf is written by the script: a softhsm module block, cert_policy = ca,signature, and the cn mapper.
  • Authentication goes through a dedicated pam_pkcs11_test service (pam_pkcs11, then pam_deny) via pamtester, so the result does not depend on running as root.
  • pam-pkcs11.yml gates on the script's exit status and no longer calls check-workflow-result.sh.
Case Required result
Valid token, correct PIN Checking signature, then successfully authenticated
Wrong PIN Error 2320
Cert from an unknown CA Error 2328: Certificate signature invalid
Key does not match the cert Error 2342: Verifying signature failed
Force-fail: valid token, correct PIN succeeds without force fail, then fails with Error 2320 with it

Under force fail, SoftHSM's PIN hashing fails first (EVP_DigestInit failed) and pam_pkcs11 reports it as a wrong PIN. Running the same PIN without force fail first rules out a real wrong PIN.

Verification

  • Local, in wolfprovider-test-deps:bookworm with this repo's master replace-default packages: all 4 cells pass (non-FIPS and FIPS, normal and force-fail).
  • Negative controls fail as intended: a self-signed user cert, a key that does not match the cert, and the old force-fail scoping.
  • A debug wolfProvider trace (arm64, non-FIPS) shows both RSA verifies in wolfProvider: the CA check via wp_rsa_digest_verify_final and the signature check via wp_rsa_verify, which returns 0 with the wrong key. SoftHSM's SHA-256 and AES go through wolfProvider too.

Not in this PR

SoftHSM 2.6.1 signs with OpenSSL 3.0's legacy RSA_private_encrypt/RSA_sign, so the token's private-key operation never reaches wolfProvider. In FIPS cells it runs outside the FIPS boundary. Same kind of gap as OpenSSH's; it goes in the audit doc's replace-default FIPS item.

@yosuke-wolfssl yosuke-wolfssl self-assigned this Oct 7, 2026
Copilot AI balanced review requested due to automatic review settings October 7, 2026 07:45
@yosuke-wolfssl yosuke-wolfssl added the ci:pam-pkcs11 PR OSP toggle: run pam-pkcs11 label Oct 7, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The authentication coverage is sound; only the workflow documentation needs minor synchronization.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Reworks PAM PKCS#11 CI to perform genuine certificate-based authentication and meaningful failure checks.

Changes:

  • Creates valid, unknown-CA, and mismatched-key SoftHSM tokens.
  • Authenticates through a dedicated pamtester service.
  • Handles force-fail validation within the test script.
File Description
.github/​workflows/​pam-pkcs11.yml Uses the script’s result directly.
.github/​scripts/​pam-pkcs11-test.sh Implements complete positive and negative authentication tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/pam-pkcs11.yml Outdated
- pam-pkcs11-test.sh puts CA-issued, unknown-CA and mismatched-key
  credentials on SoftHSM tokens and authenticates through a
  pam_pkcs11-only PAM service via pamtester, in place of su.
- The valid token must pass the signature check; a wrong PIN, the
  unknown CA and the mismatched key must each fail. Under force
  fail only the second authentication runs with it set.
- check-workflow-result.sh has a pam_pkcs11 branch that requires
  one successful authentication and "Error 2320" in the log.
- Unused packages and the pcscd start are dropped.
@yosuke-wolfssl yosuke-wolfssl added ci:pam-pkcs11 PR OSP toggle: run pam-pkcs11 and removed ci:pam-pkcs11 PR OSP toggle: run pam-pkcs11 labels Oct 7, 2026
@yosuke-wolfssl

Copy link
Copy Markdown
Contributor Author

Jenkins retest this please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:pam-pkcs11 PR OSP toggle: run pam-pkcs11

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants