Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #89137 > unrolled thread

Bug#1114737: linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set

Started byCliff Kilby <cliffjkilby@gmail.com>
First post2025-09-09 01:20 +0200
Last post2025-09-09 19:40 +0200
Articles 3 — 1 participant

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1114737: linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set Cliff Kilby <cliffjkilby@gmail.com> - 2025-09-09 01:20 +0200
    Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set) Cliff Kilby <cliffjkilby@gmail.com> - 2025-09-09 16:10 +0200
      Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set) Cliff Kilby <cliffjkilby@gmail.com> - 2025-09-09 19:40 +0200

#89137 — Bug#1114737: linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set

FromCliff Kilby <cliffjkilby@gmail.com>
Date2025-09-09 01:20 +0200
SubjectBug#1114737: linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set
Message-ID<LsTjr-dThK-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Package: src:linux
Version: 6.12.43-1
Severity: normal
X-Debbugs-Cc:cliffjkilby@gmail.com

Dear Maintainer,

I attempted to follow the instructions at
https://manpages.debian.org/trixie/ima-evm-utils/evmctl.1.en.html for TPM
backed IMA/EVM setup
It includes the command
# keyctl add trusted kmk "new 32" @u
add_key: No such device

Based on https://cateee.net/lkddb/web-lkddb/TRUSTED_KEYS.html
"trusted" is not available unless CONFIG_TRUSTED_KEYS is at least "m" if
not "y"
https://ima-doc.readthedocs.io/en/latest/ima-configuration.html#config-trusted-keys
similarly mentions it for ima setup.
It appears that the required flags:
CONFIG_KEYS=y
CONFIG_ENCRYPTED_KEYS=y
(and older kernel/functionality)
CONFIG_TCG_TPM=y
CONFIG_TCG_TPM2_HMAC=y
are all set, so, this seems like a single config change to "m" enable
module build of masterkey_trusted, trusted.

<<PCI DEVICE INFORMATION ELIDED BY SUBMITTER>>

-- System Information:
Debian Release: 13.1
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500,
'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.12.43+deb13-amd64 (SMP w/24 CPU threads; PREEMPT)
Kernel taint flags: TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE
not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: SELinux: enabled - Mode: Enforcing - Policy name: default

Versions of packages linux-image-6.12.43+deb13-amd64 depends on:
ii  dracut [linux-initramfs-tool]  106-6
ii  kmod                           34.2-2
ii  linux-base                     4.12

Versions of packages linux-image-6.12.43+deb13-amd64 recommends:
pn  apparmor  <none>

Versions of packages linux-image-6.12.43+deb13-amd64 suggests:
pn  debian-kernel-handbook  <none>
pn  firmware-linux-free     <none>
ii  grub-efi-amd64          2.12-9
pn  linux-doc-6.12          <none>

Versions of packages linux-image-6.12.43+deb13-amd64 is related to:
pn  firmware-amd-graphics      <none>
pn  firmware-atheros           <none>
pn  firmware-bnx2              <none>
pn  firmware-bnx2x             <none>
pn  firmware-brcm80211         <none>
pn  firmware-cavium            <none>
pn  firmware-cirrus            <none>
pn  firmware-intel-graphics    <none>
pn  firmware-intel-misc        <none>
pn  firmware-intel-sound       <none>
pn  firmware-ipw2x00           <none>
pn  firmware-ivtv              <none>
ii  firmware-iwlwifi           20250410-2
pn  firmware-libertas          <none>
pn  firmware-marvell-prestera  <none>
pn  firmware-mediatek          <none>
pn  firmware-misc-nonfree      <none>
pn  firmware-myricom           <none>
pn  firmware-netronome         <none>
pn  firmware-netxen            <none>
pn  firmware-nvidia-graphics   <none>
pn  firmware-qcom-soc          <none>
pn  firmware-qlogic            <none>
ii  firmware-realtek           20250410-2
pn  firmware-samsung           <none>
pn  firmware-siano             <none>
pn  firmware-ti-connectivity   <none>
pn  xen-hypervisor             <none>

-- no debconf information

[toc] | [next] | [standalone]


#89140 — Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set)

FromCliff Kilby <cliffjkilby@gmail.com>
Date2025-09-09 16:10 +0200
SubjectBug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set)
Message-ID<Lt7cJ-e32s-7@gated-at.bofh.it>
In reply to#89137

[Multipart message — attachments visible in raw view] — view raw

I went out on a ledge and tried to rebuild the kernel with the single
change proposed.
# uname -a
Linux debian 6.12.43 #2 SMP PREEMPT_DYNAMIC Tue Sep  9 09:24:23 EDT 2025
x86_64 GNU/Linux
# grep TRUSTED /boot/config-6.12.43
CONFIG_TRUSTED_KEYS=m
# dmesg | grep 'Linux version'
[    0.000000] Linux version 6.12.43 (buildlocal@debian) (gcc (Debian
14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44) #2 SMP
PREEMPT_DYNAMIC Tue Sep  9 09:24:23 EDT 2025
#modinfo trusted
filename:
/lib/modules/6.12.43/kernel/security/keys/trusted-keys/trusted.ko.xz
license:        GPL
# lsmod | grep trusted
trusted                45056  1 dm_crypt
asn1_encoder           12288  1 trusted
tee                    49152  1 trusted
# keyctl add trusted kmk "new 32" @u
add_key: Invalid argument

Ooops. It appears that even with the module, the instruction is wrong. But,
at least "trusted" is a type now. So, I can do this.

# keyctl add trusted kmk-trusted "new 32 keyhandle=0x81000001" @u
964692806
# keyctl describe  964692806
964692806: alswrv-----v------------     0     0 trusted: kmk-trusted

I do not believe that building a local kernel is a long term fix for a
security feature that should be available by default. I would still ask
that you enable the module build of this module.


On Mon, Sep 8, 2025 at 11:19 PM Debian Bug Tracking System <
owner@bugs.debian.org> wrote:

> Thank you for filing a new Bug report with Debian.
>
> You can follow progress on this Bug here: 1114737:
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1114737.
>
> This is an automatically generated reply to let you know your message
> has been received.
>
> Your message is being forwarded to the package maintainers and other
> interested parties for their attention; they will reply in due course.
>
> As you requested using X-Debbugs-CC, your message was also forwarded to
>   cliffjkilby@gmail.com
> (after having been given a Bug report number, if it did not have one).
>
> Your message has been sent to the package maintainer(s):
>  debian-kernel@lists.debian.org
>
> If you wish to submit further information on this problem, please
> send it to 1114737@bugs.debian.org.
>
> Please do not send mail to owner@bugs.debian.org unless you wish
> to report a problem with the Bug-tracking system.
>
> --
> 1114737: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1114737
> Debian Bug Tracking System
> Contact owner@bugs.debian.org with problems
>

[toc] | [prev] | [next] | [standalone]


#89149 — Bug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set)

FromCliff Kilby <cliffjkilby@gmail.com>
Date2025-09-09 19:40 +0200
SubjectBug#1114737: Acknowledgement (linux-image-6.12.43+deb13-amd64: CONFIG_TRUSTED_KEYS is not set)
Message-ID<LtatX-e5b8-1@gated-at.bofh.it>
In reply to#89140

[Multipart message — attachments visible in raw view] — view raw

There does appear to be a complication for this change. keyctl can add
trusted, but not read encrypted keys
# keyctl add encrypted evm-key "new trusted:kmk-trusted 32" @u
# keyctl pipe `keyctl search @u encrypted evm-key`
keyctl_read_alloc: Operation not supported
# keyctl search @u encrypted evm-key
58969095
The key exists but cannot be read. This appears to be due to
https://bugzilla.kernel.org/show_bug.cgi?id=202577

If trusted is a module, and encrypted is builtin, encrypted cannot open a
trusted key because the masterkey_trusted.o types are not exported out of
the encrypted-keys namespace?
(mind you, I am not a kernel developer, and this c is ... waaaaay out of my
league.)
In summary:
CONFIG_TRUSTED_KEYS=n && CONFIG_ENCRYPTED_KEYS=y == keyctl add trusted
fails.
CONFIG_TRUSTED_KEYS=m && CONFIG_ENCRYPTED_KEYS=y == keyctl read encrypted
from a trusted key fails.
In order to have both, both have to be modules (to export the types), or
both have to be builtin (to use the shared type lookups?).

CONFIG_TRUSTED_KEYS=y

I built the kernel again with the change above and :
# uname -a
Linux debian 6.12.43 #28 SMP PREEMPT_DYNAMIC Tue Sep  9 12:57:21 EDT 2025
x86_64 GNU/Linux
# dmesg | grep -P '(trusted|encrypted)'
[    1.779375] Initialise system trusted keyrings
[    4.969001] Key type trusted registered
[    5.001211] Key type encrypted registered
[   24.235628] trusted_key: encrypted_key: master key parameter '' is
invalid

# keyctl search @u trusted kmk-trusted
625450296
# keyctl add encrypted evm-key "new trusted:kmk-trusted 32" @u
234222391
# keyctl link @u @s
# keyctl pipe `keyctl search @u encrypted evm-key`
default trusted:kmk-trusted 32 <<REDACTED KEY MATERIAL>>

Success.

Given my original goal was to follow the instructions as provided, I change
my request to reconfigure the kernel build to CONFIG_TRUSTED_KEYS=y to fix
the keyctl for both trusted and encrypted types.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web