Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-80632

opencryptoki tokens are deleted on reboot (image mode)

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Normal Normal
    • rhel-10.1
    • rhel-10.0
    • opencryptoki
    • None
    • opencryptoki-3.25.0-5.el10
    • None
    • Important
    • rhel-base-utils-antfarm
    • ssg_core_services
    • 7
    • 10
    • 3
    • Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Release Note Not Required
    • Unspecified
    • Unspecified
    • Unspecified
    • All
    • None

      What were you trying to do that didn't work?

      I have initialized opencryptoki token with opencryptoki-3.24.0-6.el10.x86_64

       

      1. pkcsconf -t
        Token #3 Info:
            Label: softtok                         
            Manufacturer: IBM                             
            Model: Soft            
            Serial Number:                 
            Flags: 0x64D (RNG|LOGIN_REQUIRED|USER_PIN_INITIALIZED|CLOCK_ON_TOKEN|DUAL_CRYPTO_OPERATIONS|TOKEN_INITIALIZED)
            Sessions: 0/[effectively infinite]
            R/W Sessions: 0/[effectively infinite]
            PIN Length: 4-8
            Public Memory: [information unavailable]/[information unavailable]
            Private Memory: [information unavailable]/[information unavailable]
            Hardware Version: 0.0
            Firmware Version: 0.0
            Time: 2025022505364200
            URI: pkcs11:manufacturer=IBM;model=Soft;token=softtok
      1. reboot
      1. pkcsconf -t

      Token #3 Info:
          Label: softtok                         
          Manufacturer: IBM                             
          Model: Soft            
          Serial Number:                 
          Flags: 0x880245 (RNG|LOGIN_REQUIRED|CLOCK_ON_TOKEN|DUAL_CRYPTO_OPERATIONS|USER_PIN_TO_BE_CHANGED|SO_PIN_TO_BE_CHANGED)
          Sessions: 0/[effectively infinite]
          R/W Sessions: 0/[effectively infinite]
          PIN Length: 4-8
          Public Memory: [information unavailable]/[information unavailable]
          Private Memory: [information unavailable]/[information unavailable]
          Hardware Version: 0.0
          Firmware Version: 0.0
          Time: 2025022505381800
          URI: pkcs11:manufacturer=IBM;model=Soft;token=softtok

      After reboot, the settings is gone. This is a regression from opencryptoki-3.24.0-4.el10.x86_64

      What is the impact of this issue to you?

      token data are lost

      Please provide the package NVR for which the bug is seen:

       opencryptoki-3.24.0-6.el10

      How reproducible is this bug?:

      always

      Steps to reproduce

      1. initialize token
      2. reboot
      3. check token data

      Expected results

      data are there

      Actual results

      data are not there

              than@redhat.com Than Ngo
              ksrot@redhat.com Karel Srot
              Than Ngo Than Ngo
              Karel Srot Karel Srot
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: