• Bug#1102965: pkcs11-provider: FTBFS in testing: tests failures (9/12)

    From Lucas Nussbaum@21:1/5 to All on Sun Apr 13 14:50:04 2025
    [continued from previous message]

    v:NotBefore: Apr 12 10:06:36 2025 GMT; NotAfter: Apr 12 10:06:36 2026 GMT ---
    Server certificate
    -----BEGIN CERTIFICATE----- MIICcjCCAVqgAwIBAgIBBDANBgkqhkiG9w0BAQsFADARMQ8wDQYDVQQDEwZJc3N1 ZXIwHhcNMjUwNDEyMTAwNjM2WhcNMjYwNDEyMTAwNjM2WjAvMRgwFgYDVQQKEw9Q S0NTMTEgUHJvdmlkZXIxEzARBgNVBAMTCk15IEVDIENlcnQwWTATBgcqhkjOPQIB BggqhkjOPQMBBwNCAATBhC6Bskae48wDIXJQXRNVcx3n7y90X+kO5StIXCuMPHy1 KKX00cXF6UXUHszjlvS2SMrVZQvJc2WTOiDTiv27o4GBMH8wDAYDVR0TAQH/BAIw ADAfBgNVHREEGDAWgRR0ZXN0Y2VydEBleGFtcGxlLm9yZzAOBgNVHQ8BAf8EBAMC B4AwHQYDVR0OBBYEFL+L0nMF/mpdNL6bGu74hnxx2622MB8GA1UdIwQYMBaAFCyg 8iYK7eejABnMyB2/g2vveKgPMA0GCSqGSIb3DQEBCwUAA4IBAQA50M5wbeBoxn/E X6VGW6QqIvM6rSi+/1e4bPpF3QAWDQDe1dktyIuV+S845UEW0+evWQzNIvPuahXJ gqOHJyTVYJNK2UZHd1P0GMCbnNwAFPuJtbikTG0XXj5mCmDDGfjMDe7f4iB7yoho eXijLDEYcSu9EBSHTKMFl1KHYI59fKsFaG1/vblPeRiXYwGpynuWnS9hiRpM5Bng FVSuHPZaD/CsVje/tqIzp7dx+EVwAmCEbWSLuzM8SvOf7LPU8NJOfUHTKPnq9ul7 UbgGKwA4ITGLF6tuviJ+AXVkF6k/mlEGBU2AeEVrYxsJfIpZ9iUGLRw0DYHX9pXy
    B4KikiF9
    -----END CERTIFICATE-----
    subject=O=PKCS11 Provider, CN=My EC Cert
    issuer=CN=Issuer
    ---
    No client certificate CA names sent
    Peer signing digest: SHA256
    Peer signature type: ecdsa_secp256r1_sha256
    Peer Temp Key: ECDH, prime256v1, 256 bits
    ---
    SSL handshake has read 1120 bytes and written 257 bytes
    Verification: OK
    ---
    New, TLSv1.2, Cipher is ECDHE-ECDSA-AES128-GCM-SHA256
    Protocol: TLSv1.2
    Server public key is 256 bit
    Secure Renegotiation IS supported
    Compression: NONE
    Expansion: NONE
    No ALPN negotiated
    SSL-Session:
    Protocol : TLSv1.2
    Cipher : ECDHE-ECDSA-AES128-GCM-SHA256
    Session-ID: 76D136B343E49A29F2D5ECB96C62B2589F4CF413C03CC00000C9A602249E314D
    Session-ID-ctx:
    Master-Key: E20A86F81198157B394A507CCA9688EB50ED0C632A47F0CEC1D55635DA4CC3031B1EA45F56A023F3A17AE248FFEF1732
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 7200 (seconds)
    TLS session ticket:
    0000 - c2 3b af 46 cc 54 ce c0-a6 0f e4 8d f2 50 f2 f6 .;.F.T.......P..
    0010 - 59 61 85 51 50 9e 19 e3-4b 48 3b bf 80 19 70 c7 Ya.QP...KH;...p.
    0020 - 58 1a dc c9 7e f6 7a 69-4c fc 43 f9 68 ea b8 de X...~.ziL.C.h...
    0030 - 79 93 a9 32 49 bf 95 cd-3b cd d1 79 4d 06 ce c1 y..2I...;..yM...
    0040 - fc 37 00 ec f3 4b ae 29-96 16 f2 fe 46 73 91 26 .7...K.)....Fs.&
    0050 - 64 34 7c 9b 8e 40 81 2d-6d 49 ab 0c 79 a4 3a 44 d4|[email protected].:D
    0060 - c8 e2 4b 1d 12 3c 66 72-6c f4 99 14 e0 67 a2 97 ..K..<frl....g..
    0070 - ca a5 21 16 cc df 1d 30-5c 8a 39 54 87 da bf 33 ..!....0\.9T...3
    0080 - fa cd b5 fd e0 81 69 6f-8e aa 36 41 11 15 81 e2 ......io..6A....
    0090 - 96 96 f3 50 06 e1 3b 0c-66 b3 2d 57 e9 c7 af 64 ...P..;.f.-W...d
    00a0 - e9 54 76 3a 75 e2 44 1e-0f 2c f5 3c 4e 9d 3d 60 .Tv:u.D..,.<N.=`

    Start Time: 1744452410
    Timeout : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: yes
    ---
    TLS SUCCESSFUL
    401764DAE37F0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:691:
    Server output:
    spawn openssl s_server -accept 23456 -naccept 1 -key pkcs11:type=private;id=%00%02 -cert pkcs11:type=cert;object=ecCert
    Using default temp DH parameters
    ACCEPT
    -----BEGIN SSL SESSION PARAMETERS----- MF8CAQECAgMDBALAKwQABDDiCob4EZgVezlKUHzKlojrUO0MYypH8M7B1VY12kzD AxsepF9WoCPzoXriSP/vFzKhBgIEZ/o7OqIEAgIcIKQGBAQBAAAArQMCAQGzAwIB
    Fw==
    -----END SSL SESSION PARAMETERS-----
    Shared ciphers:ECDHE-ECDSA-AES128-GCM-SHA256
    Signature Algorithms: ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224:DSA+SHA224:DSA+
    SHA256:DSA+SHA384:DSA+SHA512
    Shared Signature Algorithms: ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224:DSA+SHA224:
    DSA+SHA256:DSA+SHA384:DSA+SHA512
    Supported Elliptic Curve Point Formats: uncompressed:ansiX962_compressed_prime:ansiX962_compressed_char2
    Supported groups: secp256r1
    Shared groups: secp256r1
    CIPHER is ECDHE-ECDSA-AES128-GCM-SHA256
    Secure Renegotiation IS supported
    TLS SUCCESSFUL
    Q
    DONE
    shutdown accept socket
    shutting down SSL
    CONNECTION CLOSED
    0 items in the session cache
    0 client connects (SSL_connect())
    0 client renegotiates (SSL_connect())
    0 client connects that finished
    1 server accepts (SSL_accept())
    0 server renegotiates (SSL_accept())
    1 server accepts that finished
    0 session cache hits
    0 session cache misses
    0 session cache timeouts
    0 callback cache hits
    0 cache full overflows (128 allowed)

    ## Run test with TLS 1.3 and specific suite
    spawn openssl s_client -connect localhost:23456 -CAfile /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/caCert.pem -tls1_3 -ciphersuites TLS_AES_256_GCM_SHA384 -groups secp256r1
    Connecting to ::1
    CONNECTED(00000005)
    Can't use SSL_get_servername
    depth=1 CN=Issuer
    verify return:1
    depth=0 O=PKCS11 Provider, CN=My EC Cert
    verify return:1
    ---
    Certificate chain
    0 s:O=PKCS11 Provider, CN=My EC Cert
    i:CN=Issuer
    a:PKEY: EC, (prime256v1); sigalg: sha256WithRSAEncryption
    v:NotBefore: Apr 12 10:06:36 2025 GMT; NotAfter: Apr 12 10:06:36 2026 GMT ---
    Server certificate
    -----BEGIN CERTIFICATE----- MIICcjCCAVqgAwIBAgIBBDANBgkqhkiG9w0BAQsFADARMQ8wDQYDVQQDEwZJc3N1 ZXIwHhcNMjUwNDEyMTAwNjM2WhcNMjYwNDEyMTAwNjM2WjAvMRgwFgYDVQQKEw9Q S0NTMTEgUHJvdmlkZXIxEzARBgNVBAMTCk15IEVDIENlcnQwWTATBgcqhkjOPQIB BggqhkjOPQMBBwNCAATBhC6Bskae48wDIXJQXRNVcx3n7y90X+kO5StIXCuMPHy1 KKX00cXF6UXUHszjlvS2SMrVZQvJc2WTOiDTiv27o4GBMH8wDAYDVR0TAQH/BAIw ADAfBgNVHREEGDAWgRR0ZXN0Y2VydEBleGFtcGxlLm9yZzAOBgNVHQ8BAf8EBAMC B4AwHQYDVR0OBBYEFL+L0nMF/mpdNL6bGu74hnxx2622MB8GA1UdIwQYMBaAFCyg 8iYK7eejABnMyB2/g2vveKgPMA0GCSqGSIb3DQEBCwUAA4IBAQA50M5wbeBoxn/E X6VGW6QqIvM6rSi+/1e4bPpF3QAWDQDe1dktyIuV+S845UEW0+evWQzNIvPuahXJ gqOHJyTVYJNK2UZHd1P0GMCbnNwAFPuJtbikTG0XXj5mCmDDGfjMDe7f4iB7yoho eXijLDEYcSu9EBSHTKMFl1KHYI59fKsFaG1/vblPeRiXYwGpynuWnS9hiRpM5Bng FVSuHPZaD/CsVje/tqIzp7dx+EVwAmCEbWSLuzM8SvOf7LPU8NJOfUHTKPnq9ul7 UbgGKwA4ITGLF6tuviJ+AXVkF6k/mlEGBU2AeEVrYxsJfIpZ9iUGLRw0DYHX9pXy
    B4KikiF9
    -----END CERTIFICATE-----
    subject=O=PKCS11 Provider, CN=My EC Cert
    issuer=CN=Issuer
    ---
    No client certificate CA names sent
    Peer signing digest: SHA256
    Peer signature type: ecdsa_secp256r1_sha256
    Peer Temp Key: ECDH, prime256v1, 256 bits
    ---
    SSL handshake has read 1055 bytes and written 335 bytes
    Verification: OK
    ---
    New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
    Protocol: TLSv1.3
    Server public key is 256 bit
    This TLS version forbids renegotiation.
    Compression: NONE
    Expansion: NONE
    No ALPN negotiated
    Early data was not sent
    Verify return code: 0 (ok)
    ---
    ---
    Post-Handshake New Session Ticket arrived:
    SSL-Session:
    Protocol : TLSv1.3
    Cipher : TLS_AES_256_GCM_SHA384
    Session-ID: F1A81BDE9E935814B8E13DA256005A1D79B7AD0563B7F998CA9BAB4F765C90EF
    Session-ID-ctx:
    Resumption PSK: ABCBC3D3C9E54565318AA3B6C33286A176A213A2B462489C47BE29082E2C128F51B16AFB14FD006931298FA713B67BC8
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 7200 (seconds)
    TLS session ticket:
    0000 - 1a 92 27 fd 29 64 e1 79-ef d9 c2 88 6f fb d0 4a ..'.)d.y....o..J
    0010 - 72 c5 f0 11 af d2 a8 e7-54 eb a1 dd d9 28 a6 d9 r.......T....(..
    0020 - 89 ed 9b 14 d8 d8 65 0e-c3 b4 c0 6d 87 55 9d 78 ......e....m.U.x
    0030 - 12 2e 03 a7 cf 96 b4 82-26 68 d2 8b aa 27 a8 20 ........&h...'.
    0040 - 84 6b 00 c9 ad 8e 52 71-5b 76 4d 18 8b 81 72 56 .k....Rq[vM...rV
    0050 - 3e 8b 0c e0 63 34 cf f5-79 a4 2b 27 32 d1 86 b8 >...c4..y.+'2...
    0060 - 46 65 6f 7a 02 a7 e2 8d-0d ec 99 b9 d6 c0 a3 b5 Feoz............
    0070 - 8a eb 3e 19 c4 fb 0f 61-8f 18 2a 13 bd 16 3d e6 ..>....a..*...=.
    0080 - ed d6 65 fb 82 71 f3 f3-b9 e0 ca b4 c8 ea 4e db ..e..q........N.
    0090 - 4d fa ca ad 5f 26 e8 e2-41 04 a4 79 6d 08 95 c2 M..._&..A..ym...
    00a0 - be 73 a2 3f c6 9b 07 ef-b0 3b 98 35 12 d0 7b 1b .s.?.....;.5..{.
    00b0 - 3e 8b 61 b6 69 be c9 1c-98 73 3f bd d5 7a 07 77 >.a.i....s?..z.w
    00c0 - 40 9e a8 90 7d 9b 63 d5-8b 5b 8e c7 ee 18 18 ed @...}.c..[......

    Start Time: 1744452410
    Timeout : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: no
    Max Early Data: 0
    ---
    read R BLOCK
    ---
    Post-Handshake New Session Ticket arrived:
    SSL-Session:
    Protocol : TLSv1.3
    Cipher : TLS_AES_256_GCM_SHA384
    Session-ID: 0428FBEEE476C15EA1EF4D566D74658B2C3A3FBF5592F2F488854EDCFC598BFC
    Session-ID-ctx:
    Resumption PSK: DB1758018B055A83973E00DA7E83321D74F37B341BEE6643E5F85317F5B8C8DC97DD56EDDE55BC68BB9541A944346538
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 7200 (seconds)
    TLS session ticket:
    0000 - 1a 92 27 fd 29 64 e1 79-ef d9 c2 88 6f fb d0 4a ..'.)d.y....o..J
    0010 - 21 b5 62 70 f4 de 80 46-5c 66 ae 52 7e 67 be fd !.bp...F\f.R~g..
    0020 - f9 6b 4f 09 da a2 00 42-7f 35 9b 05 b1 4e 9b d8 .kO....B.5...N..
    0030 - 2c b4 37 4c 37 69 c4 63-3e 71 8f 8a b8 e8 8b c8 ,.7L7i.c>q......
    0040 - 6f c6 ae 37 22 84 d4 b4-d2 a9 81 7d ee 68 a5 92 o..7"......}.h..
    0050 - 33 d0 c0 24 3a 74 dc 01-97 ab 13 f8 53 83 af 36 3..$:t......S..6
    0060 - 87 09 70 f0 e6 f3 68 a1-67 2c dc 12 8a ec ec 2e ..p...h.g,......
    0070 - 1f b3 19 87 c6 67 61 14-ec 6c 7b 3e 6f 18 35 0a .....ga..l{>o.5.
    0080 - 8e 55 b7 ff 3c 4a 0a 09-94 14 ec a3 60 ff 07 9c .U..<J......`...
    0090 - 14 95 ca 16 ec 15 d7 5b-76 19 ac f7 87 19 1f 91 .......[v.......
    00a0 - ec 90 7b fa 98 7a db c2-c6 16 7b 4c ba a7 66 62 ..{..z....{L..fb
    00b0 - 1a dc 2e 1e d2 6f 96 02-f4 0f 0b b4 71 b1 c6 d8 .....o......q...
    00c0 - 98 dd a4 f8 5c 7b fa 08-3c 71 b4 f1 db 42 f4 8a ....\{..<q...B..

    Start Time: 1744452410
    Timeout : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: no
    Max Early Data: 0
    ---
    read R BLOCK
    TLS SUCCESSFUL
    40F70A5BC87F0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:691:
    Server output:
    spawn openssl s_server -accept 23456 -naccept 1 -key pkcs11:type=private;id=%00%02 -cert pkcs11:type=cert;object=ecCert
    Using default temp DH parameters
    ACCEPT
    -----BEGIN SSL SESSION PARAMETERS----- MIGCAgEBAgIDBAQCEwIEIPfWdVNxBFPkDAiqK16vyhiv0DBHaOGAIy3rfNGQCh8F BDDbF1gBiwVag5c+ANp+gzIddPN7NBvuZkPl+FMX9bjI3JfdVu3eVbxou5VBqUQ0 ZTihBgIEZ/o7OqIEAgIcIKQGBAQBAAAArgYCBHtj+TWzAwIBFw==
    -----END SSL SESSION PARAMETERS-----
    Shared ciphers:TLS_AES_256_GCM_SHA384
    Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_
    sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512
    Shared Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_
    pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512
    Supported groups: secp256r1
    Shared groups: secp256r1
    CIPHER is TLS_AES_256_GCM_SHA384
    This TLS version forbids renegotiation.
    TLS SUCCESSFUL
    Q
    DONE
    shutdown accept socket
    shutting down SSL
    CONNECTION CLOSED
    0 items in the session cache
    0 client connects (SSL_connect())
    0 client renegotiates (SSL_connect())
    0 client connects that finished
    1 server accepts (SSL_accept())
    0 server renegotiates (SSL_accept())
    1 server accepts that finished
    0 session cache hits
    0 session cache misses
    0 session cache timeouts
    0 callback cache hits
    0 cache full overflows (128 allowed)

    ## ########################################

    ########################################
    ## Forcing the provider for all server operations


    ## Run sanity test with default values (RSA)
    spawn openssl s_client -propquery ?provider=pkcs11 -connect localhost:23456 -CAfile /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/caCert.pem
    Connecting to ::1
    CONNECTED(00000005)
    Can't use SSL_get_servername
    depth=1 CN=Issuer
    verify return:1
    depth=0 O=PKCS11 Provider, CN=My Test Cert
    verify return:1
    ---
    Certificate chain
    0 s:O=PKCS11 Provider, CN=My Test Cert
    i:CN=Issuer
    a:PKEY: RSA, 2048 (bit); sigalg: sha256WithRSAEncryption
    v:NotBefore: Apr 12 10:06:36 2025 GMT; NotAfter: Apr 12 10:06:36 2026 GMT ---
    Server certificate
    -----BEGIN CERTIFICATE----- MIIDPzCCAiegAwIBAgIBAzANBgkqhkiG9w0BAQsFADARMQ8wDQYDVQQDEwZJc3N1 ZXIwHhcNMjUwNDEyMTAwNjM2WhcNMjYwNDEyMTAwNjM2WjAxMRgwFgYDVQQKEw9Q S0NTMTEgUHJvdmlkZXIxFTATBgNVBAMTDE15IFRlc3QgQ2VydDCCASIwDQYJKoZI hvcNAQEBBQADggEPADCCAQoCggEBAMcui28zjpBTCQCCyxI2Su9brj5yxKb/ccI3 u9ipO7YCde7wVVPpjCZzXIzUmqpQ3tke+2YyBHjqcIeBJnvB+xKt6Oq6sHQ6IKL4 5dt3Vhj8Lvc/nyOFWOjJmeQLJGJvYn+ohqWIQ4Bk/3H9RDsLuam22mJ3LlHPZWcZ 2JAGyOvpZ94mrVcFXbwezCkK8kEoBCR/IZmCT7gWOFrWFEJ21JuWkyr7WZ0xaaNR 9O8EdMZBIZJ4scADmIiDn/rZ7UGQ98fC6RcCJUfZr9SG0JrGzv2ovGECF+Gd1ohT k2QV9xZ/HtV30iVD5slTfapS07ia281Q0f82YNQpgQrgvCuF+vECAwEAAaOBgTB/ MAwGA1UdEwEB/wQCMAAwHwYDVR0RBBgwFoEUdGVzdGNlcnRAZXhhbXBsZS5vcmcw DgYDVR0PAQH/BAQDAgWgMB0GA1UdDgQWBBT0OHyt6wRKSITgknAIlOweeCNYGzAf BgNVHSMEGDAWgBQsoPImCu3nowAZzMgdv4Nr73ioDzANBgkqhkiG9w0BAQsFAAOC AQEAFzMqwcTSQ5mo130cP1oP16oECeUzEDkLJipwEg3aj+3XzagczgGjdgoNqkdH 9swEEivllD3Icrm1/cdqxWeAo8ys0PdFTMfZOqu0eHdIZmW7pV8gGXsIj+V4BWoT CKOsjfJ/rFU1emy8e+ct79VyUI2BxRJPoTKdM9qaYn5c9joC6znKi1tXN5OUho5A ae+VMWvq3crGQEDN2slPPyo56YDl1rhGFY4/pZPy0X7O2EWJzzpSJbq4M0kiXdqA YS+n/1WOx57LgfCl4VDfeZpr8VngfTC+UqCBhKCEASfshkxl9wZ0XlNEn3DxA2c/ rX/Xw3YYk1eMaw1wZ1FuP3hKXw==
    -----END CERTIFICATE-----
    subject=O=PKCS11 Provider, CN=My Test Cert
    issuer=CN=Issuer
    ---
    No client certificate CA names sent
    Peer signing digest: SHA256
    Peer signature type: rsa_pss_rsae_sha256
    Negotiated TLS1.3 group: X25519MLKEM768
    ---
    SSL handshake has read 2479 bytes and written 1613 bytes
    Verification: OK
    ---
    New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
    Protocol: TLSv1.3
    Server public key is 2048 bit
    This TLS version forbids renegotiation.
    Compression: NONE
    Expansion: NONE
    No ALPN negotiated
    Early data was not sent
    Verify return code: 0 (ok)
    ---
    ---
    Post-Handshake New Session Ticket arrived:
    SSL-Session:
    Protocol : TLSv1.3
    Cipher : TLS_AES_256_GCM_SHA384
    Session-ID: 74D20B9A3C2CE206948F0AAAB7DA3637F53A155361CD9DD81032D01875B0738C
    Session-ID-ctx:
    Resumption PSK: 377FA270A7536FE1D260B8E989748582F54C47FDC7F6A9102621E3EB9122A015F3B692609A84E914BE71CA6E202CA586
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 7200 (seconds)
    TLS session ticket:
    0000 - 6b 12 65 7a fb 5d 68 16-80 43 cc 33 0d 1d 4f de k.ez.]h..C.3..O.
    0010 - 35 61 6e 45 23 26 87 5e-01 da 64 76 c5 f5 0b 05 5anE#&.^..dv....
    0020 - f6 81 c8 5b e0 d3 b4 c2-35 4c 32 77 75 07 36 3e ...[....5L2wu.6>
    0030 - 63 5b 0a b0 b6 05 3d 4b-94 99 9f 4d bf cc 71 25 c[....=K...M..q%
    0040 - 4e f1 cf 24 12 d3 81 99-8f 9b 76 a0 b0 44 25 e5 N..$......v..D%.
    0050 - ee 47 ca 70 27 f0 1b c7-d5 48 7a df c4 19 3f a3 .G.p'....Hz...?.
    0060 - 57 09 44 de f4 7a 20 00-d6 56 24 cc 08 03 2d f3 W.D..z ..V$...-.
    0070 - f5 bd 95 1a 8e 89 1d 26-25 85 95 38 f7 a3 8c ed .......&%..8....
    0080 - 07 8b c6 ba 94 e2 8f 02-79 4c ce 46 14 49 33 6d ........yL.F.I3m
    0090 - cd ca 81 2e c2 68 5c 5d-92 cf 84 cf 88 2f ce a6 .....h\]...../..
    00a0 - 71 f4 9d 16 8c e2 9a d6-e9 62 3b 1b bf 81 ab d7 q........b;.....
    00b0 - 94 57 af 86 7e 5b 93 b1-be 69 53 88 c7 96 c3 d9 .W..~[...iS.....
    00c0 - 06 50 87 6a 05 f5 09 90-5d 51 be c8 92 5b c3 45 .P.j....]Q...[.E

    Start Time: 1744452410
    Timeout : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: no
    Max Early Data: 0
    ---
    read R BLOCK
    ---
    Post-Handshake New Session Ticket arrived:
    SSL-Session:
    Protocol : TLSv1.3
    Cipher : TLS_AES_256_GCM_SHA384
    Session-ID: B5769987216926D44BF0FF08F8A2B227FCC7789840356837729C71E56BDE4E03
    Session-ID-ctx:
    Resumption PSK: 550096427F893A242B6AD10E60B9B238AA95440309D1E78DD24B9DF6BD1536D16FE073EB8A8425939C100650CE3727DF
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 7200 (seconds)
    TLS session ticket:
    0000 - 6b 12 65 7a fb 5d 68 16-80 43 cc 33 0d 1d 4f de k.ez.]h..C.3..O.
    0010 - 8e 1d 5d 08 32 0d c1 f0-fb 94 78 7e 6a 08 7c b8 ..].2.....x~j.|.
    0020 - 55 f2 f9 1c 4c 03 11 1a-fa 5c 6b 64 0c 53 b0 88 U...L....\kd.S..
    0030 - ac 85 76 c4 eb 26 e4 bf-c7 ba 2b 8a 54 74 ad 72 ..v..&....+.Tt.r
    0040 - 55 3f 0a 32 3b e8 fc e3-49 26 ec 67 4c c5 68 1a U?.2;...I&.gL.h.
    0050 - 42 89 f2 ac 83 a1 ea 8b-8e b3 43 8f e8 33 41 d8 B.........C..3A.
    0060 - d8 6a 85 96 6d ad 50 fe-23 e9 55 c9 40 8d 9c 96 .j..m.P.#.U.@...
    0070 - 5c 02 30 9b c6 4d 8e f7-5b bc c8 36 99 07 88 67 \.0..M..[..6...g
    0080 - 0c e1 a6 00 78 10 be 26-99 93 6e a9 c1 86 01 ca ....x..&..n.....
    0090 - ca e1 5f b8 1f ca 9c 0c-a4 da 7b 2f a1 71 d7 e9 .._.......{/.q..
    00a0 - 48 b9 1d fe 9e a4 1f 69-e5 a9 e6 3e 3d 83 f8 65 H......i...>=..e
    00b0 - f9 9f fd f0 1e 42 a1 72-47 13 3b 5c 4a 34 cd 70 .....B.rG.;\J4.p
    00c0 - 90 e1 a6 b4 4a 45 31 70-6e 88 63 40 38 3a b4 9d ....JE1pn.c@8:..

    Start Time: 1744452410
    Timeout : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: no
    Max Early Data: 0
    ---
    read R BLOCK
    TLS SUCCESSFUL
    402704BBE27F0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:691:
    Server output:
    spawn openssl s_server -propquery ?provider=pkcs11 -accept 23456 -naccept 1 -key pkcs11:type=private;id=%00%01 -cert pkcs11:type=cert;object=testCert
    Using default temp DH parameters
    ACCEPT
    -----BEGIN SSL SESSION PARAMETERS----- MIGDAgEBAgIDBAQCEwIEIIG2NcJHM1/kRk1Mg9kab4cvC+a6Qd5yTaOaviboffb8 BDBVAJZCf4k6JCtq0Q5gubI4qpVEAwnR543SS532vRU20W/gc+uKhCWTnBAGUM43 J9+hBgIEZ/o7OqIEAgIcIKQGBAQBAAAArgYCBD4Co9mzBAICEew=
    -----END SSL SESSION PARAMETERS-----
    Shared ciphers:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-CHACHA20-
    POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:DHE-RSA-AES256-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA256:ECDHE-ECDSA-
    AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES256-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA
    Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_
    sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224:DSA+SHA224:DSA+SHA256:DSA+SHA384:DSA+SHA512
    Shared Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_
    pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224
    Supported groups: X25519MLKEM768:x25519:secp256r1:x448:secp384r1:secp521r1:ffdhe2048:ffdhe3072
    Shared groups: X25519MLKEM768:x25519:secp256r1:x448:secp384r1:secp521r1:ffdhe2048:ffdhe3072
    CIPHER is TLS_AES_256_GCM_SHA384
    This TLS version forbids renegotiation.
    TLS SUCCESSFUL
    Q
    DONE
    shutdown accept socket
    shutting down SSL
    CONNECTION CLOSED
    0 items in the session cache
    0 client connects (SSL_connect())
    0 client renegotiates (SSL_connect())
    0 client connects that finished
    1 server accepts (SSL_accept())
    0 server renegotiates (SSL_accept())
    1 server accepts that finished
    0 session cache hits
    0 session cache misses
    0 session cache timeouts
    0 callback cache hits
    0 cache full overflows (128 allowed)

    ## Run sanity test with default values (RSA-PSS)

    ## Generating a new selfsigned certificate for pkcs11:type=private;id=%00%10
    openssl req -batch -noenc -x509 -new -key ${KEY} ${AARGS} -out ${CERT}


    spawn openssl s_client -propquery ?provider=pkcs11 -connect localhost:23456 -CAfile /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/caCert.pem
    Connecting to ::1
    CONNECTED(00000005)
    Can't use SSL_get_servername
    depth=0 C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness verify error:num=18:self-signed certificate
    verify return:1
    depth=0 C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness verify return:1
    ---
    Certificate chain
    0 s:C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness
    i:C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness
    a:PKEY: RSA-PSS, 2048 (bit); sigalg: rsassaPss
    v:NotBefore: Apr 12 10:06:50 2025 GMT; NotAfter: May 12 10:06:50 2025 GMT ---
    Server certificate
    -----BEGIN CERTIFICATE----- MIIEIzCCAtugAwIBAgIUJqjLDrmE19BW6ScGitbuzEsUzTQwPQYJKoZIhvcNAQEK MDCgDTALBglghkgBZQMEAgGhGjAYBgkqhkiG9w0BAQgwCwYJYIZIAWUDBAIBogMC ASAwZzELMAkGA1UEBhMCVVMxETAPBgNVBAgMCE5ldyBZb3JrMREwDwYDVQQHDAhO ZXcgWW9yazEYMBYGA1UECgwPUEtDUzExIFByb3ZpZGVyMRgwFgYDVQQLDA9UZXN0 aW5nIEhhcm5lc3MwHhcNMjUwNDEyMTAwNjUwWhcNMjUwNTEyMTAwNjUwWjBnMQsw CQYDVQQGEwJVUzERMA8GA1UECAwITmV3IFlvcmsxETAPBgNVBAcMCE5ldyBZb3Jr MRgwFgYDVQQKDA9QS0NTMTEgUHJvdmlkZXIxGDAWBgNVBAsMD1Rlc3RpbmcgSGFy bmVzczCCASAwCwYJKoZIhvcNAQEKA4IBDwAwggEKAoIBAQCRj1VYA16PESIIha4Q MkpJn2gxwKuOLUeV+nar521mYf1G+bbw/DOzOQR8GvPHV07vufeeyT+DWxQY+yeG mAA2lVFl5S4Yo4jAimMJn0F6PYUZFTYIhVegdqi1MZVRbUmpX/ZXdIzCsQoP6RWC EiipLuZdy8qqWvKF5lIHaDE5FIQLic+kqHDaWlGDIifSXqYHRHl7AiizchnWHFi5 +fBw4+xcQhV4DlMTtVZVJfqvIjHwQ+xa5m4c47Ec6QYtOcvRsZWJJHQ8dVdW8zaV GwZOZwbV+qlzcT85SPcaOWoHeU9d4Wp0My7XHCKawtJBmpsxcxS6hVm1SJmaWBEF YvSzAgMBAAGjaTBnMB0GA1UdDgQWBBRW3mUaJI4DQHtI6oxGkehI59ZW9DAfBgNV HSMEGDAWgBRW3mUaJI4DQHtI6oxGkehI59ZW9DAPBgNVHRMBAf8EBTADAQH/MAkG A1UdEQQCMAAwCQYDVR0SBAIwADA9BgkqhkiG9w0BAQowMKANMAsGCWCGSAFlAwQC AaEaMBgGCSqGSIb3DQEBCDALBglghkgBZQMEAgGiAwIBIAOCAQEAJQgf4EaLek1R +wnJ1PUGGg8t4Ze1BwJkMB2SDd/c8PV5074c9yYyb9PHC1288GrOhmGIV3YdHy8J RzIZpGhtasuSsofheCllFq4Z+wKcQ8FpB9Xe+pet4gBYv2s1F4TzmC3HiUdGgfDL JC310bz/r3FDVKHGvAciyuHQQUu3NhvwBCbzIP/UGfsU4aqXI9uLoLljMNfYFRGX Thxz7JvwZjkBo4O1qQ469XSoIOoHox6TN0242ucHiwdQziqucYptvK+CL97ppuUc gBW/pDpo1aW0aFlWcEE1PbY99Vm9z9kcMrBiIYrxeQ7JSLBiakT5LwrildPMOHvh
    Ofu/wRFQTg==
    -----END CERTIFICATE-----
    subject=C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness issuer=C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness ---
    No client certificate CA names sent
    Peer signing digest: SHA256
    Peer signature type: rsa_pss_pss_sha256
    Negotiated TLS1.3 group: X25519MLKEM768
    ---
    SSL handshake has read 2707 bytes and written 1613 bytes
    Verification error: self-signed certificate
    ---
    New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
    Protocol: TLSv1.3
    Server public key is 2048 bit
    This TLS version forbids renegotiation.
    Compression: NONE
    Expansion: NONE
    No ALPN negotiated
    Early data was not sent
    Verify return code: 18 (self-signed certificate)
    ---
    ---
    Post-Handshake New Session Ticket arrived:
    SSL-Session:
    Protocol : TLSv1.3
    Cipher : TLS_AES_256_GCM_SHA384
    Session-ID: 97D37B33CAAF12747CA697C0C65B200871AB1DD63623D5A6D7592AA374D40035
    Session-ID-ctx:
    Resumption PSK: 6EE4F4F4D8A2CDAE2DC79C938C0F0B9C9DBD6AE0E4A0C5BB20FC0C1B585BDD736DA0E24F9AD6C5979F0C5D3F814DBCD1
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 7200 (seconds)
    TLS session ticket:
    0000 - 57 67 c2 d2 19 9f ef 36-15 55 41 80 b1 1c a6 b2 Wg.....6.UA.....
    0010 - dd 0b ce a3 19 6b 5c 59-ee b4 20 a7 b6 87 39 fe .....k\Y.. ...9.
    0020 - cf a6 ac 0c 65 81 42 c7-dd 4f 83 7a c5 f6 50 2a ....e.B..O.z..P*
    0030 - 28 8e f4 35 d2 2e ef 8a-59 28 28 2e d5 b0 98 45 (..5....Y((....E
    0040 - 5c 58 43 09 b2 d1 04 75-4a ef d5 19 75 cd 74 03 \XC....uJ...u.t.
    0050 - 61 98 0b 3a 7b df f6 01-56 2f 59 8b 02 f5 dc 2f a..:{...V/Y..../
    0060 - d7 0d 28 35 4e 06 8f d0-09 2b a6 e8 56 53 b3 02 ..(5N....+..VS..
    0070 - cd 8c f7 a2 80 05 45 28-7c 14 28 a3 89 f9 82 50 ......E(|.(....P
    0080 - 49 5d 0f 11 a5 b1 d1 a1-f4 ef 19 8d ab 48 15 77 I]...........H.w
    0090 - 00 83 6f ae 84 8f fe e5-cb f1 0d 27 94 fb e3 ad ..o........'....
    00a0 - f4 4b 53 5b 59 96 28 2a-32 9e b1 41 fa d1 8e 68 .KS[Y.(*2..A...h
    00b0 - c1 c6 6d 02 fe 09 c9 bb-28 46 ec cd e9 94 7e 79 ..m.....(F....~y
    00c0 - fc 29 08 0b bc 01 7a 86-a9 5e 80 ae 54 b4 55 f2 .)....z..^..T.U.

    Start Time: 1744452410
    Timeout : 7200 (sec)
    Verify return code: 18 (self-signed certificate)
    Extended master secret: no
    Max Early Data: 0
    ---
    read R BLOCK
    ---
    Post-Handshake New Session Ticket arrived:
    SSL-Session:
    Protocol : TLSv1.3
    Cipher : TLS_AES_256_GCM_SHA384
    Session-ID: 44AC5BA8FFC1BF0D0766A09ABEBE658673D61181E43A0DD60FED63C1A713E666
    Session-ID-ctx:
    Resumption PSK: 8539D2A89D61B5B8C79CC889A37547158DD1A6DA177B24C881CA100DB32A9A272AD0AE8CE3B8C3E4A0E0598CD4BEA5C9
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 7200 (seconds)
    TLS session ticket:
    0000 - 57 67 c2 d2 19 9f ef 36-15 55 41 80 b1 1c a6 b2 Wg.....6.UA.....
    0010 - 9e 50 27 0f 7d 3c ed b1-09 01 ca 7c 13 b2 17 cd .P'.}<.....|....
    0020 - 27 8f 1c a2 ca 85 37 7d-c8 53 91 7b 13 af 6d d3 '.....7}.S.{..m.
    0030 - aa 53 3a 5b c7 8f 4a 07-d8 82 c4 2e be bf ff 16 .S:[..J.........
    0040 - cc 04 de d4 13 b0 bc 6f-6d 8c be bf 9d 6a b7 9f .......om....j..
    0050 - b8 6d 70 48 09 39 01 99-82 03 c7 38 15 73 6f 10 .mpH.9.....8.so.
    0060 - b8 58 cc be c4 cb b9 6c-13 bd ec 37 b7 55 55 53 .X.....l...7.UUS
    0070 - 0c 95 8b a7 ae 6b 0b 3a-ed 66 32 3b 51 0e 2e 43 .....k.:.f2;Q..C
    0080 - 8c 08 b6 9a 69 42 55 e3-d6 cd a1 ec 8b 3b b8 2b ....iBU......;.+
    0090 - 12 c3 4a 7d 7a fb fc 35-85 b3 09 f6 09 52 33 9e ..J}z..5.....R3.
    00a0 - fc 39 f8 01 ab c5 12 59-a4 c1 9e af de 17 fe fc .9.....Y........
    00b0 - 85 36 4b 28 99 07 3e 53-ed 3a 66 a1 4d 13 88 8d .6K(..>S.:f.M...
    00c0 - dd d2 4c 5c a4 d5 f9 f4-fd e5 c7 3a 0c 04 ed 53 ..L\.......:...S

    Start Time: 1744452410
    Timeout : 7200 (sec)
    Verify return code: 18 (self-signed certificate)
    Extended master secret: no
    Max Early Data: 0
    ---
    read R BLOCK
    TLS SUCCESSFUL
    400724796C7F0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:691:
    Server output:
    spawn openssl s_server -propquery ?provider=pkcs11 -accept 23456 -naccept 1 -key pkcs11:type=private;id=%00%10 -cert /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/rsapss-default.pem
    Using default temp DH parameters
    ACCEPT
    -----BEGIN SSL SESSION PARAMETERS----- MIGDAgEBAgIDBAQCEwIEICOeuFLKzmUV9XAB8b5Ixw5fmTDEkaudmDpgKMvxlJCe BDCFOdKonWG1uMecyImjdUcVjdGm2hd7JMiByhANsyqaJyrQrozjuMPkoOBZjNS+ pcmhBgIEZ/o7OqIEAgIcIKQGBAQBAAAArgYCBE3JgS2zBAICEew=
    -----END SSL SESSION PARAMETERS-----
    Shared ciphers:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-CHACHA20-
    POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:DHE-RSA-AES256-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA256:ECDHE-ECDSA-
    AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES256-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA
    Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_
    sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224:DSA+SHA224:DSA+SHA256:DSA+SHA384:DSA+SHA512
    Shared Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_
    pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224
    Supported groups: X25519MLKEM768:x25519:secp256r1:x448:secp384r1:secp521r1:ffdhe2048:ffdhe3072
    Shared groups: X25519MLKEM768:x25519:secp256r1:x448:secp384r1:secp521r1:ffdhe2048:ffdhe3072
    CIPHER is TLS_AES_256_GCM_SHA384
    This TLS version forbids renegotiation.
    TLS SUCCESSFUL
    Q
    DONE
    shutdown accept socket
    shutting down SSL
    CONNECTION CLOSED
    0 items in the session cache
    0 client connects (SSL_connect())
    0 client renegotiates (SSL_connect())
    0 client connects that finished
    1 server accepts (SSL_accept())
    0 server renegotiates (SSL_accept())
    1 server accepts that finished
    0 session cache hits
    0 session cache misses
    0 session cache timeouts
    0 callback cache hits
    0 cache full overflows (128 allowed)

    ## Run sanity test with RSA-PSS and SHA256

    ## Generating a new selfsigned certificate for pkcs11:type=private;id=%00%11
    openssl req -batch -noenc -x509 -new -key ${KEY} ${AARGS} -out ${CERT}


    spawn openssl s_client -propquery ?provider=pkcs11 -connect localhost:23456 -CAfile /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/caCert.pem
    Connecting to ::1
    CONNECTED(00000005)
    Can't use SSL_get_servername
    depth=0 C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness verify error:num=18:self-signed certificate
    verify return:1
    depth=0 C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness verify return:1
    ---

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)