[continued from previous message]
v:NotBefore: Apr 12 10:06:36 2025 GMT; NotAfter: Apr 12 10:06:36 2026 GMT ---
Server certificate
-----BEGIN CERTIFICATE----- MIICcjCCAVqgAwIBAgIBBDANBgkqhkiG9w0BAQsFADARMQ8wDQYDVQQDEwZJc3N1 ZXIwHhcNMjUwNDEyMTAwNjM2WhcNMjYwNDEyMTAwNjM2WjAvMRgwFgYDVQQKEw9Q S0NTMTEgUHJvdmlkZXIxEzARBgNVBAMTCk15IEVDIENlcnQwWTATBgcqhkjOPQIB BggqhkjOPQMBBwNCAATBhC6Bskae48wDIXJQXRNVcx3n7y90X+kO5StIXCuMPHy1 KKX00cXF6UXUHszjlvS2SMrVZQvJc2WTOiDTiv27o4GBMH8wDAYDVR0TAQH/BAIw ADAfBgNVHREEGDAWgRR0ZXN0Y2VydEBleGFtcGxlLm9yZzAOBgNVHQ8BAf8EBAMC B4AwHQYDVR0OBBYEFL+L0nMF/mpdNL6bGu74hnxx2622MB8GA1UdIwQYMBaAFCyg 8iYK7eejABnMyB2/g2vveKgPMA0GCSqGSIb3DQEBCwUAA4IBAQA50M5wbeBoxn/E X6VGW6QqIvM6rSi+/1e4bPpF3QAWDQDe1dktyIuV+S845UEW0+evWQzNIvPuahXJ gqOHJyTVYJNK2UZHd1P0GMCbnNwAFPuJtbikTG0XXj5mCmDDGfjMDe7f4iB7yoho eXijLDEYcSu9EBSHTKMFl1KHYI59fKsFaG1/vblPeRiXYwGpynuWnS9hiRpM5Bng FVSuHPZaD/CsVje/tqIzp7dx+EVwAmCEbWSLuzM8SvOf7LPU8NJOfUHTKPnq9ul7 UbgGKwA4ITGLF6tuviJ+AXVkF6k/mlEGBU2AeEVrYxsJfIpZ9iUGLRw0DYHX9pXy
B4KikiF9
-----END CERTIFICATE-----
subject=O=PKCS11 Provider, CN=My EC Cert
issuer=CN=Issuer
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: ecdsa_secp256r1_sha256
Peer Temp Key: ECDH, prime256v1, 256 bits
---
SSL handshake has read 1120 bytes and written 257 bytes
Verification: OK
---
New, TLSv1.2, Cipher is ECDHE-ECDSA-AES128-GCM-SHA256
Protocol: TLSv1.2
Server public key is 256 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1.2
Cipher : ECDHE-ECDSA-AES128-GCM-SHA256
Session-ID: 76D136B343E49A29F2D5ECB96C62B2589F4CF413C03CC00000C9A602249E314D
Session-ID-ctx:
Master-Key: E20A86F81198157B394A507CCA9688EB50ED0C632A47F0CEC1D55635DA4CC3031B1EA45F56A023F3A17AE248FFEF1732
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket:
0000 - c2 3b af 46 cc 54 ce c0-a6 0f e4 8d f2 50 f2 f6 .;.F.T.......P..
0010 - 59 61 85 51 50 9e 19 e3-4b 48 3b bf 80 19 70 c7 Ya.QP...KH;...p.
0020 - 58 1a dc c9 7e f6 7a 69-4c fc 43 f9 68 ea b8 de X...~.ziL.C.h...
0030 - 79 93 a9 32 49 bf 95 cd-3b cd d1 79 4d 06 ce c1 y..2I...;..yM...
0040 - fc 37 00 ec f3 4b ae 29-96 16 f2 fe 46 73 91 26 .7...K.)....Fs.&
0050 - 64 34 7c 9b 8e 40 81 2d-6d 49 ab 0c 79 a4 3a 44 d4|[email protected].:D
0060 - c8 e2 4b 1d 12 3c 66 72-6c f4 99 14 e0 67 a2 97 ..K..<frl....g..
0070 - ca a5 21 16 cc df 1d 30-5c 8a 39 54 87 da bf 33 ..!....0\.9T...3
0080 - fa cd b5 fd e0 81 69 6f-8e aa 36 41 11 15 81 e2 ......io..6A....
0090 - 96 96 f3 50 06 e1 3b 0c-66 b3 2d 57 e9 c7 af 64 ...P..;.f.-W...d
00a0 - e9 54 76 3a 75 e2 44 1e-0f 2c f5 3c 4e 9d 3d 60 .Tv:u.D..,.<N.=`
Start Time: 1744452410
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: yes
---
TLS SUCCESSFUL
401764DAE37F0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:691:
Server output:
spawn openssl s_server -accept 23456 -naccept 1 -key pkcs11:type=private;id=%00%02 -cert pkcs11:type=cert;object=ecCert
Using default temp DH parameters
ACCEPT
-----BEGIN SSL SESSION PARAMETERS----- MF8CAQECAgMDBALAKwQABDDiCob4EZgVezlKUHzKlojrUO0MYypH8M7B1VY12kzD AxsepF9WoCPzoXriSP/vFzKhBgIEZ/o7OqIEAgIcIKQGBAQBAAAArQMCAQGzAwIB
Fw==
-----END SSL SESSION PARAMETERS-----
Shared ciphers:ECDHE-ECDSA-AES128-GCM-SHA256
Signature Algorithms: ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224:DSA+SHA224:DSA+
SHA256:DSA+SHA384:DSA+SHA512
Shared Signature Algorithms: ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224:DSA+SHA224:
DSA+SHA256:DSA+SHA384:DSA+SHA512
Supported Elliptic Curve Point Formats: uncompressed:ansiX962_compressed_prime:ansiX962_compressed_char2
Supported groups: secp256r1
Shared groups: secp256r1
CIPHER is ECDHE-ECDSA-AES128-GCM-SHA256
Secure Renegotiation IS supported
TLS SUCCESSFUL
Q
DONE
shutdown accept socket
shutting down SSL
CONNECTION CLOSED
0 items in the session cache
0 client connects (SSL_connect())
0 client renegotiates (SSL_connect())
0 client connects that finished
1 server accepts (SSL_accept())
0 server renegotiates (SSL_accept())
1 server accepts that finished
0 session cache hits
0 session cache misses
0 session cache timeouts
0 callback cache hits
0 cache full overflows (128 allowed)
## Run test with TLS 1.3 and specific suite
spawn openssl s_client -connect localhost:23456 -CAfile /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/caCert.pem -tls1_3 -ciphersuites TLS_AES_256_GCM_SHA384 -groups secp256r1
Connecting to ::1
CONNECTED(00000005)
Can't use SSL_get_servername
depth=1 CN=Issuer
verify return:1
depth=0 O=PKCS11 Provider, CN=My EC Cert
verify return:1
---
Certificate chain
0 s:O=PKCS11 Provider, CN=My EC Cert
i:CN=Issuer
a:PKEY: EC, (prime256v1); sigalg: sha256WithRSAEncryption
v:NotBefore: Apr 12 10:06:36 2025 GMT; NotAfter: Apr 12 10:06:36 2026 GMT ---
Server certificate
-----BEGIN CERTIFICATE----- MIICcjCCAVqgAwIBAgIBBDANBgkqhkiG9w0BAQsFADARMQ8wDQYDVQQDEwZJc3N1 ZXIwHhcNMjUwNDEyMTAwNjM2WhcNMjYwNDEyMTAwNjM2WjAvMRgwFgYDVQQKEw9Q S0NTMTEgUHJvdmlkZXIxEzARBgNVBAMTCk15IEVDIENlcnQwWTATBgcqhkjOPQIB BggqhkjOPQMBBwNCAATBhC6Bskae48wDIXJQXRNVcx3n7y90X+kO5StIXCuMPHy1 KKX00cXF6UXUHszjlvS2SMrVZQvJc2WTOiDTiv27o4GBMH8wDAYDVR0TAQH/BAIw ADAfBgNVHREEGDAWgRR0ZXN0Y2VydEBleGFtcGxlLm9yZzAOBgNVHQ8BAf8EBAMC B4AwHQYDVR0OBBYEFL+L0nMF/mpdNL6bGu74hnxx2622MB8GA1UdIwQYMBaAFCyg 8iYK7eejABnMyB2/g2vveKgPMA0GCSqGSIb3DQEBCwUAA4IBAQA50M5wbeBoxn/E X6VGW6QqIvM6rSi+/1e4bPpF3QAWDQDe1dktyIuV+S845UEW0+evWQzNIvPuahXJ gqOHJyTVYJNK2UZHd1P0GMCbnNwAFPuJtbikTG0XXj5mCmDDGfjMDe7f4iB7yoho eXijLDEYcSu9EBSHTKMFl1KHYI59fKsFaG1/vblPeRiXYwGpynuWnS9hiRpM5Bng FVSuHPZaD/CsVje/tqIzp7dx+EVwAmCEbWSLuzM8SvOf7LPU8NJOfUHTKPnq9ul7 UbgGKwA4ITGLF6tuviJ+AXVkF6k/mlEGBU2AeEVrYxsJfIpZ9iUGLRw0DYHX9pXy
B4KikiF9
-----END CERTIFICATE-----
subject=O=PKCS11 Provider, CN=My EC Cert
issuer=CN=Issuer
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: ecdsa_secp256r1_sha256
Peer Temp Key: ECDH, prime256v1, 256 bits
---
SSL handshake has read 1055 bytes and written 335 bytes
Verification: OK
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Protocol: TLSv1.3
Server public key is 256 bit
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: F1A81BDE9E935814B8E13DA256005A1D79B7AD0563B7F998CA9BAB4F765C90EF
Session-ID-ctx:
Resumption PSK: ABCBC3D3C9E54565318AA3B6C33286A176A213A2B462489C47BE29082E2C128F51B16AFB14FD006931298FA713B67BC8
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket:
0000 - 1a 92 27 fd 29 64 e1 79-ef d9 c2 88 6f fb d0 4a ..'.)d.y....o..J
0010 - 72 c5 f0 11 af d2 a8 e7-54 eb a1 dd d9 28 a6 d9 r.......T....(..
0020 - 89 ed 9b 14 d8 d8 65 0e-c3 b4 c0 6d 87 55 9d 78 ......e....m.U.x
0030 - 12 2e 03 a7 cf 96 b4 82-26 68 d2 8b aa 27 a8 20 ........&h...'.
0040 - 84 6b 00 c9 ad 8e 52 71-5b 76 4d 18 8b 81 72 56 .k....Rq[vM...rV
0050 - 3e 8b 0c e0 63 34 cf f5-79 a4 2b 27 32 d1 86 b8 >...c4..y.+'2...
0060 - 46 65 6f 7a 02 a7 e2 8d-0d ec 99 b9 d6 c0 a3 b5 Feoz............
0070 - 8a eb 3e 19 c4 fb 0f 61-8f 18 2a 13 bd 16 3d e6 ..>....a..*...=.
0080 - ed d6 65 fb 82 71 f3 f3-b9 e0 ca b4 c8 ea 4e db ..e..q........N.
0090 - 4d fa ca ad 5f 26 e8 e2-41 04 a4 79 6d 08 95 c2 M..._&..A..ym...
00a0 - be 73 a2 3f c6 9b 07 ef-b0 3b 98 35 12 d0 7b 1b .s.?.....;.5..{.
00b0 - 3e 8b 61 b6 69 be c9 1c-98 73 3f bd d5 7a 07 77 >.a.i....s?..z.w
00c0 - 40 9e a8 90 7d 9b 63 d5-8b 5b 8e c7 ee 18 18 ed @...}.c..[......
Start Time: 1744452410
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: 0428FBEEE476C15EA1EF4D566D74658B2C3A3FBF5592F2F488854EDCFC598BFC
Session-ID-ctx:
Resumption PSK: DB1758018B055A83973E00DA7E83321D74F37B341BEE6643E5F85317F5B8C8DC97DD56EDDE55BC68BB9541A944346538
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket:
0000 - 1a 92 27 fd 29 64 e1 79-ef d9 c2 88 6f fb d0 4a ..'.)d.y....o..J
0010 - 21 b5 62 70 f4 de 80 46-5c 66 ae 52 7e 67 be fd !.bp...F\f.R~g..
0020 - f9 6b 4f 09 da a2 00 42-7f 35 9b 05 b1 4e 9b d8 .kO....B.5...N..
0030 - 2c b4 37 4c 37 69 c4 63-3e 71 8f 8a b8 e8 8b c8 ,.7L7i.c>q......
0040 - 6f c6 ae 37 22 84 d4 b4-d2 a9 81 7d ee 68 a5 92 o..7"......}.h..
0050 - 33 d0 c0 24 3a 74 dc 01-97 ab 13 f8 53 83 af 36 3..$:t......S..6
0060 - 87 09 70 f0 e6 f3 68 a1-67 2c dc 12 8a ec ec 2e ..p...h.g,......
0070 - 1f b3 19 87 c6 67 61 14-ec 6c 7b 3e 6f 18 35 0a .....ga..l{>o.5.
0080 - 8e 55 b7 ff 3c 4a 0a 09-94 14 ec a3 60 ff 07 9c .U..<J......`...
0090 - 14 95 ca 16 ec 15 d7 5b-76 19 ac f7 87 19 1f 91 .......[v.......
00a0 - ec 90 7b fa 98 7a db c2-c6 16 7b 4c ba a7 66 62 ..{..z....{L..fb
00b0 - 1a dc 2e 1e d2 6f 96 02-f4 0f 0b b4 71 b1 c6 d8 .....o......q...
00c0 - 98 dd a4 f8 5c 7b fa 08-3c 71 b4 f1 db 42 f4 8a ....\{..<q...B..
Start Time: 1744452410
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
TLS SUCCESSFUL
40F70A5BC87F0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:691:
Server output:
spawn openssl s_server -accept 23456 -naccept 1 -key pkcs11:type=private;id=%00%02 -cert pkcs11:type=cert;object=ecCert
Using default temp DH parameters
ACCEPT
-----BEGIN SSL SESSION PARAMETERS----- MIGCAgEBAgIDBAQCEwIEIPfWdVNxBFPkDAiqK16vyhiv0DBHaOGAIy3rfNGQCh8F BDDbF1gBiwVag5c+ANp+gzIddPN7NBvuZkPl+FMX9bjI3JfdVu3eVbxou5VBqUQ0 ZTihBgIEZ/o7OqIEAgIcIKQGBAQBAAAArgYCBHtj+TWzAwIBFw==
-----END SSL SESSION PARAMETERS-----
Shared ciphers:TLS_AES_256_GCM_SHA384
Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_
sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512
Shared Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_
pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512
Supported groups: secp256r1
Shared groups: secp256r1
CIPHER is TLS_AES_256_GCM_SHA384
This TLS version forbids renegotiation.
TLS SUCCESSFUL
Q
DONE
shutdown accept socket
shutting down SSL
CONNECTION CLOSED
0 items in the session cache
0 client connects (SSL_connect())
0 client renegotiates (SSL_connect())
0 client connects that finished
1 server accepts (SSL_accept())
0 server renegotiates (SSL_accept())
1 server accepts that finished
0 session cache hits
0 session cache misses
0 session cache timeouts
0 callback cache hits
0 cache full overflows (128 allowed)
## ########################################
########################################
## Forcing the provider for all server operations
## Run sanity test with default values (RSA)
spawn openssl s_client -propquery ?provider=pkcs11 -connect localhost:23456 -CAfile /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/caCert.pem
Connecting to ::1
CONNECTED(00000005)
Can't use SSL_get_servername
depth=1 CN=Issuer
verify return:1
depth=0 O=PKCS11 Provider, CN=My Test Cert
verify return:1
---
Certificate chain
0 s:O=PKCS11 Provider, CN=My Test Cert
i:CN=Issuer
a:PKEY: RSA, 2048 (bit); sigalg: sha256WithRSAEncryption
v:NotBefore: Apr 12 10:06:36 2025 GMT; NotAfter: Apr 12 10:06:36 2026 GMT ---
Server certificate
-----BEGIN CERTIFICATE----- MIIDPzCCAiegAwIBAgIBAzANBgkqhkiG9w0BAQsFADARMQ8wDQYDVQQDEwZJc3N1 ZXIwHhcNMjUwNDEyMTAwNjM2WhcNMjYwNDEyMTAwNjM2WjAxMRgwFgYDVQQKEw9Q S0NTMTEgUHJvdmlkZXIxFTATBgNVBAMTDE15IFRlc3QgQ2VydDCCASIwDQYJKoZI hvcNAQEBBQADggEPADCCAQoCggEBAMcui28zjpBTCQCCyxI2Su9brj5yxKb/ccI3 u9ipO7YCde7wVVPpjCZzXIzUmqpQ3tke+2YyBHjqcIeBJnvB+xKt6Oq6sHQ6IKL4 5dt3Vhj8Lvc/nyOFWOjJmeQLJGJvYn+ohqWIQ4Bk/3H9RDsLuam22mJ3LlHPZWcZ 2JAGyOvpZ94mrVcFXbwezCkK8kEoBCR/IZmCT7gWOFrWFEJ21JuWkyr7WZ0xaaNR 9O8EdMZBIZJ4scADmIiDn/rZ7UGQ98fC6RcCJUfZr9SG0JrGzv2ovGECF+Gd1ohT k2QV9xZ/HtV30iVD5slTfapS07ia281Q0f82YNQpgQrgvCuF+vECAwEAAaOBgTB/ MAwGA1UdEwEB/wQCMAAwHwYDVR0RBBgwFoEUdGVzdGNlcnRAZXhhbXBsZS5vcmcw DgYDVR0PAQH/BAQDAgWgMB0GA1UdDgQWBBT0OHyt6wRKSITgknAIlOweeCNYGzAf BgNVHSMEGDAWgBQsoPImCu3nowAZzMgdv4Nr73ioDzANBgkqhkiG9w0BAQsFAAOC AQEAFzMqwcTSQ5mo130cP1oP16oECeUzEDkLJipwEg3aj+3XzagczgGjdgoNqkdH 9swEEivllD3Icrm1/cdqxWeAo8ys0PdFTMfZOqu0eHdIZmW7pV8gGXsIj+V4BWoT CKOsjfJ/rFU1emy8e+ct79VyUI2BxRJPoTKdM9qaYn5c9joC6znKi1tXN5OUho5A ae+VMWvq3crGQEDN2slPPyo56YDl1rhGFY4/pZPy0X7O2EWJzzpSJbq4M0kiXdqA YS+n/1WOx57LgfCl4VDfeZpr8VngfTC+UqCBhKCEASfshkxl9wZ0XlNEn3DxA2c/ rX/Xw3YYk1eMaw1wZ1FuP3hKXw==
-----END CERTIFICATE-----
subject=O=PKCS11 Provider, CN=My Test Cert
issuer=CN=Issuer
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: rsa_pss_rsae_sha256
Negotiated TLS1.3 group: X25519MLKEM768
---
SSL handshake has read 2479 bytes and written 1613 bytes
Verification: OK
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Protocol: TLSv1.3
Server public key is 2048 bit
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: 74D20B9A3C2CE206948F0AAAB7DA3637F53A155361CD9DD81032D01875B0738C
Session-ID-ctx:
Resumption PSK: 377FA270A7536FE1D260B8E989748582F54C47FDC7F6A9102621E3EB9122A015F3B692609A84E914BE71CA6E202CA586
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket:
0000 - 6b 12 65 7a fb 5d 68 16-80 43 cc 33 0d 1d 4f de k.ez.]h..C.3..O.
0010 - 35 61 6e 45 23 26 87 5e-01 da 64 76 c5 f5 0b 05 5anE#&.^..dv....
0020 - f6 81 c8 5b e0 d3 b4 c2-35 4c 32 77 75 07 36 3e ...[....5L2wu.6>
0030 - 63 5b 0a b0 b6 05 3d 4b-94 99 9f 4d bf cc 71 25 c[....=K...M..q%
0040 - 4e f1 cf 24 12 d3 81 99-8f 9b 76 a0 b0 44 25 e5 N..$......v..D%.
0050 - ee 47 ca 70 27 f0 1b c7-d5 48 7a df c4 19 3f a3 .G.p'....Hz...?.
0060 - 57 09 44 de f4 7a 20 00-d6 56 24 cc 08 03 2d f3 W.D..z ..V$...-.
0070 - f5 bd 95 1a 8e 89 1d 26-25 85 95 38 f7 a3 8c ed .......&%..8....
0080 - 07 8b c6 ba 94 e2 8f 02-79 4c ce 46 14 49 33 6d ........yL.F.I3m
0090 - cd ca 81 2e c2 68 5c 5d-92 cf 84 cf 88 2f ce a6 .....h\]...../..
00a0 - 71 f4 9d 16 8c e2 9a d6-e9 62 3b 1b bf 81 ab d7 q........b;.....
00b0 - 94 57 af 86 7e 5b 93 b1-be 69 53 88 c7 96 c3 d9 .W..~[...iS.....
00c0 - 06 50 87 6a 05 f5 09 90-5d 51 be c8 92 5b c3 45 .P.j....]Q...[.E
Start Time: 1744452410
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: B5769987216926D44BF0FF08F8A2B227FCC7789840356837729C71E56BDE4E03
Session-ID-ctx:
Resumption PSK: 550096427F893A242B6AD10E60B9B238AA95440309D1E78DD24B9DF6BD1536D16FE073EB8A8425939C100650CE3727DF
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket:
0000 - 6b 12 65 7a fb 5d 68 16-80 43 cc 33 0d 1d 4f de k.ez.]h..C.3..O.
0010 - 8e 1d 5d 08 32 0d c1 f0-fb 94 78 7e 6a 08 7c b8 ..].2.....x~j.|.
0020 - 55 f2 f9 1c 4c 03 11 1a-fa 5c 6b 64 0c 53 b0 88 U...L....\kd.S..
0030 - ac 85 76 c4 eb 26 e4 bf-c7 ba 2b 8a 54 74 ad 72 ..v..&....+.Tt.r
0040 - 55 3f 0a 32 3b e8 fc e3-49 26 ec 67 4c c5 68 1a U?.2;...I&.gL.h.
0050 - 42 89 f2 ac 83 a1 ea 8b-8e b3 43 8f e8 33 41 d8 B.........C..3A.
0060 - d8 6a 85 96 6d ad 50 fe-23 e9 55 c9 40 8d 9c 96 .j..m.P.#.U.@...
0070 - 5c 02 30 9b c6 4d 8e f7-5b bc c8 36 99 07 88 67 \.0..M..[..6...g
0080 - 0c e1 a6 00 78 10 be 26-99 93 6e a9 c1 86 01 ca ....x..&..n.....
0090 - ca e1 5f b8 1f ca 9c 0c-a4 da 7b 2f a1 71 d7 e9 .._.......{/.q..
00a0 - 48 b9 1d fe 9e a4 1f 69-e5 a9 e6 3e 3d 83 f8 65 H......i...>=..e
00b0 - f9 9f fd f0 1e 42 a1 72-47 13 3b 5c 4a 34 cd 70 .....B.rG.;\J4.p
00c0 - 90 e1 a6 b4 4a 45 31 70-6e 88 63 40 38 3a b4 9d ....JE1pn.c@8:..
Start Time: 1744452410
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
TLS SUCCESSFUL
402704BBE27F0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:691:
Server output:
spawn openssl s_server -propquery ?provider=pkcs11 -accept 23456 -naccept 1 -key pkcs11:type=private;id=%00%01 -cert pkcs11:type=cert;object=testCert
Using default temp DH parameters
ACCEPT
-----BEGIN SSL SESSION PARAMETERS----- MIGDAgEBAgIDBAQCEwIEIIG2NcJHM1/kRk1Mg9kab4cvC+a6Qd5yTaOaviboffb8 BDBVAJZCf4k6JCtq0Q5gubI4qpVEAwnR543SS532vRU20W/gc+uKhCWTnBAGUM43 J9+hBgIEZ/o7OqIEAgIcIKQGBAQBAAAArgYCBD4Co9mzBAICEew=
-----END SSL SESSION PARAMETERS-----
Shared ciphers:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-CHACHA20-
POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:DHE-RSA-AES256-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA256:ECDHE-ECDSA-
AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES256-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA
Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_
sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224:DSA+SHA224:DSA+SHA256:DSA+SHA384:DSA+SHA512
Shared Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_
pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224
Supported groups: X25519MLKEM768:x25519:secp256r1:x448:secp384r1:secp521r1:ffdhe2048:ffdhe3072
Shared groups: X25519MLKEM768:x25519:secp256r1:x448:secp384r1:secp521r1:ffdhe2048:ffdhe3072
CIPHER is TLS_AES_256_GCM_SHA384
This TLS version forbids renegotiation.
TLS SUCCESSFUL
Q
DONE
shutdown accept socket
shutting down SSL
CONNECTION CLOSED
0 items in the session cache
0 client connects (SSL_connect())
0 client renegotiates (SSL_connect())
0 client connects that finished
1 server accepts (SSL_accept())
0 server renegotiates (SSL_accept())
1 server accepts that finished
0 session cache hits
0 session cache misses
0 session cache timeouts
0 callback cache hits
0 cache full overflows (128 allowed)
## Run sanity test with default values (RSA-PSS)
## Generating a new selfsigned certificate for pkcs11:type=private;id=%00%10
openssl req -batch -noenc -x509 -new -key ${KEY} ${AARGS} -out ${CERT}
spawn openssl s_client -propquery ?provider=pkcs11 -connect localhost:23456 -CAfile /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/caCert.pem
Connecting to ::1
CONNECTED(00000005)
Can't use SSL_get_servername
depth=0 C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness verify error:num=18:self-signed certificate
verify return:1
depth=0 C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness verify return:1
---
Certificate chain
0 s:C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness
i:C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness
a:PKEY: RSA-PSS, 2048 (bit); sigalg: rsassaPss
v:NotBefore: Apr 12 10:06:50 2025 GMT; NotAfter: May 12 10:06:50 2025 GMT ---
Server certificate
-----BEGIN CERTIFICATE----- MIIEIzCCAtugAwIBAgIUJqjLDrmE19BW6ScGitbuzEsUzTQwPQYJKoZIhvcNAQEK MDCgDTALBglghkgBZQMEAgGhGjAYBgkqhkiG9w0BAQgwCwYJYIZIAWUDBAIBogMC ASAwZzELMAkGA1UEBhMCVVMxETAPBgNVBAgMCE5ldyBZb3JrMREwDwYDVQQHDAhO ZXcgWW9yazEYMBYGA1UECgwPUEtDUzExIFByb3ZpZGVyMRgwFgYDVQQLDA9UZXN0 aW5nIEhhcm5lc3MwHhcNMjUwNDEyMTAwNjUwWhcNMjUwNTEyMTAwNjUwWjBnMQsw CQYDVQQGEwJVUzERMA8GA1UECAwITmV3IFlvcmsxETAPBgNVBAcMCE5ldyBZb3Jr MRgwFgYDVQQKDA9QS0NTMTEgUHJvdmlkZXIxGDAWBgNVBAsMD1Rlc3RpbmcgSGFy bmVzczCCASAwCwYJKoZIhvcNAQEKA4IBDwAwggEKAoIBAQCRj1VYA16PESIIha4Q MkpJn2gxwKuOLUeV+nar521mYf1G+bbw/DOzOQR8GvPHV07vufeeyT+DWxQY+yeG mAA2lVFl5S4Yo4jAimMJn0F6PYUZFTYIhVegdqi1MZVRbUmpX/ZXdIzCsQoP6RWC EiipLuZdy8qqWvKF5lIHaDE5FIQLic+kqHDaWlGDIifSXqYHRHl7AiizchnWHFi5 +fBw4+xcQhV4DlMTtVZVJfqvIjHwQ+xa5m4c47Ec6QYtOcvRsZWJJHQ8dVdW8zaV GwZOZwbV+qlzcT85SPcaOWoHeU9d4Wp0My7XHCKawtJBmpsxcxS6hVm1SJmaWBEF YvSzAgMBAAGjaTBnMB0GA1UdDgQWBBRW3mUaJI4DQHtI6oxGkehI59ZW9DAfBgNV HSMEGDAWgBRW3mUaJI4DQHtI6oxGkehI59ZW9DAPBgNVHRMBAf8EBTADAQH/MAkG A1UdEQQCMAAwCQYDVR0SBAIwADA9BgkqhkiG9w0BAQowMKANMAsGCWCGSAFlAwQC AaEaMBgGCSqGSIb3DQEBCDALBglghkgBZQMEAgGiAwIBIAOCAQEAJQgf4EaLek1R +wnJ1PUGGg8t4Ze1BwJkMB2SDd/c8PV5074c9yYyb9PHC1288GrOhmGIV3YdHy8J RzIZpGhtasuSsofheCllFq4Z+wKcQ8FpB9Xe+pet4gBYv2s1F4TzmC3HiUdGgfDL JC310bz/r3FDVKHGvAciyuHQQUu3NhvwBCbzIP/UGfsU4aqXI9uLoLljMNfYFRGX Thxz7JvwZjkBo4O1qQ469XSoIOoHox6TN0242ucHiwdQziqucYptvK+CL97ppuUc gBW/pDpo1aW0aFlWcEE1PbY99Vm9z9kcMrBiIYrxeQ7JSLBiakT5LwrildPMOHvh
Ofu/wRFQTg==
-----END CERTIFICATE-----
subject=C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness issuer=C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness ---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: rsa_pss_pss_sha256
Negotiated TLS1.3 group: X25519MLKEM768
---
SSL handshake has read 2707 bytes and written 1613 bytes
Verification error: self-signed certificate
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Protocol: TLSv1.3
Server public key is 2048 bit
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 18 (self-signed certificate)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: 97D37B33CAAF12747CA697C0C65B200871AB1DD63623D5A6D7592AA374D40035
Session-ID-ctx:
Resumption PSK: 6EE4F4F4D8A2CDAE2DC79C938C0F0B9C9DBD6AE0E4A0C5BB20FC0C1B585BDD736DA0E24F9AD6C5979F0C5D3F814DBCD1
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket:
0000 - 57 67 c2 d2 19 9f ef 36-15 55 41 80 b1 1c a6 b2 Wg.....6.UA.....
0010 - dd 0b ce a3 19 6b 5c 59-ee b4 20 a7 b6 87 39 fe .....k\Y.. ...9.
0020 - cf a6 ac 0c 65 81 42 c7-dd 4f 83 7a c5 f6 50 2a ....e.B..O.z..P*
0030 - 28 8e f4 35 d2 2e ef 8a-59 28 28 2e d5 b0 98 45 (..5....Y((....E
0040 - 5c 58 43 09 b2 d1 04 75-4a ef d5 19 75 cd 74 03 \XC....uJ...u.t.
0050 - 61 98 0b 3a 7b df f6 01-56 2f 59 8b 02 f5 dc 2f a..:{...V/Y..../
0060 - d7 0d 28 35 4e 06 8f d0-09 2b a6 e8 56 53 b3 02 ..(5N....+..VS..
0070 - cd 8c f7 a2 80 05 45 28-7c 14 28 a3 89 f9 82 50 ......E(|.(....P
0080 - 49 5d 0f 11 a5 b1 d1 a1-f4 ef 19 8d ab 48 15 77 I]...........H.w
0090 - 00 83 6f ae 84 8f fe e5-cb f1 0d 27 94 fb e3 ad ..o........'....
00a0 - f4 4b 53 5b 59 96 28 2a-32 9e b1 41 fa d1 8e 68 .KS[Y.(*2..A...h
00b0 - c1 c6 6d 02 fe 09 c9 bb-28 46 ec cd e9 94 7e 79 ..m.....(F....~y
00c0 - fc 29 08 0b bc 01 7a 86-a9 5e 80 ae 54 b4 55 f2 .)....z..^..T.U.
Start Time: 1744452410
Timeout : 7200 (sec)
Verify return code: 18 (self-signed certificate)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: 44AC5BA8FFC1BF0D0766A09ABEBE658673D61181E43A0DD60FED63C1A713E666
Session-ID-ctx:
Resumption PSK: 8539D2A89D61B5B8C79CC889A37547158DD1A6DA177B24C881CA100DB32A9A272AD0AE8CE3B8C3E4A0E0598CD4BEA5C9
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket:
0000 - 57 67 c2 d2 19 9f ef 36-15 55 41 80 b1 1c a6 b2 Wg.....6.UA.....
0010 - 9e 50 27 0f 7d 3c ed b1-09 01 ca 7c 13 b2 17 cd .P'.}<.....|....
0020 - 27 8f 1c a2 ca 85 37 7d-c8 53 91 7b 13 af 6d d3 '.....7}.S.{..m.
0030 - aa 53 3a 5b c7 8f 4a 07-d8 82 c4 2e be bf ff 16 .S:[..J.........
0040 - cc 04 de d4 13 b0 bc 6f-6d 8c be bf 9d 6a b7 9f .......om....j..
0050 - b8 6d 70 48 09 39 01 99-82 03 c7 38 15 73 6f 10 .mpH.9.....8.so.
0060 - b8 58 cc be c4 cb b9 6c-13 bd ec 37 b7 55 55 53 .X.....l...7.UUS
0070 - 0c 95 8b a7 ae 6b 0b 3a-ed 66 32 3b 51 0e 2e 43 .....k.:.f2;Q..C
0080 - 8c 08 b6 9a 69 42 55 e3-d6 cd a1 ec 8b 3b b8 2b ....iBU......;.+
0090 - 12 c3 4a 7d 7a fb fc 35-85 b3 09 f6 09 52 33 9e ..J}z..5.....R3.
00a0 - fc 39 f8 01 ab c5 12 59-a4 c1 9e af de 17 fe fc .9.....Y........
00b0 - 85 36 4b 28 99 07 3e 53-ed 3a 66 a1 4d 13 88 8d .6K(..>S.:f.M...
00c0 - dd d2 4c 5c a4 d5 f9 f4-fd e5 c7 3a 0c 04 ed 53 ..L\.......:...S
Start Time: 1744452410
Timeout : 7200 (sec)
Verify return code: 18 (self-signed certificate)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
TLS SUCCESSFUL
400724796C7F0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:691:
Server output:
spawn openssl s_server -propquery ?provider=pkcs11 -accept 23456 -naccept 1 -key pkcs11:type=private;id=%00%10 -cert /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/rsapss-default.pem
Using default temp DH parameters
ACCEPT
-----BEGIN SSL SESSION PARAMETERS----- MIGDAgEBAgIDBAQCEwIEICOeuFLKzmUV9XAB8b5Ixw5fmTDEkaudmDpgKMvxlJCe BDCFOdKonWG1uMecyImjdUcVjdGm2hd7JMiByhANsyqaJyrQrozjuMPkoOBZjNS+ pcmhBgIEZ/o7OqIEAgIcIKQGBAQBAAAArgYCBE3JgS2zBAICEew=
-----END SSL SESSION PARAMETERS-----
Shared ciphers:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-CHACHA20-
POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:DHE-RSA-AES256-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA256:ECDHE-ECDSA-
AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES256-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA
Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_
sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224:DSA+SHA224:DSA+SHA256:DSA+SHA384:DSA+SHA512
Shared Signature Algorithms: id-ml-dsa-65:id-ml-dsa-87:id-ml-dsa-44:ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:ecdsa_brainpoolP256r1_sha256:ecdsa_brainpoolP384r1_sha384:ecdsa_brainpoolP512r1_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_
pss_pss_sha512:RSA-PSS+SHA256:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224
Supported groups: X25519MLKEM768:x25519:secp256r1:x448:secp384r1:secp521r1:ffdhe2048:ffdhe3072
Shared groups: X25519MLKEM768:x25519:secp256r1:x448:secp384r1:secp521r1:ffdhe2048:ffdhe3072
CIPHER is TLS_AES_256_GCM_SHA384
This TLS version forbids renegotiation.
TLS SUCCESSFUL
Q
DONE
shutdown accept socket
shutting down SSL
CONNECTION CLOSED
0 items in the session cache
0 client connects (SSL_connect())
0 client renegotiates (SSL_connect())
0 client connects that finished
1 server accepts (SSL_accept())
0 server renegotiates (SSL_accept())
1 server accepts that finished
0 session cache hits
0 session cache misses
0 session cache timeouts
0 callback cache hits
0 cache full overflows (128 allowed)
## Run sanity test with RSA-PSS and SHA256
## Generating a new selfsigned certificate for pkcs11:type=private;id=%00%11
openssl req -batch -noenc -x509 -new -key ${KEY} ${AARGS} -out ${CERT}
spawn openssl s_client -propquery ?provider=pkcs11 -connect localhost:23456 -CAfile /build/reproducible-path/pkcs11-provider-1.0/obj-x86_64-linux-gnu/tests/softhsm/caCert.pem
Connecting to ::1
CONNECTED(00000005)
Can't use SSL_get_servername
depth=0 C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness verify error:num=18:self-signed certificate
verify return:1
depth=0 C=US, ST=New York, L=New York, O=PKCS11 Provider, OU=Testing Harness verify return:1
---
[continued in next message]
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)