<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en" style='--code-editor-font: var(--default-mono-font, "GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospace;'>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
<title>
GitLab
</title>
<style data-premailer="ignore" type="text/css">
a { color: #1068bf; }
</style>
<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: rgba(255,255,255,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size: inherit;
}
</style>
</head>
<body style='font-size: inherit; -webkit-text-shadow: rgba(255,255,255,.01) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji";'>
<div class="content">
<p class="details" style="font-style: italic; color: #626168;">
<a href="https://gitlab.com/ametzler">Andreas Metzler</a> created an issue: <a href="https://gitlab.com/gnutls/gnutls/-/issues/1784">#1784</a>
</p>
<div class="md" style="position: relative; z-index: 1; color: #3a383f; word-wrap: break-word;">
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">Hello,
this is <a href="http://bugs.debian.org/1125519" rel="nofollow noreferrer noopener" target="_blank" style="margin-top: 0;">http://bugs.debian.org/1125519</a> reported by Claudio Ferreira Filho. Attaching verbatim since I really have no opinion whether this is a clear-cut hardware bug or not.</p>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">Dear Maintainer,</p>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">I've discovered an incompatibility between GnuTLS 3.8.11 and SafeSign IC
3.8.0.0 PKCS#11 module that prevents the use of SafeSign tokens with
applications like OpenConnect VPN.</p>
<h2 id="user-content-problem-description" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Problem Description<a href="#problem-description" aria-label="Link to heading 'Problem Description'" data-heading-content="Problem Description" class="anchor" style="margin-top: 0;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">When GnuTLS attempts to initialize the SafeSign PKCS#11 module, it fails
with "Thread locking error" because SafeSign returns CKR_NEED_TO_CREATE_THREADS
(0x09) when it receives the CKF_LIBRARY_CANT_CREATE_OS_THREADS flag.</p>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">This is contradictory behavior: the module is saying "I need to create threads"
when explicitly told "you cannot create threads". However, SafeSign works
correctly when initialized with flags=0.</p>
<h2 id="user-content-steps-to-reproduce" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Steps to Reproduce<a href="#steps-to-reproduce" aria-label="Link to heading 'Steps to Reproduce'" data-heading-content="Steps to Reproduce" class="anchor" style="margin-top: 0;"></a>
</h2>
<ol dir="auto" style="text-align: initial; margin: 0 0 1rem; padding: 0;">
<li style="margin-top: 0; line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Install SafeSign IC 3.8.0.0 driver (libaetpkss.so)</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Insert a SafeSign token (e.g., G&D StarSign CUT S)</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Try to use the token with OpenConnect or any GnuTLS-based application</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Observe "Cannot initialize PKCS <a href="https://gitlab.com/gnutls/gnutls/-/issues/11" title="Gnutls should use MSG_NOSIGNAL when writing to a socket" class="gfm gfm-issue" data-original="#11" data-link="false" data-link-reference="false" data-issue="240725" data-project="179611" data-iid="11" data-namespace-path="gnutls/gnutls" data-project-path="gnutls/gnutls" data-issue-type="issue" data-container="body" data-placement="top" data-reference-type="issue" style="margin-top: 0;">#11 (closed)</a> module" error</li>
</ol>
<h2 id="user-content-testing" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Testing<a href="#testing" aria-label="Link to heading 'Testing'" data-heading-content="Testing" class="anchor" style="margin-top: 0;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">Direct testing shows the issue:</p>
<div class="gl-relative markdown-code-block js-markdown-code">
<pre data-canonical-lang="c" class="code highlight js-syntax-highlight language-c" v-pre="true" style='display: block; font-size: 14px; color: #3a383f; line-height: 1.6em; overflow-x: auto; border-radius: .25rem; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; margin: 0 0 1rem; padding: 12px; border: 1px solid #dcdcde;'><code style='font-size: inherit; color: inherit; word-wrap: normal; word-break: keep-all; background-color: inherit; border-radius: .25rem; white-space: pre; margin-top: 0; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; overflow-wrap: normal; padding: unset;'><span id="LC1" class="line" lang="c" style="margin-top: 0;"><span class="n" style="margin-top: 0;">CK_C_INITIALIZE_ARGS</span> <span class="n">args</span> <span class="o">=</span> <span class="p">{</span><span class="nb">NULL</span><span class="p">,</span> <span class="nb">NULL</span><span class="p">,</span> <span class="nb">NULL</span><span class="p">,</span> <span class="nb">NULL</span><span class="p">,</span> </span>
<span id="LC2" class="line" lang="c"> <span class="n" style="margin-top: 0;">CKF_OS_LOCKING_OK</span> <span class="o">|</span> <span class="n">CKF_LIBRARY_CANT_CREATE_OS_THREADS</span><span class="p">,</span> </span>
<span id="LC3" class="line" lang="c"> <span class="nb" style="margin-top: 0;">NULL</span><span class="p">};</span></span>
<span id="LC4" class="line" lang="c"><span class="n" style="margin-top: 0;">rv</span> <span class="o">=</span> <span class="n">C_Initialize</span><span class="p">(</span><span class="o">&</span><span class="n">args</span><span class="p">);</span></span>
<span id="LC5" class="line" lang="c"><span class="c1" style="margin-top: 0;">// SafeSign returns: 0x00000009 (CKR_NEED_TO_CREATE_THREADS)</span></span>
<span id="LC6" class="line" lang="c"></span>
<span id="LC7" class="line" lang="c"><span class="n" style="margin-top: 0;">args</span><span class="p">.</span><span class="n">flags</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span></span>
<span id="LC8" class="line" lang="c"><span class="n" style="margin-top: 0;">rv</span> <span class="o">=</span> <span class="n">C_Initialize</span><span class="p">(</span><span class="o">&</span><span class="n">args</span><span class="p">);</span></span>
<span id="LC9" class="line" lang="c"><span class="c1" style="margin-top: 0;">// SafeSign returns: 0x00000000 (CKR_OK)</span></span></code></pre>
<copy-code></copy-code><insert-code-snippet></insert-code-snippet>
</div>
<h2 id="user-content-proposed-solution" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Proposed Solution<a href="#proposed-solution" aria-label="Link to heading 'Proposed Solution'" data-heading-content="Proposed Solution" class="anchor" style="margin-top: 0;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">Add a fallback for CKR_NEED_TO_CREATE_THREADS similar to the existing
CKR_CANT_LOCK fallback. When a module returns CKR_NEED_TO_CREATE_THREADS,
retry initialization with flags=0.</p>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">I've attached a patch that implements this solution. The patch:</p>
<ul dir="auto" style="text-align: initial; list-style-type: disc; margin: 0 0 1rem; padding: 0;">
<li style="margin-top: 0; line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Maintains compatibility with conforming PKCS#11 modules</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Enables support for SafeSign and potentially other non-conforming modules</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Follows the same pattern as the existing CKR_CANT_LOCK fallback</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Has been tested successfully with SafeSign tokens</li>
</ul>
<h2 id="user-content-impact" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Impact<a href="#impact" aria-label="Link to heading 'Impact'" data-heading-content="Impact" class="anchor" style="margin-top: 0;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">This issue affects users of:</p>
<ul dir="auto" style="text-align: initial; list-style-type: disc; margin: 0 0 1rem; padding: 0;">
<li style="margin-top: 0; line-height: 1.6em; margin-left: 25px; padding-left: 3px;">SafeSign tokens (common in Brazilian government/corporate environments)</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">OpenConnect VPN with certificate authentication</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Any GnuTLS-based application using PKCS#11</li>
</ul>
<h2 id="user-content-environment" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Environment<a href="#environment" aria-label="Link to heading 'Environment'" data-heading-content="Environment" class="anchor" style="margin-top: 0;"></a>
</h2>
<ul dir="auto" style="text-align: initial; list-style-type: disc; margin: 0 0 1rem; padding: 0;">
<li style="margin-top: 0; line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Debian: Sid/Forky</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">GnuTLS: 3.8.11-3</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">SafeSign: IC Standard Linux 3.8.0.0</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Token: Giesecke & Devrient StarSign CUT S</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Certificate: ICP-Brasil (Brazilian PKI)</li>
</ul>
<h2 id="user-content-additional-information" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Additional Information<a href="#additional-information" aria-label="Link to heading 'Additional Information'" data-heading-content="Additional Information" class="anchor" style="margin-top: 0;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">The issue does NOT occur with:</p>
<ul dir="auto" style="text-align: initial; list-style-type: disc; margin: 0 0 1rem; padding: 0;">
<li style="margin-top: 0; line-height: 1.6em; margin-left: 25px; padding-left: 3px;">pkcs11-tool (OpenSC) - works correctly</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">GnuTLS 3.7.x (Debian Trixie) - works correctly</li>
</ul>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">This suggests the issue was introduced in GnuTLS 3.8.x or that 3.7.x had
more lenient initialization logic.</p>
<h2 id="user-content-documentation" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Documentation<a href="#documentation" aria-label="Link to heading 'Documentation'" data-heading-content="Documentation" class="anchor" style="margin-top: 0;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">Complete investigation and testing documentation available at:
<a href="https://github.com/dataprev/vpn-safesign-gnutls" rel="nofollow noreferrer noopener" target="_blank" style="margin-top: 0;">https://github.com/dataprev/vpn-safesign-gnutls</a> (if published)</p>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">The investigation took approximately 8 hours and included:</p>
<ul dir="auto" style="text-align: initial; list-style-type: disc; margin: 0 0 1rem; padding: 0;">
<li style="margin-top: 0; line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Analysis of GnuTLS source code</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Testing with multiple PKCS#11 modules</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Comparison between GnuTLS 3.7.x and 3.8.x</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">Validation with real-world VPN usage</li>
</ul>
<h2 id="user-content-patch" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Patch<a href="#patch" aria-label="Link to heading 'Patch'" data-heading-content="Patch" class="anchor" style="margin-top: 0;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0 0 1rem;" align="initial">Please find attached the patch file:
0001-pkcs11-Add-fallback-for-CKR_NEED_TO_CREATE_THREADS.patch</p>
<p dir="auto" style="color: #3a383f; margin: 0;" align="initial">The patch is minimal (7 lines) and follows GnuTLS coding standards.
<a href="https://gitlab.com/-/project/179611/uploads/17259892134d08ac9dd25c1371e075bb/sugggested.patch" data-canonical-src="/uploads/17259892134d08ac9dd25c1371e075bb/sugggested.patch" data-link="true" class="gfm" style="margin-top: 0;">sugggested.patch</a></p>
</div>
</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #626168;">
—
<br>
Reply to this email directly or <a href="https://gitlab.com/gnutls/gnutls/-/issues/1784">view it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target="_blank" rel="noopener noreferrer" href="https://gitlab.com">gitlab.com</a>. <a href="https://gitlab.com/-/sent_notifications/2-14nazkkjhhzbd2x06isdjioe4/unsubscribe" target="_blank" rel="noopener noreferrer">Unsubscribe</a> from this thread · <a href="https://gitlab.com/-/profile/notifications" target="_blank" rel="noopener noreferrer" class="mng-notif-link">Manage all notifications</a> · <a href="https://gitlab.com/help" target="_blank" rel="noopener noreferrer" class="help-link">Help</a>
<span style="color: transparent; font-size: 0; display: none; overflow: hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://gitlab.com/gnutls/gnutls/-/issues/1784 at 1768499262
</span>
<script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","action":{"@type":"ViewAction","name":"View Issue","url":"https://gitlab.com/gnutls/gnutls/-/issues/1784"}}</script>
</p>
</div>
</body>
</html>