Project

General

Profile

Actions

tickets #160754

closed

kanidm-unixd TPM error

Added by crameleon about 1 month ago. Updated about 1 month ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Physical infrastructure / Hardware
Target version:
-
Start date:
2024-05-23
Due date:
% Done:

0%

Estimated time:

Description

On falkor2{0,1,2}.i.o.o the following is observed during boot:

falkor20 (Hypervisor):~ # journalctl -u kanidm-unixd --no-pager
May 23 01:32:51 falkor20.infra.opensuse.org systemd[1]: Starting Kanidm Local Client Resolver...
May 23 01:33:07 falkor20.infra.opensuse.org kanidm_unixd[19212]: 00000000-0000-0000-0000-000000000000 WARN     🚧 [warn]: WARNING: DB folder /var/cache/kanidm-unixd has 'everyone' permission bits in the mode. This could be a security risk ...
May 23 01:33:07 falkor20.infra.opensuse.org kanidm_unixd[19212]: ERROR:tcti:src/tss2-tcti/tctildr.c:428:Tss2_TctiLdr_Initialize_Ex() Failed to instantiate TCTI
May 23 01:33:07 falkor20.infra.opensuse.org kanidm_unixd[19212]: 00000000-0000-0000-0000-000000000000 ERROR    🚨 [error]:  | tpm_err: TssError(Tcti(TctiReturnCode { base_error: NotSupported }))
May 23 01:33:07 falkor20.infra.opensuse.org kanidm_unixd[19212]: 00000000-0000-0000-0000-000000000000 WARN     🚧 [warn]: Unable to open requested tpm device, falling back to soft tpm | tpm_err: TpmContextCreate
May 23 01:33:07 falkor20.infra.opensuse.org kanidm_unixd[19212]: 00000000-0000-0000-0000-000000000000 INFO     i [info]: Server started ...
May 23 01:33:07 falkor20.infra.opensuse.org systemd[1]: Started Kanidm Local Client Resolver.

It seems to work regardless, but gives the impression of something being wrong.
The machines have physical TPM modules.


Files

falkor20.dmesg (483 KB) falkor20.dmesg crameleon, 2024-05-23 02:17
Actions

Also available in: Atom PDF