From e0b6a38aa29caad543e41a6f0d4f2478e2665ab2 Mon Sep 17 00:00:00 2001 From: Viktor Liu Date: Fri, 2 Oct 2026 12:27:00 +0200 Subject: [PATCH] Require a token label whenever a PKCS#11 PIN is set --- client/internal/certproof/README.md | 22 +++++++++---------- client/internal/certproof/pinlatch.go | 3 +++ client/internal/certproof/pkcs11store.go | 18 ++++++++++----- client/internal/certproof/pkcs11store_test.go | 16 +++++++++++--- client/internal/certproof/store_other_test.go | 5 +++-- client/internal/pkcs11/uri.go | 5 +++++ 6 files changed, 46 insertions(+), 23 deletions(-) diff --git a/client/internal/certproof/README.md b/client/internal/certproof/README.md index 2c63c78a9..8a62849b5 100644 --- a/client/internal/certproof/README.md +++ b/client/internal/certproof/README.md @@ -147,23 +147,21 @@ NB_TPM_DEVICE=/tmp/swtpm.sock go test ./client/internal/certproof/ -run TestColl Distributions that follow Red Hat's guidance reach the TPM through tpm2-pkcs11, a PKCS#11 module whose token holds both the key and, after `tpm2_ptool addcert`, the certificate. -The store reads that token when the daemon's environment carries the token's user PIN in -`NB_TPM_PIN`. The PIN is never read from the profile config or a command-line flag; set it -on the service instead: - -```sh -netbird service install --service-env NB_TPM_PIN=1234 -``` - -That alone opens the first token the p11-kit proxy exposes, which is tpm2-pkcs11 on a -stock setup that has registered it. `CertPKCS11URI`, an RFC 7512 URI, narrows that down -on a host with several tokens or without p11-kit: +The store reads that token when `CertPKCS11URI` in the profile config, an RFC 7512 URI, +names it, and the daemon's environment carries the token's user PIN in `NB_TPM_PIN`. The +PIN is not a profile config field or a command-line flag; set it on the service: ```json "CertPKCS11URI": "pkcs11:token=netbird?module-path=/usr/lib/x86_64-linux-gnu/libtpm2_pkcs11.so" ``` -`token` selects the token by label, or the first token present when absent. `module-path` +```sh +netbird service install --service-env NB_TPM_PIN=1234 +``` + +`token` selects the token by label and is required whenever a PIN is set, from any source: +a PIN that names no token would go to whichever token is listed first, which may be a +plugged-in smartcard, and each wrong PIN counts towards that card's lockout. `module-path` names the library to load; `module-name=tpm2_pkcs11` resolves to `libtpm2_pkcs11.so` on the loader's search path, and with neither the p11-kit proxy is loaded, which exposes every module the system has registered. The URI may carry the PIN itself, as `pin-value` inline diff --git a/client/internal/certproof/pinlatch.go b/client/internal/certproof/pinlatch.go index 1dd7d03d1..1e02540f8 100644 --- a/client/internal/certproof/pinlatch.go +++ b/client/internal/certproof/pinlatch.go @@ -12,6 +12,9 @@ import ( // shared with everything else on the machine, and proofs are collected on every sync. var errPINRejectedBefore = errors.New("PKCS#11 token rejected this PIN before, not trying it again") +// errPINNeedsToken refuses a PIN that names no token to log in to. +var errPINNeedsToken = errors.New("a PKCS#11 PIN needs the token named in CertPKCS11URI, as token=