clevis icon indicating copy to clipboard operation
clevis copied to clipboard

Issues registering with Tang server

Open johnandrews17 opened this issue 7 years ago • 7 comments

Hi all.

I've just been building a new Tang setup, and having issues registering against out tang servers. I've built a fresh CentOS 7 VM as the client with Clevis installed on it, but when registering and i'm supposed to be prompted for the current LUKS password, it just skips/exits. (See attached screenshot)

clevis

Any suggestions?

I've tried rebooting a few times, and this machine can curl the /adv URL of the Tang server OK.

johnandrews17 avatar Apr 08 '18 22:04 johnandrews17

Also just tried changing the existing LUKS password, which changed successfully, but still get the above when trying to register against a Tang server.

johnandrews17 avatar Apr 08 '18 22:04 johnandrews17

What version are you running? rpm -qa clevis-luks

npmccallum avatar Apr 09 '18 14:04 npmccallum

Apologises npmcallum, i'm away from the office now till Monday, so can't confirm. I installed it very recently, maybe....a week ago. But i'll confirm next week. Thanks

johnandrews17 avatar Apr 10 '18 21:04 johnandrews17

OK, the version installed is:

clevis-luks-6-1.el7.x86_64

johnandrews17 avatar Apr 15 '18 21:04 johnandrews17

Any suggestions?

johnandrews17 avatar Apr 27 '18 05:04 johnandrews17

I just want to confirm the issue. I'm currently experimenting with clevis/tang and Ubuntu 18.04. When binding luks, I got the trust keys prompt. After that it just skips (without asking for a luks passphrase). Just as described by @johnandrews17. According to the tang server log everything was ok and adv request was received.

The issue was solved after creating new tang keys and removing the original keys which were created automatically during tang installation. After that the luks bind could be done as expected.

~]# DB=/var/db/tang ~]# jose jwk gen -i '{"alg":"ES512"}' -o $DB/new_sig.jwk ~]# jose jwk gen -i '{"alg":"ECMR"}' -o $DB/new_exc.jwk

XueSheng-GIT avatar Jul 30 '18 08:07 XueSheng-GIT

@johnandrews17 , @XueSheng-GIT : have you tried this with latest versions of Clevis?

sarroutbi avatar Jun 09 '21 18:06 sarroutbi