Skip to content

unable to use sealed key (TPM_RC_AUTH_FAIL (session 1): the authorization HMAC check failed and DA counter incremented") #59

@FLX-0x00

Description

@FLX-0x00

I have not been able to use my sealed key for a few weeks now. I tried to generate a new key with ssh-tpm-keygen, but it does not work either (different error message - something with hmac, not very sure about it). The whole setup worked flawlessly until 4-5 weeks ago. Is there any help in troubleshooting this problem? I have absolutely no idea where to start.

Things I tried:

  • Restart everything
  • restart the agent
  • generate a new key direktly with ssh-tpm-keygen
  • importing my current key again
  • switching the kernel to lts
  • installing latest release from git with the 0c68627 commit latest
  • checking errors with journalctl -k --grep=tpm
  • check if tpm2_pcrread works

After try to use the key the ssh-tpm-agent.service logs level=INFO msg="agent 13: failed getting handle: TPM_RC_INTEGRITY (parameter 1): integrity check failed"

my current working kernel is 6.10.3-arch1-2 (Arch Linux)
keytype is ecdsa-sha2-nistp256

Hoping for some input on this =)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions