New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 891557 link

Starred by 2 users

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 3
Type: Bug

Blocking:
issue 558497



Sign in to add a comment

Investigate using Key labels for Smart Lock cryptohome keys

Project Member Reported by hansberry@chromium.org, Oct 3

Issue description

As per discussion in  crbug.com/888031 :

The logs are getting spammed with these error messages:

2018-09-21T18:19:07.582809-07:00 ERR cryptohomed[1393]: The TPM failed to unwrap the intermediate key with the supplied credentials
2018-09-21T18:19:07.582924-07:00 ERR cryptohomed[1393]: Failed to decrypt any keysets for abd5a2707ffef6938a0ed7caab52a3b12fd50335: mount error 2, crypto error 8
2018-09-21T18:19:07.582960-07:00 WARNING cryptohomed[1393]: AddKeyset: invalid authentication provided

This is because Smart Lock has no label on its keyset, so it's trying to authorize against all other keysets.

apronin@ recommends that we use labels, but unfortunately, Smart Lock has in the past not used labels -- simply adding them will not allow migration (the old key set without a label will be lost). Investigation is needed to determine the best way to implement this and still allow migration.

 
Components: OS>Systems>Security
Components: -OS>Systems>Security
Blocking: 558497

Sign in to add a comment