hi chaps!
Ok when doing openssl genpkey in 0.4.21 against MLDSA key, it works :-) also works for MLKEM key
key is genned, and has CKA_ID set (i built master pull git clone)
However for SLHDSA genpkey, its failing with CKR inconsistent template.
I am including both working MLDSA log and failing SLHDSA log
itll show the template coming in on both etc.
I can see the MLDSA genpket FAILS the 1st time, but it tries c_generatekey a 2nd time and succeeds with a better template of just sign and verify.
this is tested on Entrust ncipher N5c rack mount hsm with latest version.
We cannot have all trues in the teamplate, it will fail with inconsistent template
we cant have sign true encrypt true wrap true all blinged out or will fail :-)
Can you duplicate the "2 try" method that the libp11 MLDSA code is using?
This way for your soft hsm it will generate an all blinged out key with all trues for anything you wanna do :-)
and for other real hsm providers, it will try again a 2nd time after failing and gen a key with just sign and verify (reduced template with trues)
Here is a quick rundown of what each one did:
[root@rhel98libp11sw1395 nfast]# cat pkcs11_MLDSAgenpkey.log | grep C_G
2026-09-09 18:53:03 [1286985]: pkcs11: 00000000 >> C_GetFunctionList
2026-09-09 18:53:03 [1286985]: pkcs11: 00000000 >> C_GetInterface
2026-09-09 18:53:03 [1286985]: pkcs11: 00000000 >> C_GetInterfaceList
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> NFC_GetInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotList
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotList
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetTokenInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GenerateKeyPair
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GenerateKeyPair
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetSessionInfo
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
so we see the MLDSA case ran c_generate 2 times, 1st one failed on the big template, and 2nd one succeeded on the sign verify template.
[root@rhel98libp11sw1395 nfast]# cat pkcs11_SLHDSAgenpkey.log | grep C_G
2026-09-09 18:58:17 [1288838]: pkcs11: 00000000 >> C_GetFunctionList
2026-09-09 18:58:17 [1288838]: pkcs11: 00000000 >> C_GetInterface
2026-09-09 18:58:17 [1288838]: pkcs11: 00000000 >> C_GetInterfaceList
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> NFC_GetInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotList
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotList
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetTokenInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 000008CC >> C_GenerateKeyPair
on SLHDSA it only tried the big all true everything template and failed and did not try to do a smaller sign verify template (like the MLDSA code does)
can we implement what the MLDSA code does for the SLHDSA keygen template code? a 2 try?
i think this will work for everyone !!! :-) softhsm and real hsm providers :-)
many thanks!
2 x pkcs11 logs here:
pkcs11_MLDSAgenpkey.log
pkcs11_SLHDSAgenpkey.log
hi chaps!
Ok when doing openssl genpkey in 0.4.21 against MLDSA key, it works :-) also works for MLKEM key
key is genned, and has CKA_ID set (i built master pull git clone)
However for SLHDSA genpkey, its failing with CKR inconsistent template.
I am including both working MLDSA log and failing SLHDSA log
itll show the template coming in on both etc.
I can see the MLDSA genpket FAILS the 1st time, but it tries c_generatekey a 2nd time and succeeds with a better template of just sign and verify.
this is tested on Entrust ncipher N5c rack mount hsm with latest version.
We cannot have all trues in the teamplate, it will fail with inconsistent template
we cant have sign true encrypt true wrap true all blinged out or will fail :-)
Can you duplicate the "2 try" method that the libp11 MLDSA code is using?
This way for your soft hsm it will generate an all blinged out key with all trues for anything you wanna do :-)
and for other real hsm providers, it will try again a 2nd time after failing and gen a key with just sign and verify (reduced template with trues)
Here is a quick rundown of what each one did:
[root@rhel98libp11sw1395 nfast]# cat pkcs11_MLDSAgenpkey.log | grep C_G
2026-09-09 18:53:03 [1286985]: pkcs11: 00000000 >> C_GetFunctionList
2026-09-09 18:53:03 [1286985]: pkcs11: 00000000 >> C_GetInterface
2026-09-09 18:53:03 [1286985]: pkcs11: 00000000 >> C_GetInterfaceList
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> NFC_GetInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotList
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotList
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetTokenInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GenerateKeyPair
2026-09-09 18:53:03 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GenerateKeyPair
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetSessionInfo
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
2026-09-09 18:53:04 [1286985] t4077d8b1307f0000: pkcs11: 000008CC >> C_GetAttributeValue
so we see the MLDSA case ran c_generate 2 times, 1st one failed on the big template, and 2nd one succeeded on the sign verify template.
[root@rhel98libp11sw1395 nfast]# cat pkcs11_SLHDSAgenpkey.log | grep C_G
2026-09-09 18:58:17 [1288838]: pkcs11: 00000000 >> C_GetFunctionList
2026-09-09 18:58:17 [1288838]: pkcs11: 00000000 >> C_GetInterface
2026-09-09 18:58:17 [1288838]: pkcs11: 00000000 >> C_GetInterfaceList
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> NFC_GetInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotList
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotList
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetTokenInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 00000000 >> C_GetSlotInfo
2026-09-09 18:58:17 [1288838] t407718d2e67f0000: pkcs11: 000008CC >> C_GenerateKeyPair
on SLHDSA it only tried the big all true everything template and failed and did not try to do a smaller sign verify template (like the MLDSA code does)
can we implement what the MLDSA code does for the SLHDSA keygen template code? a 2 try?
i think this will work for everyone !!! :-) softhsm and real hsm providers :-)
many thanks!
2 x pkcs11 logs here:
pkcs11_MLDSAgenpkey.log
pkcs11_SLHDSAgenpkey.log