Bug #15103
closed
Netgate Crypto ID missing in 23.09.01 after fresh firmware
Added by Jonathan Lee 11 months ago.
Updated 8 months ago.
Category:
Cryptographic Modules
Release Notes:
Force Exclusion
Affected Plus Version:
23.09.1
Affected Architecture:
SG-1100, SG-2100
Files
- Status changed from New to Confirmed
- Affected Architecture SG-1100 added
Also see: https://redmine.netgate.com/issues/12636
The CryptoID is shown as expected if the /etc/thoth/thothid is populated. That file is populated by ping-auth which no longer exists which is why fresh installs show the error but upgrades do not.
It still works the thorth folder is empty.
I fixed it by transferring the folder over from an older SSD
ping-auth -s no longer populates it for you so its empty, how does this effect OpenVPN users?
With 23.05.01
AES-GCM,ChaCha20-Poly1305,AES-ICM,AES-XTS,SHA1,SHA256,SHA384,SHA512
is shown for my model 2100 when IPsec-MB Crypto is activated much of the config.xml that is blocks of random information disappears when IPsec-MB Crypto is active.
- Status changed from Confirmed to Resolved
- Assignee set to Marcos M
- Target version set to 24.03
- Release Notes changed from Default to Force Exclusion
Thoth is no longer used - the error is from old code which has been cleaned up in dev snaps. This is being tracked with NG#12636.
I thought I would mention, I also have this issue in 23.09.1 that I just did a reinstall on. 23.09.1 is running on an HP thin client with AMD RX-427BB (x64) processor (HP t730).
The Dashboard shows AES + ChaCha Encryptions listed, but under OpenVPN server and clients it lists 'no hardware crypto acceleration'.
In 24 the crypto acceleration does not list any counters when VPN is running also. I thought it was able to enable and offboard automatically. However, the counters do not reflect that it is used at all currently in arm 24.03.b.20240322.1708
Also available in: Atom
PDF