Skip to content

Commit 8fc209a

Browse files
authored
Merge pull request #528 from jku/more-pkcs-error-handling
signer: Handle the "yubikey auth required" case
2 parents b90391f + 0df997b commit 8fc209a

File tree

2 files changed

+10
-1
lines changed

2 files changed

+10
-1
lines changed

signer/pyproject.toml

+1
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,7 @@ python_version = "3.9"
3636
[[tool.mypy.overrides]]
3737
module = [
3838
"securesystemslib.*",
39+
"PyKCS11.*",
3940
]
4041
ignore_missing_imports = "True"
4142

signer/tuf_on_ci_sign/_signer_repository.py

+9-1
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@
1515
from enum import Enum, unique
1616

1717
import click
18+
from PyKCS11 import CKR_USER_NOT_LOGGED_IN, PyKCS11Error
1819
from securesystemslib.exceptions import UnverifiedSignatureError
1920
from securesystemslib.formats import encode_canonical
2021
from securesystemslib.hash import digest
@@ -289,7 +290,14 @@ def _sign(self, role: str, md: Metadata, key: Key) -> None:
289290
self.user.set_signer(key, signer)
290291
break
291292
except UnsignedMetadataError as e:
292-
print(f"Failed to sign {role} with {self.user.name} key.\n {e}")
293+
# Very light error handling for specific PKCS11 errors
294+
msg = str(e)
295+
if isinstance(e.__context__, PyKCS11Error):
296+
pkcs_err = e.__context__
297+
if pkcs_err.value == CKR_USER_NOT_LOGGED_IN:
298+
msg = "Required authentication (e.g. touch) did not happpen"
299+
300+
print(f"Failed to sign {role} with {self.user.name} key:\n {msg}")
293301
logger.debug("Sign traceback", exc_info=True)
294302
except UnverifiedSignatureError as e:
295303
print(

0 commit comments

Comments
 (0)