p11wrap is mistakenly adding CKA_EC_PARAMS attribute.
When unwrapping the key, that parameter is forbidden, according to PKCS#11 v2.40 curr table 31 PKCS#11 v2.40 base table 10, item 6, _"MUST not be specified when object is unwrapped with CUnwrapKey."
This results in EC keys that cannot unwrap, when using cbcpad wrapping algorithm.
The workaround is to comment out CKA_EC_PARAMS from the wrap file before unwrapping the key.
p11wrap
is mistakenly addingCKA_EC_PARAMS
attribute.When unwrapping the key, that parameter is forbidden, according to PKCS#11 v2.40 curr table 31 PKCS#11 v2.40 base table 10, item 6, _"MUST not be specified when object is unwrapped with CUnwrapKey."
This results in EC keys that cannot unwrap, when using
cbcpad
wrapping algorithm. The workaround is to comment outCKA_EC_PARAMS
from the wrap file before unwrapping the key.