-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 On Fri, 2022-10-07 at 18:17 +0200, Yves-Alexis Perez wrote: > So there's definitely something fishy in my kernel and I'm unsure why. > > Would anyone have a clue about what is happening here, and any idea how to > debug further? With some help from systemtap I managed to debug further and narrowed down the problem to the RNG (and more specifically anssi_cprng). When booting, first load of the module returns: [ 7.910500] alg: cprng: Failed to load transform for ansi_cprng: -2 [ 7.917774] alg: No test for fips(ansi_cprng) (fips_ansi_cprng) But unloading/reloading the module afterwards only shows the second line and IPsec starts working again (whether the `ip xfrm state` lines or strongSwan more generally). I have yet to debug further but my feeling is that it might be TPM-related but I'm unsure and have no clear debugging path for now. I'll let you know if I find anything. Regards, - -- Yves-Alexis -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAmN7bIIACgkQ3rYcyPpX RFsqdQgA62FGOagIAHKW000yQ/pm42+vO9DZFo7zJ17OHCsjintACME/bU3p3O+l mmWz7yv1ib7GcCL19p1ZN/XX3ukORYwuvm3ixKy7mytRb1qwphKLKl1t08NeEceB b7z2ZyjQAIPslkT0LL88fk5T3iOjelZg94fNTerUxDiGWCt6a8Oqz09jBUEK2yST UgkOGVPlNQM5Frs/SUiC2HhkHQEmek/urwncKVBfBCcmJQcqaaGBKeAyZB+JEyCz 1h0HnrHhIhjWPj93SwdbaqjnT7eIOT+jQSQ67CatUWkQBEHT1FJgcyle/mzhb8hs wGW4VaOtbfTOtdMVlXFyipNMszMG2g== =6MCJ -----END PGP SIGNATURE-----