{"id":2225001,"url":"http://patchwork.ozlabs.org/api/patches/2225001/?format=json","web_url":"http://patchwork.ozlabs.org/project/uboot/patch/20260420083850.8504-1-Wojciech.Dubowik@mt.com/","project":{"id":18,"url":"http://patchwork.ozlabs.org/api/projects/18/?format=json","name":"U-Boot","link_name":"uboot","list_id":"u-boot.lists.denx.de","list_email":"u-boot@lists.denx.de","web_url":null,"scm_url":null,"webscm_url":null,"list_archive_url":"","list_archive_url_format":"","commit_url_format":""},"msgid":"<20260420083850.8504-1-Wojciech.Dubowik@mt.com>","list_archive_url":null,"date":"2026-04-20T08:38:49","name":"[v2] tools: mkeficapsule: Add disable pkcs11 menu option","commit_ref":null,"pull_url":null,"state":"superseded","archived":false,"hash":"5625ac2769850cba2d4ce16a264b429e5b708714","submitter":{"id":90988,"url":"http://patchwork.ozlabs.org/api/people/90988/?format=json","name":"Wojciech Dubowik","email":"Wojciech.Dubowik@mt.com"},"delegate":{"id":3651,"url":"http://patchwork.ozlabs.org/api/users/3651/?format=json","username":"trini","first_name":"Tom","last_name":"Rini","email":"trini@ti.com"},"mbox":"http://patchwork.ozlabs.org/project/uboot/patch/20260420083850.8504-1-Wojciech.Dubowik@mt.com/mbox/","series":[{"id":500569,"url":"http://patchwork.ozlabs.org/api/series/500569/?format=json","web_url":"http://patchwork.ozlabs.org/project/uboot/list/?series=500569","date":"2026-04-20T08:38:49","name":"[v2] tools: mkeficapsule: Add disable pkcs11 menu option","version":2,"mbox":"http://patchwork.ozlabs.org/series/500569/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2225001/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2225001/checks/","tags":{},"related":[],"headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=mt.com header.i=@mt.com header.a=rsa-sha256\n header.s=selector2 header.b=C2sy2dnz;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=lists.denx.de\n (client-ip=85.214.62.61; helo=phobos.denx.de;\n envelope-from=u-boot-bounces@lists.denx.de; receiver=patchwork.ozlabs.org)","phobos.denx.de;\n dmarc=pass (p=reject dis=none) header.from=mt.com","phobos.denx.de;\n spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de","phobos.denx.de;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=mt.com header.i=@mt.com header.b=\"C2sy2dnz\";\n\tdkim-atps=neutral","phobos.denx.de;\n dmarc=pass (p=reject dis=none) header.from=mt.com","phobos.denx.de;\n spf=fail smtp.mailfrom=Wojciech.Dubowik@mt.com","dkim=none (message not signed)\n header.d=none;dmarc=none action=none header.from=mt.com;"],"Received":["from phobos.denx.de (phobos.denx.de [85.214.62.61])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fzf6H0tstz1yD4\n\tfor <incoming@patchwork.ozlabs.org>; Mon, 20 Apr 2026 18:39:03 +1000 (AEST)","from h2850616.stratoserver.net (localhost [IPv6:::1])\n\tby phobos.denx.de (Postfix) with ESMTP id 5C8A4842B7;\n\tMon, 20 Apr 2026 10:39:00 +0200 (CEST)","by phobos.denx.de (Postfix, from userid 109)\n id BA8B0842C7; Mon, 20 Apr 2026 10:38:59 +0200 (CEST)","from AM0PR83CU005.outbound.protection.outlook.com\n (mail-westeuropeazlp170100001.outbound.protection.outlook.com\n [IPv6:2a01:111:f403:c201::1])\n (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits))\n (No client certificate requested)\n by phobos.denx.de (Postfix) with ESMTPS id 9E6D4839D5\n for <u-boot@lists.denx.de>; Mon, 20 Apr 2026 10:38:57 +0200 (CEST)","from DB9PR03MB7180.eurprd03.prod.outlook.com (2603:10a6:10:22d::13)\n by PAXPR03MB8228.eurprd03.prod.outlook.com (2603:10a6:102:24f::17)\n with Microsoft SMTP Server (version=TLS1_2,\n cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9818.32; Mon, 20 Apr\n 2026 08:38:55 +0000","from DB9PR03MB7180.eurprd03.prod.outlook.com\n ([fe80::6fd2:12a9:4423:8ddc]) by DB9PR03MB7180.eurprd03.prod.outlook.com\n ([fe80::6fd2:12a9:4423:8ddc%6]) with mapi id 15.20.9818.032; Mon, 20 Apr 2026\n 08:38:55 +0000"],"X-Spam-Checker-Version":"SpamAssassin 3.4.2 (2018-09-13) on phobos.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED,\n DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_BLOCKED,\n SPF_HELO_PASS,SPF_PASS autolearn=ham autolearn_force=no version=3.4.2","ARC-Seal":"i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;\n b=o+szjAFKCK6KNVUG58AJM+fnPKtPzxKO1+uWHChsZTmuodmF75HzfxwlUFZAq+hhePz5VXXalcM1J/FS42JHPS4UV2nw0CrXyk+0XUb1Y8XQOhV4usEsicibjTChyncLgqdnh/12hfSRKRlnpDF5XWO7fLZfFEPigq6AI5WW+dRdzNcLJeCgDoviLrJILCDWp2oijOu+NPYExKsT4MFcvgDVqXBOh5ULkZenzMG8fTE37ZQLF12RXMcp37uJ/xpi8yBQTlLLmM58DbXxrmO5JbBX+4xQwggwrnMEPVnZ+sRwTTyxw0SfI169/TO3kWbqA3SRunFbiFAPz0CnwtcwjQ==","ARC-Message-Signature":"i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;\n s=arcselector10001;\n h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;\n bh=ilJA22Mt3ThAzt7TwLldmjbKrGPbqitbyRQmO6/aIFk=;\n b=wPoaPzHnusfK+2hTUyC98C2dhyDqljcZuVZKPCPcvDlcpZasCu6SknOj4j+3YI+nYjty4PkB1BjKtuaKdOGu4zjn/HdaVuAQAQgEvHzR5XQx2982VOiJ6DXWv77yacXKG6hWJxWDtyxn8BL88M+PXQKiFVa+tAQMKhXAmh6dAcm7kh8U9idCUIy9pONcgrm+VY9aGsTlOX2qgGMr6ZtfS7xV1UGReEb8fT1g2ER7sjz/WT91hkFZD4/BFwp4J50unfuBv2jJwqEg/nlDjTdGDWvJlzym5JXAMXD4HRkCcObcJ+E1dVGjWvCrs86P05u1P/La7J0i231oj+8awtxUyg==","ARC-Authentication-Results":"i=1; mx.microsoft.com 1; spf=pass\n smtp.mailfrom=mt.com; dmarc=pass action=none header.from=mt.com; dkim=pass\n header.d=mt.com; arc=none","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=mt.com; s=selector2;\n h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;\n bh=ilJA22Mt3ThAzt7TwLldmjbKrGPbqitbyRQmO6/aIFk=;\n b=C2sy2dnzeHDBfIJVwsCXVuKBy0qsBEWktJAtN95ehOXUX/EUEIqlAYK0E2fTUxcj2plFN4gjxa04ofnyH2Ja2r8UWf8AKHQiFttV8wRFvAY7yCxDBRBdF3qAGZqNFz2+OeqlJCVoynvt/5TkyGmpK1mFA49vALDJY1DJNSnvENUaBs7UM0E5A5gM+2SXAF7IAGuuM5oKFdX9ygAaHs7bCmPjl5dPg7HZo2OAa9WArAnhyclKlmnOWKojKbLpG3B1/iNhh8x0pPQ0SdceVNNDdHCoVgvZMHE/H0M3b9iavrzTVXJxZtJn252d8vWv7CHEH6H/Jxt7wR1lAIq9wTxRFA==","From":"Wojciech Dubowik <Wojciech.Dubowik@mt.com>","To":"u-boot@lists.denx.de","Cc":"Wojciech Dubowik <Wojciech.Dubowik@mt.com>,\n Simon Glass <sjg@chromium.org>,\n Franz Schnyder <fra.schnyder@gmail.com>, trini@konsulko.com,\n \"openembedded-core @ lists . openembedded . org\"\n <openembedded-core@lists.openembedded.org>,\n Francesco Dolcini <francesco@dolcini.it>","Subject":"[PATCH v2] tools: mkeficapsule: Add disable pkcs11 menu option","Date":"Mon, 20 Apr 2026 10:38:49 +0200","Message-ID":"<20260420083850.8504-1-Wojciech.Dubowik@mt.com>","X-Mailer":"git-send-email 2.47.3","Content-Transfer-Encoding":"8bit","Content-Type":"text/plain","X-ClientProxiedBy":"ZR0P278CA0074.CHEP278.PROD.OUTLOOK.COM\n (2603:10a6:910:22::7) To DB9PR03MB7180.eurprd03.prod.outlook.com\n (2603:10a6:10:22d::13)","MIME-Version":"1.0","X-MS-PublicTrafficType":"Email","X-MS-TrafficTypeDiagnostic":"DB9PR03MB7180:EE_|PAXPR03MB8228:EE_","X-MS-Office365-Filtering-Correlation-Id":"b2ae9920-563e-42bf-9dd1-08de9eb841ef","X-MS-Exchange-SenderADCheck":"1","X-MS-Exchange-AntiSpam-Relay":"0","X-Microsoft-Antispam":"BCL:0;\n ARA:13230040|366016|1800799024|376014|52116014|19092799006|38350700014|56012099003|18002099003;","X-Microsoft-Antispam-Message-Info":"\n mxkByTUsTyt4Ip/joCUbdX7gd05I+jnxiHYZsIPtAzAYkt7NkzmjfB7dVBqVmbsTLuAOJ8M5rAo+oTitXT3OBe5jjfGYb0pNdYrKa+S+9035D0jKm/CfOGUxtNMjpdWdA1PFBwRgBQe1x6a5N0OvYoGf1Arg8kglgTKebDo97Czkxd8rQG+FoseGQgDyKM8emFl4tVMxkU0uLIhMlYSVC7grrifHkcE7TY08odaUDX6HMVIPA9JUiXAtXqSQcIYGCb1qCnn/uO/RDLKtpJocPwMmMb7MAxc0hJGzqlK7tevA2izQn930IVdVNh38QyCMYl3zrwy8N6Y+81bOchdzler41Yj7cq00B0uHHfInTKUhPtatNbKHAKomlLX60H5RN6ayxVxGLiIg9pG0bmjTeYhcuaIXcptf30fTkcWVYq2z6XIMpxKGqbojcj53I+ejc0ZenLcYZNycWViBswyus6Kiw0l6iwb2CiOPTNuKWNmmQvpAT/vYgsTAQ6K6jHlv5FQYlGXP+lI0go21wwy9hqpaINpbDOcjFoUSpXmp29f9s67Rc/aXOYrkeudLCv7P7/ag+7soB1v4n3OECpRLKwmLUwJTxXYIrKi0937gev+dhDJxz6F9Fv5tHJnAHy9Eaus77M/PZ44K7b4vPygR2bfeuqlVgtAUX9uHPcNRGzW+DsjSdqHVZ9XwTER1TlQ7+hK04K0kNg6r/wDFv8d7Q2DwDijRH3a19dQsNi308cPMidCCpkm41W8xZ5KRvNfVN0C1DBA/yrjU7zA9VfBDhmGD5PMtB0b70J4UE25iGbY=","X-Forefront-Antispam-Report":"CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:;\n IPV:NLI; SFV:NSPM; H:DB9PR03MB7180.eurprd03.prod.outlook.com; PTR:; CAT:NONE;\n SFS:(13230040)(366016)(1800799024)(376014)(52116014)(19092799006)(38350700014)(56012099003)(18002099003);\n DIR:OUT; SFP:1101;","X-MS-Exchange-AntiSpam-MessageData-ChunkCount":"1","X-MS-Exchange-AntiSpam-MessageData-0":"\n GI+CZn8ILStuCMSsmFsatXoex3g16vbC3RDc79mXlzaC98bJ8ehPj7+27cOSgFpwka4tml611Ocq177j3sd/1c1qdyX5aSsomplIY4Ei2yWLpad0jlA3ktSEtEtQhPO98HPpJrlOCaSpqagSJCHy8o7EKVQyd/S9T2GdSLIprmEJ9kZTzXlx7vAMep9YfIRF4AmXdHf2vnflIUxLlcCUTjAIfRF59ds92g7S7J/WoNk0JXp79LrCKuoyhG8+lxHtP7RZUp1CNMsl3dccaNyleRJVup0thhWXVxR8WDtwNsxTGf90powqSgu2nLKkrsrIPCvKbdrDYbMC4+qRiqOJoWlMEKLFCGxJuoVHWGdL1kVfuXf7NtdsHnq9r1jVKGNuG8RcNeeCpQF/XpOpsACLIKAQ7Bv1mCRhF+83F6kq6pVp3dZ6zc7bKEZOAx5IXZQBx0blqNhJZbusblH8Qh9a3u7eXqL0GSolIeMMCNKdCk0bCN32j868KBkNth2RlHqfD6LIgZhPSdKfs4U7okSJN++XLwZiHESftlN1dUQl5TxjTZiiljOZjYR/q8cjFLtTtpYHyGWBwIlqaRlqAmeGEQiVpIAX7uYy+rIltrx5OYB0A0JVbnOcjj0naSi2S5V+oyK7V+45vBmZQokwx86kXe36TtleCU/U2vjYS6pKl6iCyu1gYaxiUhaUCmMuJcNsY7prcT8H8oCaiymvjEmvxQtDIkoGplHBwtQfbLryHvWXzEjK6nYBF+wRuQeaOZjLopGZ8a43j7m9ER3DsxG0MizBX1TH8STWHgSPud6BDSQbcw/gBcmSxMy5cmy+gQV9EEy2U5XTQHHjdSL8qwSbRW1nNGw5W2sB66Ia8QfK60OkL+rFMhbBLGfg3krI3n/eWSPqETi3FZXdWwtFQKEbrnEIT4JletTh9zkKZZ0dQqw+d6GWD1rizsNGS7zjiAccc36remfdzw3iRL1/zy+QN2kL0+f5lhWIHiFwG13RAdWRhxPuq5irT9EbZ27r8exJo0TCqU+IGmLYQBi+K/Mi14zdA3Ag4+BueZapmxWwpMLx6aHVUzxOE0hwqpxnfFtP+n/qlqmAh7WDR4jMJHzPQtCpP1HPSgHDKJ/ioTRstfKxUSIwVc2mvZxuAFXvMILz/izGulfydkqm0rYYcHxTzMCOQk1EqbR1YFhLWKNClGMQgmDzRJSF1kRVJzRCM4dshEfoZQyEkERnqNPxDdAv/7Xw4QE4KhJUmxLFMryeB0xmP83PrHz6xQvk2mGjYsiJ+N7l3C7HQygOEQJK5ZCMb7oMQ9l2nOY/q/avekeB+kSkznATr6rRXrx/GiMENyPLEysbR/lpmXVNklze3qOZ/GhgLMbeTa/JWFNTAUXxy+SqG1kcvYPNDOtvsQxF3WzpvOSfop1tdWtY7NN6fhpndRihOxrL2xF1ZDnczSy9tLuaXK+YgFlq37xPVRJKI87jrCesdwl/nLUbIM+j+g+H61fvv7zN0L8geweaQmYCILMnRgB4EErMiwy0oBh5JS93h85uNyaIUcr6/yRwsVY1MoavlnsLqP3TssN2qygjdh69DmfEBVJnlqnqyeLfLkbJQdX7iZWZuJr8xIH/keU7BwEKLP+rxYrFicTTqwqvk0JwmZE/mWVk8Cma7p7zIoMJ5T0UkctLq0jXioS/yvp/YV+XOD+gMm7SgeeqsLSBRwSPnIsOqtyxaiRYZyzG6VB+QxLBpA6LL5IRub65J6H0Yw==","X-OriginatorOrg":"mt.com","X-MS-Exchange-CrossTenant-Network-Message-Id":"\n b2ae9920-563e-42bf-9dd1-08de9eb841ef","X-MS-Exchange-CrossTenant-AuthSource":"DB9PR03MB7180.eurprd03.prod.outlook.com","X-MS-Exchange-CrossTenant-AuthAs":"Internal","X-MS-Exchange-CrossTenant-OriginalArrivalTime":"20 Apr 2026 08:38:55.1467 (UTC)","X-MS-Exchange-CrossTenant-FromEntityHeader":"Hosted","X-MS-Exchange-CrossTenant-Id":"fb4c0aee-6cd2-482f-a1a5-717e7c02496b","X-MS-Exchange-CrossTenant-MailboxType":"HOSTED","X-MS-Exchange-CrossTenant-UserPrincipalName":"\n gkLZzNxlARqJyo/WrCYY9ToW6u2MTg2CrBfdkHBpwJ22dq5MPOXMBgX8Im9guqs/+aP9fi++07XktkDy3VTojw==","X-MS-Exchange-Transport-CrossTenantHeadersStamped":"PAXPR03MB8228","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.39","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<https://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=subscribe>","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>","X-Virus-Scanned":"clamav-milter 0.103.8 at phobos.denx.de","X-Virus-Status":"Clean"},"content":"Some distros are using gnutls library without pkcs11 support\nand linking of mkeficapsule will fail. Add disable pkcs11\noption with default set to no so distros can control this\nfeature with config option.\n\nSuggested-by: Tom Rini <trini@konsulko.com>\nCc: Franz Schnyder <fra.schnyder@gmail.com>\nSigned-off-by: Wojciech Dubowik <Wojciech.Dubowik@mt.com>\n---\nChanges in v2:\n- make use of stderr more consistent\n- add missing ifndef around pkcs11 deinit functions\n---\n tools/Kconfig        |  8 ++++++++\n tools/Makefile       |  3 +++\n tools/mkeficapsule.c | 17 ++++++++++++++++-\n 3 files changed, 27 insertions(+), 1 deletion(-)","diff":"diff --git a/tools/Kconfig b/tools/Kconfig\nindex ef33295b8ecd..ccc878595d3b 100644\n--- a/tools/Kconfig\n+++ b/tools/Kconfig\n@@ -114,6 +114,14 @@ config TOOLS_MKEFICAPSULE\n \t  optionally sign that file. If you want to enable UEFI capsule\n \t  update feature on your target, you certainly need this.\n \n+config MKEFICAPSULE_DISABLE_PKCS11\n+\tbool \"Disable pkcs11 support\"\n+\tdepends on TOOLS_MKEFICAPSULE\n+\tdefault n\n+\thelp\n+\t  Disable pkcs11 support. Can be used in cases when host GnuTLS\n+\t  library doesn't support it.\n+\n menuconfig FSPI_CONF_HEADER\n \tbool \"FlexSPI Header Configuration\"\n \thelp\ndiff --git a/tools/Makefile b/tools/Makefile\nindex 1a5f425ecdaa..60e84bfbf20d 100644\n--- a/tools/Makefile\n+++ b/tools/Makefile\n@@ -271,6 +271,9 @@ mkeficapsule-objs := generated/lib/uuid.o \\\n \t$(LIBFDT_OBJS) \\\n \tmkeficapsule.o\n hostprogs-always-$(CONFIG_TOOLS_MKEFICAPSULE) += mkeficapsule\n+ifeq ($(CONFIG_MKEFICAPSULE_DISABLE_PKCS11),y)\n+HOSTCFLAGS_mkeficapsule.o += -DCONFIG_MKEFICAPSULE_DISABLE_PKCS11\n+endif\n \n include tools/fwumdata_src/fwumdata.mk\n \ndiff --git a/tools/mkeficapsule.c b/tools/mkeficapsule.c\nindex ec640c57e8a5..2f6e22626c51 100644\n--- a/tools/mkeficapsule.c\n+++ b/tools/mkeficapsule.c\n@@ -229,9 +229,11 @@ static int create_auth_data(struct auth_context *ctx)\n \tgnutls_pkcs7_t pkcs7;\n \tgnutls_datum_t data;\n \tgnutls_datum_t signature;\n+#ifndef CONFIG_MKEFICAPSULE_DISABLE_PKCS11\n \tgnutls_pkcs11_obj_t *obj_list;\n \tunsigned int obj_list_size = 0;\n \tconst char *lib;\n+#endif\n \tint ret;\n \tbool pkcs11_cert = false;\n \tbool pkcs11_key = false;\n@@ -242,6 +244,7 @@ static int create_auth_data(struct auth_context *ctx)\n \tif (!strncmp(ctx->key_file, \"pkcs11:\", strlen(\"pkcs11:\")))\n \t\tpkcs11_key = true;\n \n+#ifndef CONFIG_MKEFICAPSULE_DISABLE_PKCS11\n \tif (pkcs11_cert || pkcs11_key) {\n \t\tlib = getenv(\"PKCS11_MODULE_PATH\");\n \t\tif (!lib) {\n@@ -259,6 +262,7 @@ static int create_auth_data(struct auth_context *ctx)\n \t\t\treturn -1;\n \t\t}\n \t}\n+#endif\n \n \tif (!pkcs11_cert) {\n \t\tret = read_bin_file(ctx->cert_file, &cert.data, &file_size);\n@@ -301,6 +305,7 @@ static int create_auth_data(struct auth_context *ctx)\n \n \t/* load x509 certificate */\n \tif (pkcs11_cert) {\n+#ifndef CONFIG_MKEFICAPSULE_DISABLE_PKCS11\n \t\tret = gnutls_pkcs11_obj_list_import_url4(&obj_list, &obj_list_size,\n \t\t\t\t\t\t\t ctx->cert_file, 0);\n \t\tif (ret < 0 || obj_list_size == 0) {\n@@ -309,6 +314,10 @@ static int create_auth_data(struct auth_context *ctx)\n \t\t}\n \n \t\tgnutls_x509_crt_import_pkcs11(x509, obj_list[0]);\n+#else\n+\t\tfprintf(stdout, \"Pkcs11 support is disabled\\n\");\n+\t\treturn -1;\n+#endif\n \t} else {\n \t\tret = gnutls_x509_crt_import(x509, &cert, GNUTLS_X509_FMT_PEM);\n \t\tif (ret < 0) {\n@@ -320,12 +329,17 @@ static int create_auth_data(struct auth_context *ctx)\n \n \t/* load a private key */\n \tif (pkcs11_key) {\n+#ifndef CONFIG_MKEFICAPSULE_DISABLE_PKCS11\n \t\tret = gnutls_privkey_import_pkcs11_url(pkey, ctx->key_file);\n \t\tif (ret < 0) {\n \t\t\tfprintf(stderr, \"error in %d: %s\\n\", __LINE__,\n \t\t\t\tgnutls_strerror(ret));\n \t\t\treturn -1;\n \t\t}\n+#else\n+\t\tfprintf(stderr, \"Pkcs11 support is disabled\\n\");\n+\t\treturn -1;\n+#endif\n \t} else {\n \t\tret = gnutls_privkey_import_x509_raw(pkey, &key, GNUTLS_X509_FMT_PEM,\n \t\t\t\t\t\t     0, 0);\n@@ -403,11 +417,12 @@ static int create_auth_data(struct auth_context *ctx)\n \t *   gnutls_free(signature.data);\n \t */\n \n+#ifndef CONFIG_MKEFICAPSULE_DISABLE_PKCS11\n \tif (pkcs11_cert || pkcs11_key) {\n \t\tgnutls_global_deinit();\n \t\tgnutls_pkcs11_deinit();\n \t}\n-\n+#endif\n \treturn 0;\n }\n \n","prefixes":["v2"]}