I'm announcing a release of tpm2-pkcs11 version 1.2.0, available here:
Which has the following changelog:
* Fix PSS signatures. Non-FIPS mode TPMs produce PSS signatures with a
max salt len that poses interoperability issues with verifying clients,
notably TLS in OpenSSL.
* Handle Esys\_LoadExternal() API change where the hierarchy handle switches to an
ESYS\_TR rather than a TPM2\_RH\_.