Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
Name: opencryptoki-ccatok | Distribution: AlmaLinux |
Version: 3.22.0 | Vendor: AlmaLinux |
Release: 3.el9 | Build date: Wed Apr 3 17:18:01 2024 |
Group: Unspecified | Build host: s390x-builder02.almalinux.org |
Size: 765659 | Source RPM: opencryptoki-3.22.0-3.el9.src.rpm |
Packager: AlmaLinux Packaging Team <packager@almalinux.org> | |
Url: https://github.com/opencryptoki/opencryptoki | |
Summary: CCA cryptographic devices (secure-key) support for opencryptoki |
Opencryptoki implements the PKCS#11 specification v2.20 for a set of cryptographic hardware, such as IBM 4764 and 4765 crypto cards, and the Trusted Platform Module (TPM) chip. Opencryptoki also brings a software token implementation that can be used without any cryptographic hardware. This package brings the necessary libraries and files to support CCA devices in the opencryptoki stack. CCA is an interface to IBM cryptographic hardware such as IBM 4764 or 4765 that uses the "co-processor" or "secure-key" path.
CPL
* Fri Feb 16 2024 Than Ngo <than@redhat.com> - 3.22.0-3 - Fix implicit rejection with RSA keys with empty CKA_PRIVATE_EXPONENT Related: RHEL-22792 * Thu Feb 08 2024 Than Ngo <than@redhat.com> - 3.22.0-2 - timing side-channel in handling of RSA PKCS#1 v1.5 padded ciphertexts (Marvin) Resolves: RHEL-22792 * Tue Nov 21 2023 Than Ngo <than@redhat.com> - 3.22.0-1 - Resolves: RHEL-11412, rebase to 3.22.0 - Resolves: RHEL-10569, openCryptoki for PKCS #11 3.0 * Fri Jul 14 2023 Than Ngo <than@redhat.com> - 3.21.0-8 - Resolves: #2222592, p11sak tool: slot option does not accept argument 0 for slot index 0 - Resolves: #2222596, p11sak fails as soon as there reside non-key objects * Tue Jun 13 2023 Than Ngo <than@redhat.com> - 3.21.0-5 - add requirement on selinux-policy >= 38.1.14-1 for pkcsslotd policy sandboxing Related: #2160061 * Fri May 26 2023 Than Ngo <than@redhat.com> - 3.21.0-4 - add verify attributes for opencryptoki.conf to ignore the verification Related: #2160061 * Mon May 22 2023 Than Ngo <than@redhat.com> - 3.21.0-3 - Resolves: #2110497, concurrent MK rotation for cca token - Resolves: #2110498, concurrent MK rotation for ep11 token - Resolves: #2110499, ep11 token: PKCS #11 3.0 - support AES_XTS - Resolves: #2111010, cca token: protected key support - Resolves: #2160061, rebase to 3.21.0 - Resolves: #2160105, pkcsslotd hardening - Resolves: #2160107, p11sak support Dilithium and Kyber keys - Resolves: #2160109, ica and soft tokens: PKCS #11 3.0 - support AES_XTS * Mon Jan 30 2023 Than Ngo <than@redhat.com> - 3.19.0-2 - Resolves: #2044182, Support of ep11 token for new IBM Z Hardware (IBM z16) * Tue Oct 11 2022 Than Ngo <than@redhat.com> - 3.19.0-1 - Resolves: #2126294, opencryptoki fails after generating > 500 RSA keys - Resolves: #2110314, rebase to 3.19.0 - Resolves: #2110989, openCryptoki key generation with expected MKVP only on CCA and EP11 tokens - Resolves: #2110476, openCryptoki ep11 token: master key consistency - Resolves: #2018458, openCryptoki ep11 token: vendor specific key derivation * Fri Jul 29 2022 Than Ngo <than@redhat.com> - 3.18.0-4 - Related: #2044179, do not touch opencryptoki.conf if it is in place already and even if it is unchanged * Tue Jun 07 2022 Than Ngo <than@redhat.com> - 3.18.0-3 - Related: #2044179, fix json output * Mon May 09 2022 Than Ngo <than@redhat.com> - 3.18.0-2 - Related: #2044179, add missing strength.conf * Mon May 09 2022 Than Ngo <than@redhat.com> - 3.18.0-1 - Resolves: #2044179, rebase to 3.18.0 - Resolves: #2068091, pkcsconf -t failed with Segmentation fault in FIPS mode - Resolves: #2066763, Dilithium support not available - Resolves: #2064697, OpenSSL 3.0 Compatibility for IBM Security Libraries and Tools - Resolves: #2044181, support crypto profiles - Resolves: #2044180, add crypto counters * Tue May 03 2022 Than Ngo <than@redhat.com> - 3.17.0-6 - Resolves: #2066763, Dilithium support not available * Mon Mar 14 2022 Than Ngo <than@redhat.com> - 3.17.0-5 - Resolves: #2064697, ICA/EP11: Support libica version 4
/etc/opencryptoki/ccatok.conf /usr/lib/.build-id /usr/lib/.build-id/53 /usr/lib/.build-id/53/16d0d4ff7bbfe755fa3c939490d29c2f1a3e56 /usr/lib/.build-id/9d /usr/lib/.build-id/9d/b19ad7c8452f16515496df519fa0207779d456 /usr/lib64/opencryptoki/stdll/PKCS11_CCA.so /usr/lib64/opencryptoki/stdll/libpkcs11_cca.la /usr/lib64/opencryptoki/stdll/libpkcs11_cca.so /usr/lib64/opencryptoki/stdll/libpkcs11_cca.so.0 /usr/lib64/opencryptoki/stdll/libpkcs11_cca.so.0.0.0 /usr/sbin/pkcscca /usr/share/doc/opencryptoki-ccatok /usr/share/doc/opencryptoki-ccatok/README.cca_stdll /usr/share/man/man1/pkcscca.1.gz /var/lib/opencryptoki/ccatok /var/lib/opencryptoki/ccatok/TOK_OBJ
Generated by rpm2html 1.8.1
Fabrice Bellet, Thu Nov 7 08:00:08 2024