2d53004059
Use SunPKCS11 Attributes Configuration to set CKA_SIGN=true on SecretKey generate/import operations in FIPS mode, see: https://docs.oracle.com/javase/8/docs/technotes/guides/security/p11guide.html#ATTRS
9 lines
197 B
INI
9 lines
197 B
INI
name = NSS-FIPS
|
|
nssLibraryDirectory = @NSS_LIBDIR@
|
|
nssSecmodDirectory = sql:/etc/pki/nssdb
|
|
nssDbMode = readOnly
|
|
nssModule = fips
|
|
|
|
attributes(*,CKO_SECRET_KEY,CKK_GENERIC_SECRET)={ CKA_SIGN=true }
|
|
|