Use SunPKCS11 Attributes Configuration to set CKA_SIGN=true on SecretKey generate/import operations in FIPS mode, see: https://docs.oracle.com/javase/8/docs/technotes/guides/security/p11guide.html#ATTRS Resolves: rhbz#2102435
		
			
				
	
	
		
			9 lines
		
	
	
		
			197 B
		
	
	
	
		
			INI
		
	
	
	
	
	
			
		
		
	
	
			9 lines
		
	
	
		
			197 B
		
	
	
	
		
			INI
		
	
	
	
	
	
| name = NSS-FIPS
 | |
| nssLibraryDirectory = @NSS_LIBDIR@
 | |
| nssSecmodDirectory = sql:/etc/pki/nssdb
 | |
| nssDbMode = readOnly
 | |
| nssModule = fips
 | |
| 
 | |
| attributes(*,CKO_SECRET_KEY,CKK_GENERIC_SECRET)={ CKA_SIGN=true }
 | |
| 
 |