Commit Graph

24 Commits

Author SHA1 Message Date
Than Ngo
5dccb92199 - Fix implicit rejection with RSA keys with empty CKA_PRIVATE_EXPONENT
Related: RHEL-22791
2024-02-16 12:24:04 +01:00
Than Ngo
39b1da5188 timing side-channel in handling of RSA PKCS#1 v1.5 padded ciphertexts (Marvin)
Resolves: RHEL-22791
2024-02-11 23:43:53 +01:00
Than Ngo
5f26da258b Resolves: RHEL-11413, update to 3.22.0 2023-11-23 14:05:02 +00:00
Karel Srot
a658fde51d CI: Add SW token update plan
Resolves: RHEL-840
2023-07-24 08:19:50 +02:00
Than Ngo
e698005342 Resolves: #2223588, FTBFS 2023-07-18 14:22:24 +02:00
Than Ngo
c390af2f87 Related: #2222595, add triggerun to reload daemon 2023-07-18 12:16:24 +02:00
Than Ngo
517add43b1 Resolves: #2222595, p11sak tool: slot option does not accept argument 0 for slot index 0
Resolves: #2222594, p11sak fails as soon as there reside non-key objects
2023-07-14 16:51:30 +02:00
Than Ngo
19af14b3a5 - add workaround for segfault in PEM_write_bio() on OpenSSL 1.1.1
Related: #2159741
2023-07-05 10:00:16 +02:00
Than Ngo
a4b916ba16 - add requirement on selinux-policy >= 3.14.3-121 for pkcsslotd policy sandboxing
Related: #215969
2023-06-13 12:11:05 +02:00
Than Ngo
c89d9c9606 - add requirement on selinux-policy >= 3.14.3-121 for pkcsslotd policy sandboxing
Related: #2159697
2023-06-13 12:10:11 +02:00
Than Ngo
5bc4f8b724 - add verify attributes for opencryptoki.conf to ignore the verification
- drop unnecessary opencryptoki-3.11.0-group.patch

Related: #2159697
2023-05-25 18:03:03 +02:00
Than Ngo
4c8aef5468 - pkcsstats: Fix handling of user name
- p11sak: Fix user confirmation prompt behavior when stdin is closed
Related: #2159697
2023-05-22 14:14:25 +00:00
Karel Srot
5ddc3c6763 Enable CI testing for c8s branch.
Resolves: RHEL-479
2023-05-19 07:36:27 +00:00
Than Ngo
25187255f5 add missing /var/lib/opencryptoki/HSM_MK_CHANGE
disable unsupported sandbox options and add /run to ReadWritePaths to exclude /run directory from being made read-only on rhel8
Related: #2159697
2023-05-17 13:41:18 +02:00
Than Ngo
9e22d31c4b Resolves: #1984865, ep11 and cca: support concurrent HSM master key changes
Resolves: #2110500, ep11 token: PKCS #11 3.0 - support AES_XTS
Resolves: #2111011, cca token: protected key support
Resolves: #2159697, update to 3.21.0
Resolves: #2159740, pkcsslotd hardening
Resolves: #2159741, p11sak support Dilithium and Kyber keys
Resolves: #2159742, ica and soft tokens: PKCS #11 3.0 - support AES_XTS
2023-05-16 10:15:14 +02:00
Troy Dawson
1232683448 Bring gating.yaml over from Brew dist-git
Signed-off-by: Troy Dawson <tdawson@redhat.com>
2023-03-10 11:09:33 -08:00
James Antill
4d2f097f20 Import rpm: c8s 2023-02-27 14:37:06 -05:00
CentOS Sources
fc8d8dc654 Auto sync2gitlab import of opencryptoki-3.19.0-2.el8.src.rpm 2023-02-01 08:10:05 +00:00
CentOS Sources
b3ee30c50c Auto sync2gitlab import of opencryptoki-3.19.0-1.el8.src.rpm 2022-11-09 04:14:42 +00:00
CentOS Sources
ad8244536e Auto sync2gitlab import of opencryptoki-3.18.0-3.el8.src.rpm 2022-08-03 10:14:45 +00:00
CentOS Sources
08f86ef6ef Auto sync2gitlab import of opencryptoki-3.18.0-2.el8.src.rpm 2022-06-08 08:16:32 +00:00
CentOS Sources
0abc49b494 Auto sync2gitlab import of opencryptoki-3.18.0-1.el8.src.rpm 2022-06-02 14:32:16 +00:00
James Antill
80c1420375 Auto sync2gitlab import of opencryptoki-3.17.0-3.el8.src.rpm 2022-05-26 12:13:03 -04:00
James Antill
ca16975ff7 Initial c8s branch. 2022-05-26 12:13:01 -04:00