From 0b70f32c2443fed62afd4704b3694b04340bf05c Mon Sep 17 00:00:00 2001 From: AlmaLinux RelEng Bot Date: Mon, 30 Mar 2026 10:49:45 -0400 Subject: [PATCH] import CS openwsman-2.8.1-2.el9 --- .gitignore | 1 + .openwsman.metadata | 1 + .../openwsman-2.4.12-ruby-binding-build.patch | 54 +++++++- SOURCES/openwsman-2.6.2-openssl-1.1-fix.patch | 54 ++++---- SOURCES/openwsman-2.6.8-CVE-2019-3816.patch | 79 ----------- SOURCES/openwsman-2.6.8-CVE-2019-3833.patch | 94 ------------- ...sman-2.6.8-http-unauthorized-improve.patch | 56 -------- ...penwsman-2.6.8-ssl-certs-gen-changes.patch | 102 ++++++++++++++ .../openwsman-2.6.8-update-ssleay-conf.patch | 11 +- .../openwsman-2.8.1-facility-definition.patch | 16 +++ SOURCES/openwsman-2.8.1-post-quantum.patch | 128 ++++++++++++++++++ SPECS/openwsman.spec | 123 +++++++++++++---- 12 files changed, 427 insertions(+), 292 deletions(-) delete mode 100644 SOURCES/openwsman-2.6.8-CVE-2019-3816.patch delete mode 100644 SOURCES/openwsman-2.6.8-CVE-2019-3833.patch delete mode 100644 SOURCES/openwsman-2.6.8-http-unauthorized-improve.patch create mode 100644 SOURCES/openwsman-2.6.8-ssl-certs-gen-changes.patch create mode 100644 SOURCES/openwsman-2.8.1-facility-definition.patch create mode 100644 SOURCES/openwsman-2.8.1-post-quantum.patch diff --git a/.gitignore b/.gitignore index b2157a1..6da27f6 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,3 @@ SOURCES/openwsmand.8.gz SOURCES/v2.6.8.tar.gz +SOURCES/v2.8.1.tar.gz diff --git a/.openwsman.metadata b/.openwsman.metadata index 68fbfd5..19e768b 100644 --- a/.openwsman.metadata +++ b/.openwsman.metadata @@ -1,2 +1,3 @@ a6a8bbbfa71ce04bedae55f2f06ce97089b6c5e1 SOURCES/openwsmand.8.gz e061a41b3d5f5fa4ee284726d283e15f4a0e8c46 SOURCES/v2.6.8.tar.gz +1ecfd2f1f3bc9cc3e56065c52f796390752bc14e SOURCES/v2.8.1.tar.gz diff --git a/SOURCES/openwsman-2.4.12-ruby-binding-build.patch b/SOURCES/openwsman-2.4.12-ruby-binding-build.patch index 1a4e76e..aa940ea 100644 --- a/SOURCES/openwsman-2.4.12-ruby-binding-build.patch +++ b/SOURCES/openwsman-2.4.12-ruby-binding-build.patch @@ -1,12 +1,54 @@ -diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/bindings/ruby/extconf.rb ---- openwsman-2.4.12/bindings/ruby/extconf.rb.orig 2015-02-09 09:28:58.232581263 +0100 -+++ openwsman-2.4.12/bindings/ruby/extconf.rb 2015-02-09 09:38:22.836772879 +0100 -@@ -32,7 +32,7 @@ swig = find_executable("swig") +diff -up openwsman-2.8.1/bindings/ruby/extconf.rb.orig openwsman-2.8.1/bindings/ruby/extconf.rb +--- openwsman-2.8.1/bindings/ruby/extconf.rb.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/bindings/ruby/extconf.rb 2025-10-20 12:55:46.327604671 +0200 +@@ -5,16 +5,31 @@ + require 'mkmf' + # $CFLAGS = "#{$CFLAGS} -Werror" + ++# libwsman requires 'int facility' to be defined by the application ++# Add syslog.h for LOG_DAEMON constant ++$CFLAGS = "#{$CFLAGS} -include syslog.h" ++ + # requires wsman, wsman_client, and libxml2 ++# Add build directory to library search path ++$LDFLAGS = "#{$LDFLAGS} -L/builddir/build/BUILD/openwsman/openwsman-2.8.1/build/src/lib" ++ ++# Add BOTH source include roots (and their /u) to compilation flags ++$CPPFLAGS = "#{$CPPFLAGS} " \ ++"-I/builddir/build/BUILD/openwsman-2.8.1/include " \ ++"-I/builddir/build/BUILD/openwsman-2.8.1/include/u " \ ++"-I/builddir/build/BUILD/openwsman/openwsman-2.8.1/include " \ ++"-I/builddir/build/BUILD/openwsman/openwsman-2.8.1/include/u" + +-unless have_library('wsman', 'wsman_create_doc') ++# Custom test for libwsman that includes facility definition ++unless try_link("#include \n#include \nint facility = LOG_DAEMON;\nint main(void) { (void)wsman_create_doc(); return 0; }", '-lwsman -lxml2') + STDERR.puts "Cannot find wsman_create_doc() in libwsman" + STDERR.puts "Is openwsman-devel installed ?" + exit 1 + end + find_header 'wsman-xml-api.h', '/usr/include/openwsman' + +-unless have_library('wsman_client', 'wsmc_create') ++# Custom test for libwsman_client that includes facility definition ++unless try_link("#include \n#include \nint facility = LOG_DAEMON;\nint main(void) { (void)wsmc_create(\"localhost\", 80, \"/wsman\", \"http\", \"u\", \"p\"); return 0; }", '-lwsman_client -lwsman -lxml2') + STDERR.puts "Cannot find wsmc_create() in libwsman_client" + STDERR.puts "Is openwsman-devel installed ?" + exit 1 +@@ -32,8 +47,14 @@ swig = find_executable("swig") raise "SWIG not found" unless swig major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.6.8/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} " \ ++"-I. -I/usr/include/openwsman " \ ++"-I/builddir/build/BUILD/openwsman-2.8.1/include " \ ++"-I/builddir/build/BUILD/openwsman-2.8.1/include/u " \ ++"-I/builddir/build/BUILD/openwsman/openwsman-2.8.1/include " \ ++"-I/builddir/build/BUILD/openwsman/openwsman-2.8.1/include/u " \ ++"-o openwsman_wrap.c openwsman.i") - $CPPFLAGS = "-I/usr/include/openwsman -I.." +-$CPPFLAGS = "-I/usr/include/openwsman -I.." ++$CPPFLAGS = "#{$CPPFLAGS} -I/usr/include/openwsman -I.." + create_makefile('_openwsman') diff --git a/SOURCES/openwsman-2.6.2-openssl-1.1-fix.patch b/SOURCES/openwsman-2.6.2-openssl-1.1-fix.patch index 98f6bc2..9322adb 100644 --- a/SOURCES/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/SOURCES/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,6 +1,6 @@ -diff -up openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig openwsman-2.6.8/src/server/shttpd/compat_unix.h ---- openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/compat_unix.h 2018-11-22 13:30:10.756423510 +0100 +diff -up openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig openwsman-2.8.1/src/server/shttpd/compat_unix.h +--- openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/compat_unix.h 2025-02-03 09:11:35.072818890 +0100 @@ -27,10 +27,6 @@ pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) #endif /* !NO_THREADS */ @@ -12,10 +12,10 @@ diff -up openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig openwsman-2.6.8/sr #define DIRSEP '/' #define IS_DIRSEP_CHAR(c) ((c) == '/') #define O_BINARY 0 -diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/server/shttpd/io_ssl.c ---- openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/io_ssl.c 2018-11-22 13:30:10.757423510 +0100 -@@ -11,23 +11,6 @@ +diff -up openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig openwsman-2.8.1/src/server/shttpd/io_ssl.c +--- openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/io_ssl.c 2025-02-03 09:12:22.387355905 +0100 +@@ -11,28 +11,6 @@ #include "defs.h" #if !defined(NO_SSL) @@ -29,8 +29,13 @@ diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/ser - {"SSL_set_fd", {0}}, - {"SSL_new", {0}}, - {"SSL_CTX_new", {0}}, +-#if OPENSSL_VERSION_NUMBER < 0x10100000L - {"SSLv23_server_method", {0}}, - {"SSL_library_init", {0}}, +-#else +- {"TLS_server_method", {0}}, +- {"OPENSSL_init_ssl", {0}}, +-#endif - {"SSL_CTX_use_PrivateKey_file", {0}}, - {"SSL_CTX_use_certificate_file",{0}}, - {NULL, {0}} @@ -39,10 +44,10 @@ diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/ser void _shttpd_ssl_handshake(struct stream *stream) { -diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c ---- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2018-11-22 13:30:41.314416695 +0100 -@@ -1476,20 +1476,14 @@ set_ssl(struct shttpd_ctx *ctx, const ch +diff -up openwsman-2.8.1/src/server/shttpd/shttpd.c.orig openwsman-2.8.1/src/server/shttpd/shttpd.c +--- openwsman-2.8.1/src/server/shttpd/shttpd.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/shttpd.c 2025-02-03 09:13:43.415562784 +0100 +@@ -1510,25 +1510,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch int retval = FALSE; EC_KEY* key; @@ -59,20 +64,20 @@ diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/ser - } - /* Initialize SSL crap */ -+ debug("Initialize SSL"); -+ SSL_load_error_strings(); -+#if OPENSSL_VERSION_NUMBER >= 0x10100000L -+ OPENSSL_init_ssl(0, NULL); -+#else - SSL_library_init(); -+#endif + #if OPENSSL_VERSION_NUMBER < 0x10100000L + SSL_library_init(); if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) - _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); -diff -up openwsman-2.6.8/src/server/shttpd/ssl.h.orig openwsman-2.6.8/src/server/shttpd/ssl.h ---- openwsman-2.6.8/src/server/shttpd/ssl.h.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/ssl.h 2018-11-22 13:30:10.757423510 +0100 -@@ -12,52 +12,4 @@ + #else +- OPENSSL_init_ssl(); ++ OPENSSL_init_ssl(0, NULL); + if ((CTX = SSL_CTX_new(TLS_server_method())) == NULL) + #endif + _shttpd_report_ssl_error("SSL_CTX_new failed", NULL); +diff -up openwsman-2.8.1/src/server/shttpd/ssl.h.orig openwsman-2.8.1/src/server/shttpd/ssl.h +--- openwsman-2.8.1/src/server/shttpd/ssl.h.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/ssl.h 2025-02-03 09:14:43.142975166 +0100 +@@ -12,55 +12,4 @@ #include @@ -120,6 +125,9 @@ diff -up openwsman-2.6.8/src/server/shttpd/ssl.h.orig openwsman-2.6.8/src/server -#if OPENSSL_VERSION_NUMBER < 0x10100000L -#define SSLv23_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() -#define SSL_library_init() (* (int (*)(void)) FUNC(10))() +-#else +-#define TLS_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() +-#define OPENSSL_init_ssl() (* (int (*)(void)) FUNC(10))() #endif -#define SSL_CTX_use_PrivateKey_file(x,y,z) (* (int (*)(SSL_CTX *, \ - const char *, int)) FUNC(11))((x), (y), (z)) diff --git a/SOURCES/openwsman-2.6.8-CVE-2019-3816.patch b/SOURCES/openwsman-2.6.8-CVE-2019-3816.patch deleted file mode 100644 index aa8835f..0000000 --- a/SOURCES/openwsman-2.6.8-CVE-2019-3816.patch +++ /dev/null @@ -1,79 +0,0 @@ -diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c ---- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 08:52:06.112090942 +0100 -+++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:01:15.496156789 +0100 -@@ -336,10 +336,12 @@ date_to_epoch(const char *s) - } - - static void --remove_double_dots(char *s) -+remove_all_leading_dots(char *s) - { - char *p = s; - -+ while (*s != '\0' && *s == '.') s++; -+ - while (*s != '\0') { - *p++ = *s++; - if (s[-1] == '/' || s[-1] == '\\') -@@ -546,7 +548,7 @@ decide_what_to_do(struct conn *c) - *c->query++ = '\0'; - - _shttpd_url_decode(c->uri, strlen(c->uri), c->uri, strlen(c->uri) + 1); -- remove_double_dots(c->uri); -+ remove_all_leading_dots(c->uri); - - root = c->ctx->options[OPT_ROOT]; - if (strlen(c->uri) + strlen(root) >= sizeof(path)) { -@@ -556,6 +558,7 @@ decide_what_to_do(struct conn *c) - - (void) _shttpd_snprintf(path, sizeof(path), "%s%s", root, c->uri); - -+ DBG(("decide_what_to_do -> processed path: [%s]", path)); - /* User may use the aliases - check URI for mount point */ - if (is_alias(c->ctx, c->uri, &alias_uri, &alias_path) != NULL) { - (void) _shttpd_snprintf(path, sizeof(path), "%.*s%s", -@@ -572,7 +575,10 @@ decide_what_to_do(struct conn *c) - if ((ruri = _shttpd_is_registered_uri(c->ctx, c->uri)) != NULL) { - _shttpd_setup_embedded_stream(c, - ruri->callback, ruri->callback_data); -- } else -+ } else { -+ _shttpd_send_server_error(c, 403, "Forbidden"); -+ } -+#if 0 - if (strstr(path, HTPASSWD)) { - /* Do not allow to view passwords files */ - _shttpd_send_server_error(c, 403, "Forbidden"); -@@ -656,6 +662,7 @@ decide_what_to_do(struct conn *c) - } else { - _shttpd_send_server_error(c, 500, "Internal Error"); - } -+#endif - } - - static int -diff -up openwsman-2.6.8/src/server/wsmand.c.orig openwsman-2.6.8/src/server/wsmand.c ---- openwsman-2.6.8/src/server/wsmand.c.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/wsmand.c 2019-03-13 09:03:25.919181279 +0100 -@@ -198,6 +198,10 @@ static void daemonize(void) - int fd; - char *pid; - -+ /* Change our CWD to / */ -+ i = chdir("/"); -+ assert(i == 0); -+ - if (wsmand_options_get_foreground_debug() > 0) { - return; - } -@@ -214,10 +218,6 @@ static void daemonize(void) - log_pid = 0; - setsid(); - -- /* Change our CWD to / */ -- i=chdir("/"); -- assert(i == 0); -- - /* Close all file descriptors. */ - for (i = getdtablesize(); i >= 0; --i) - close(i); diff --git a/SOURCES/openwsman-2.6.8-CVE-2019-3833.patch b/SOURCES/openwsman-2.6.8-CVE-2019-3833.patch deleted file mode 100644 index 301724f..0000000 --- a/SOURCES/openwsman-2.6.8-CVE-2019-3833.patch +++ /dev/null @@ -1,94 +0,0 @@ -diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c ---- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 09:32:32.417633057 +0100 -+++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:58:04.482486589 +0100 -@@ -705,11 +705,11 @@ parse_http_request(struct conn *c) - _shttpd_send_server_error(c, 500, "Cannot allocate request"); - } - -+ io_inc_tail(&c->rem.io, req_len); -+ - if (c->loc.flags & FLAG_CLOSED) - return; - -- io_inc_tail(&c->rem.io, req_len); -- - DBG(("Conn %d: parsing request: [%.*s]", c->rem.chan.sock, req_len, s)); - c->rem.flags |= FLAG_HEADERS_PARSED; - -@@ -975,7 +975,7 @@ write_stream(struct stream *from, struct - } - - --static void -+static int - connection_desctructor(struct llhead *lp) - { - struct conn *c = LL_ENTRY(lp, struct conn, link); -@@ -999,7 +999,8 @@ connection_desctructor(struct llhead *lp - * Check the "Connection: " header before we free c->request - * If it its 'keep-alive', then do not close the connection - */ -- do_close = (c->ch.connection.v_vec.len >= vec.len && -+ do_close = c->rem.flags & FLAG_CLOSED || -+ (c->ch.connection.v_vec.len >= vec.len && - !_shttpd_strncasecmp(vec.ptr,c->ch.connection.v_vec.ptr,vec.len)) || - (c->major_version < 1 || - (c->major_version >= 1 && c->minor_version < 1)); -@@ -1021,7 +1022,7 @@ connection_desctructor(struct llhead *lp - io_clear(&c->loc.io); - c->birth_time = _shttpd_current_time; - if (io_data_len(&c->rem.io) > 0) -- process_connection(c, 0, 0); -+ return 1; - } else { - if (c->rem.io_class != NULL) - c->rem.io_class->close(&c->rem); -@@ -1032,6 +1033,8 @@ connection_desctructor(struct llhead *lp - - free(c); - } -+ -+ return 0; - } - - static void -@@ -1039,7 +1042,7 @@ worker_destructor(struct llhead *lp) - { - struct worker *worker = LL_ENTRY(lp, struct worker, link); - -- free_list(&worker->connections, connection_desctructor); -+ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); - free(worker); - } - -@@ -1072,6 +1075,8 @@ add_to_set(int fd, fd_set *set, int *max - static void - process_connection(struct conn *c, int remote_ready, int local_ready) - { -+again: -+ - /* Read from remote end if it is ready */ - if (remote_ready && io_space_len(&c->rem.io)) - read_stream(&c->rem); -@@ -1100,7 +1105,11 @@ process_connection(struct conn *c, int r - if ((_shttpd_current_time > c->expire_time) || - (c->rem.flags & FLAG_CLOSED) || - ((c->loc.flags & FLAG_CLOSED) && !io_data_len(&c->loc.io))) -- connection_desctructor(&c->link); -+ if (connection_desctructor(&c->link)) { -+ remote_ready = 0; -+ local_ready = 0; -+ goto again; -+ } - } - - static int -@@ -1642,7 +1651,7 @@ worker_function(void *param) - while (worker->exit_flag == 0) - poll_worker(worker, 1000 * 10); - -- free_list(&worker->connections, connection_desctructor); -+ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); - free(worker); - } - diff --git a/SOURCES/openwsman-2.6.8-http-unauthorized-improve.patch b/SOURCES/openwsman-2.6.8-http-unauthorized-improve.patch deleted file mode 100644 index c9cdc45..0000000 --- a/SOURCES/openwsman-2.6.8-http-unauthorized-improve.patch +++ /dev/null @@ -1,56 +0,0 @@ -diff -up openwsman-2.6.8/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.8/src/lib/wsman-curl-client-transport.c ---- openwsman-2.6.8/src/lib/wsman-curl-client-transport.c.orig 2022-11-24 10:02:08.114053046 +0100 -+++ openwsman-2.6.8/src/lib/wsman-curl-client-transport.c 2022-11-24 10:02:08.119053046 +0100 -@@ -455,6 +455,7 @@ wsmc_handler( WsManClient *cl, - long http_code; - long auth_avail = 0; - char *_user = NULL, *_pass = NULL; -+ int _no_auth = 0; /* 0 if authentication is used, 1 if no authentication was used */ - u_buf_t *response = NULL; - //char *soapaction; - char *tmp_str = NULL; -@@ -554,6 +555,7 @@ wsmc_handler( WsManClient *cl, - _user = wsmc_get_user(cl); - _pass = wsmc_get_password(cl); - if (_user && _pass && cl->data.auth_set) { -+ _no_auth = 0; - r = curl_easy_setopt(curl, CURLOPT_HTTPAUTH, cl->data.auth_set); - if (r != CURLE_OK) { - cl->fault_string = u_strdup(curl_easy_strerror(r)); -@@ -574,6 +576,11 @@ wsmc_handler( WsManClient *cl, - curl_err("curl_easy_setopt(curl, CURLOPT_USERPWD, ..) failed"); - goto DONE; - } -+ } else { -+ /* request without user credentials, remember this for -+ * later use when it might become necessary to print an error message -+ */ -+ _no_auth = 1; - } - - if (wsman_debug_level_debugged(DEBUG_LEVEL_MESSAGE)) { -@@ -606,6 +613,24 @@ wsmc_handler( WsManClient *cl, - break; - case 401: - // The server requires authentication. -+ /* RFC 2616 states: -+ * -+ * If the request already included Authorization credentials, then the 401 -+ * response indicates that authorization has been refused for those -+ * credentials. If the 401 response contains the same challenge as the -+ * prior response, and the user agent has already attempted -+ * authentication at least once, then the user SHOULD be presented the -+ * entity that was given in the response, since that entity might -+ * include relevant diagnostic information. -+ */ -+ if (_no_auth == 0) { -+ /* no authentication credentials were used. It is only -+ * possible to write a message about the current situation. There -+ * is no information about the last attempt to access the resource. -+ * Maybe at a later point in time I will implement more state information. -+ */ -+ fprintf(stdout,"Authentication failed, please retry\n"); -+ } - break; - default: - // The status code does not indicate success. diff --git a/SOURCES/openwsman-2.6.8-ssl-certs-gen-changes.patch b/SOURCES/openwsman-2.6.8-ssl-certs-gen-changes.patch new file mode 100644 index 0000000..0f0b96a --- /dev/null +++ b/SOURCES/openwsman-2.6.8-ssl-certs-gen-changes.patch @@ -0,0 +1,102 @@ +diff -up openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig openwsman-2.8.1/etc/owsmangencert.sh.cmake +--- openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/etc/owsmangencert.sh.cmake 2025-10-17 10:16:34.482996406 +0200 +@@ -1,10 +1,74 @@ +-#!/bin/sh +- + #!/bin/sh -e + + CERTFILE=@WSMANCONF_DIR@/servercert.pem + KEYFILE=@WSMANCONF_DIR@/serverkey.pem + CNFFILE=@WSMANCONF_DIR@/ssleay.cnf ++CAFILE=@WSMANCONF_DIR@/ca.crt ++DAYS=365 ++ ++function create_ssl_cnf ++{ ++ # Get minimum RSA key length at current security level ++ # This workarounds openssl not enforcing min. key length enforced by current security level ++ KEYSIZE=`grep min_rsa_size /etc/crypto-policies/state/CURRENT.pol | cut -d ' ' -f 3` ++ ++ # Create OpenSSL configuration files for generating certificates ++ echo "[ req ]" > $CNFFILE ++ echo "default_bits = $KEYSIZE" >> $CNFFILE ++ echo "default_keyfile = privkey.pem" >> $CNFFILE ++ echo "distinguished_name = req_distinguished_name" >> $CNFFILE ++ ++ echo "[ req_distinguished_name ]" >> $CNFFILE ++ echo "countryName = Country Name (2 letter code)" >> $CNFFILE ++ echo "countryName_default = GB" >> $CNFFILE ++ echo "countryName_min = 2" >> $CNFFILE ++ echo "countryName_max = 2" >> $CNFFILE ++ ++ echo "stateOrProvinceName = State or Province Name (full name)" >> $CNFFILE ++ echo "stateOrProvinceName_default = Some-State" >> $CNFFILE ++ ++ echo "localityName = Locality Name (eg, city)" >> $CNFFILE ++ ++ echo "organizationName = Organization Name (eg, company; recommended)" >> $CNFFILE ++ echo "organizationName_max = 64" >> $CNFFILE ++ ++ echo "organizationalUnitName = Organizational Unit Name (eg, section)" >> $CNFFILE ++ echo "organizationalUnitName_max = 64" >> $CNFFILE ++ ++ echo "commonName = server name (eg. ssl.domain.tld; required!!!)" >> $CNFFILE ++ echo "commonName_max = 80" >> $CNFFILE ++ ++ echo "emailAddress = Email Address" >> $CNFFILE ++ echo "emailAddress_max = 85" >> $CNFFILE ++} ++ ++function selfsign_sscg() ++{ ++ sscg --quiet \ ++ --lifetime "$DAYS" \ ++ --cert-key-file "$KEYFILE" \ ++ --cert-file "$CERTFILE" \ ++ --ca-file "$CAFILE" ++} ++ ++function selfsign_openssl() ++{ ++ ++ echo ++ echo creating selfsigned certificate ++ echo "replace it with one signed by a certification authority (CA)" ++ echo ++ echo enter your ServerName at the Common Name prompt ++ echo ++ ++ # use special .cnf, because with normal one no valid selfsigned ++ # certificate is created ++ ++ openssl req -days $DAYS $@ -config $CNFFILE \ ++ -new -x509 -nodes -out $CERTFILE \ ++ -keyout $KEYFILE ++ chmod 600 $KEYFILE ++} + + if [ "$1" != "--force" -a -f $KEYFILE ]; then + echo "$KEYFILE exists! Use \"$0 --force.\"" +@@ -15,18 +79,7 @@ if [ "$1" = "--force" ]; then + shift + fi + +-echo +-echo creating selfsigned certificate +-echo "replace it with one signed by a certification authority (CA)" +-echo +-echo enter your ServerName at the Common Name prompt +-echo +- +-# use special .cnf, because with normal one no valid selfsigned +-# certificate is created +- +-openssl req -days 365 $@ -config $CNFFILE \ +- -newkey rsa:2048 -x509 -nodes -out $CERTFILE \ +- -keyout $KEYFILE +-chmod 600 $KEYFILE ++create_ssl_cnf + ++# If sscg fails, try openssl ++selfsign_sscg || selfsign_openssl diff --git a/SOURCES/openwsman-2.6.8-update-ssleay-conf.patch b/SOURCES/openwsman-2.6.8-update-ssleay-conf.patch index 15c5c74..c312af5 100644 --- a/SOURCES/openwsman-2.6.8-update-ssleay-conf.patch +++ b/SOURCES/openwsman-2.6.8-update-ssleay-conf.patch @@ -1,12 +1,9 @@ -diff -up openwsman-2.6.8/etc/ssleay.cnf.orig openwsman-2.6.8/etc/ssleay.cnf ---- openwsman-2.6.8/etc/ssleay.cnf.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/etc/ssleay.cnf 2020-09-22 14:27:56.216306882 +0200 -@@ -2,10 +2,8 @@ - # SSLeay example configuration file. +diff -up openwsman-2.7.1/etc/ssleay.cnf.orig openwsman-2.7.1/etc/ssleay.cnf +--- openwsman-2.7.1/etc/ssleay.cnf.orig 2021-11-09 08:27:48.577749509 +0100 ++++ openwsman-2.7.1/etc/ssleay.cnf 2021-11-09 08:28:10.499967010 +0100 +@@ -3,7 +3,7 @@ # --RANDFILE = /dev/random -- [ req ] -default_bits = 1024 +default_bits = 2048 diff --git a/SOURCES/openwsman-2.8.1-facility-definition.patch b/SOURCES/openwsman-2.8.1-facility-definition.patch new file mode 100644 index 0000000..8ce986a --- /dev/null +++ b/SOURCES/openwsman-2.8.1-facility-definition.patch @@ -0,0 +1,16 @@ +diff -up openwsman-2.8.1/src/lib/u/log.c.orig openwsman-2.8.1/src/lib/u/log.c +--- openwsman-2.8.1/src/lib/u/log.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/lib/u/log.c 2025-10-22 09:22:30.104144805 +0200 +@@ -25,8 +25,10 @@ + + #include + +-/* applications that use libu will define their own "int facility" variable */ +-extern int facility; ++/* Define facility in the library for backward compatibility with openwsman 2.6.8 ++ * Applications can still override this if needed */ ++int facility = LOG_DAEMON; ++ + + /* log hook. if not-zero use this function to write log messages */ + static u_log_hook_t hook = NULL; diff --git a/SOURCES/openwsman-2.8.1-post-quantum.patch b/SOURCES/openwsman-2.8.1-post-quantum.patch new file mode 100644 index 0000000..3f0f53f --- /dev/null +++ b/SOURCES/openwsman-2.8.1-post-quantum.patch @@ -0,0 +1,128 @@ +diff -up openwsman-2.8.1/etc/openwsman.conf.orig openwsman-2.8.1/etc/openwsman.conf +--- openwsman-2.8.1/etc/openwsman.conf.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/etc/openwsman.conf 2026-01-27 14:55:28.358323530 +0100 +@@ -32,8 +32,12 @@ ipv6 = yes + + # the openwsman server certificate file, in .pem format + ssl_cert_file = /etc/openwsman/servercert.pem ++# the openwsman server certificate fallback file, in .pem format ++#ssl_cert_fallback_file = /etc/openwsman/servercert-fallback.pem + # the openwsman server private key, in .pem format + ssl_key_file = /etc/openwsman/serverkey.pem ++# the openwsman server private key fallback, in .pem format ++#ssl_key_fallback_file = /etc/openwsman/serverkey-fallback.pem + + # space-separated list of SSL protocols to *dis*able + # possible values: SSLv2 SSLv3 TLSv1 TLSv1_1 TLSv1_2 +diff -up openwsman-2.8.1/src/server/shttpd/shttpd.c.orig openwsman-2.8.1/src/server/shttpd/shttpd.c +--- openwsman-2.8.1/src/server/shttpd/shttpd.c.orig 2026-01-27 14:55:28.353983369 +0100 ++++ openwsman-2.8.1/src/server/shttpd/shttpd.c 2026-01-27 15:02:00.178890046 +0100 +@@ -1508,7 +1508,6 @@ set_ssl(struct shttpd_ctx *ctx, const ch + char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols(); + char *ssl_cipher_list = wsmand_options_get_ssl_cipher_list(); + int retval = FALSE; +- EC_KEY* key; + + /* Initialize SSL crap */ + +@@ -1527,11 +1526,15 @@ set_ssl(struct shttpd_ctx *ctx, const ch + else + retval = TRUE; + +- /* This enables ECDH Perfect Forward secrecy. Currently with just the most generic p256 prime curve */ +- key = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1); +- if (key != NULL) { +- SSL_CTX_set_tmp_ecdh(CTX, key); +- EC_KEY_free(key); ++ /* Add fall back certificate/key pair */ ++ if (wsmand_options_get_ssl_cert_fallback_file() && ++ wsmand_options_get_ssl_key_fallback_file()) { ++ if (SSL_CTX_use_certificate_file(CTX, wsmand_options_get_ssl_cert_fallback_file(), SSL_FILETYPE_PEM) != 1) ++ _shttpd_elog(E_LOG, NULL, "cannot open certificate fallback file %s", pem); ++ else if (SSL_CTX_use_PrivateKey_file(CTX, wsmand_options_get_ssl_key_fallback_file(), SSL_FILETYPE_PEM) != 1) ++ _shttpd_elog(E_LOG, NULL, "cannot open fallback PrivateKey %s", pem); ++ else ++ retval = TRUE; + } + + while (ssl_disabled_protocols) { +@@ -1593,6 +1596,26 @@ set_ssl(struct shttpd_ctx *ctx, const ch + } + ctx->ssl_ctx = CTX; + ++ /* Configure TLS key exchange groups with PQC support */ ++ if (SSL_CTX_set1_groups_list(CTX, "X25519MLKEM768:P-256:P-384:X25519") != 1) { ++ unsigned long err = ERR_peek_last_error(); ++ _shttpd_elog(E_LOG, NULL, "SSL: Failed to set PQC groups: %s", ++ ERR_error_string(err, NULL)); ++ /* Fallback to traditional groups */ ++ if (SSL_CTX_set1_groups_list(CTX, "P-256:P-384:X25519") != 1) ++ _shttpd_elog(E_LOG, NULL, "SSL: Failed to set traditional groups"); ++ } ++ ++ /* Configure TLS signature algorithms with PQC support (ML-DSA) */ ++ if (SSL_CTX_set1_sigalgs_list(CTX, "mldsa65:rsa_pss_rsae_sha256:rsa_pss_rsae_sha384:rsa_pss_rsae_sha512:ecdsa_secp256r1_sha256:ecdsa_secp384r1_sha384") != 1) { ++ unsigned long err = ERR_peek_last_error(); ++ _shttpd_elog(E_LOG, NULL, "SSL: Failed to set PQC signature algorithms: %s", ++ ERR_error_string(err, NULL)); ++ /* Fallback to traditional signature algorithms */ ++ if (SSL_CTX_set1_sigalgs_list(CTX, "rsa_pss_rsae_sha256:rsa_pss_rsae_sha384:rsa_pss_rsae_sha512:ecdsa_secp256r1_sha256:ecdsa_secp384r1_sha384") != 1) ++ _shttpd_elog(E_LOG, NULL, "SSL: Failed to set traditional signature algorithms"); ++ } ++ + return (retval); + } + #endif /* NO_SSL */ +diff -up openwsman-2.8.1/src/server/wsmand-daemon.c.orig openwsman-2.8.1/src/server/wsmand-daemon.c +--- openwsman-2.8.1/src/server/wsmand-daemon.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/wsmand-daemon.c 2026-01-27 14:55:28.358709575 +0100 +@@ -76,8 +76,10 @@ static int use_ipv6 = 0; + #endif + static int use_digest = 0; + static char *ssl_key_file = NULL; ++static char *ssl_key_fallback_file = NULL; + static char *service_path = DEFAULT_SERVICE_PATH; + static char *ssl_cert_file = NULL; ++static char *ssl_cert_fallback_file = NULL; + static char *ssl_disabled_protocols = NULL; + static char *ssl_cipher_list = NULL; + static char *pid_file = DEFAULT_PID_PATH; +@@ -186,7 +188,9 @@ int wsmand_read_config(dictionary * ini) + service_path = + iniparser_getstring(ini, "server:service_path", "/wsman"); + ssl_key_file = iniparser_getstr(ini, "server:ssl_key_file"); ++ ssl_key_fallback_file = iniparser_getstr(ini, "server:ssl_key_fallback_file"); + ssl_cert_file = iniparser_getstr(ini, "server:ssl_cert_file"); ++ ssl_cert_fallback_file = iniparser_getstr(ini, "server:ssl_cert_fallback_file"); + ssl_disabled_protocols = iniparser_getstr(ini, "server:ssl_disabled_protocols"); + ssl_cipher_list = iniparser_getstr(ini, "server:ssl_cipher_list"); + use_ipv4 = iniparser_getboolean(ini, "server:ipv4", 1); +@@ -364,6 +368,16 @@ char *wsmand_options_get_ssl_cert_file(v + return ssl_cert_file; + } + ++char *wsmand_options_get_ssl_key_fallback_file(void) ++{ ++ return ssl_key_fallback_file; ++} ++ ++char *wsmand_options_get_ssl_cert_fallback_file(void) ++{ ++ return ssl_cert_fallback_file; ++} ++ + char *wsmand_options_get_ssl_disabled_protocols(void) + { + return ssl_disabled_protocols; +diff -up openwsman-2.8.1/src/server/wsmand-daemon.h.orig openwsman-2.8.1/src/server/wsmand-daemon.h +--- openwsman-2.8.1/src/server/wsmand-daemon.h.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/wsmand-daemon.h 2026-01-27 14:55:28.358825793 +0100 +@@ -76,6 +76,8 @@ int wsmand_options_get_server_port(void) + int wsmand_options_get_server_ssl_port(void); + char *wsmand_options_get_ssl_key_file(void); + char *wsmand_options_get_ssl_cert_file(void); ++char *wsmand_options_get_ssl_key_fallback_file(void); ++char *wsmand_options_get_ssl_cert_fallback_file(void); + char *wsmand_options_get_ssl_disabled_protocols(void); + char *wsmand_options_get_ssl_cipher_list(void); + int wsmand_options_get_digest(void); diff --git a/SPECS/openwsman.spec b/SPECS/openwsman.spec index 6ce9b34..d9dc8bd 100644 --- a/SPECS/openwsman.spec +++ b/SPECS/openwsman.spec @@ -1,9 +1,10 @@ # RubyGems's macros expect gem_name to exist. %global gem_name %{name} +%global compatver 2.6.8 Name: openwsman -Version: 2.6.8 -Release: 23%{?dist} +Version: 2.8.1 +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -15,15 +16,19 @@ Source1: openwsmand.8.gz Source2: openwsmand.service # script for testing presence of the certificates in ExecStartPre Source3: owsmantestcert.sh +# source for libwsman_client lib compatibility +Source4: https://github.com/Openwsman/openwsman/archive/v%{compatver}.tar.gz Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch +# Patch5 is just for compat package, not needed in 2.8.1 Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch -Patch6: openwsman-2.6.8-CVE-2019-3816.patch -Patch7: openwsman-2.6.8-CVE-2019-3833.patch Patch8: openwsman-2.6.8-update-ssleay-conf.patch -Patch9: openwsman-2.6.8-http-unauthorized-improve.patch +Patch10: openwsman-2.6.8-ssl-certs-gen-changes.patch +# Patch11 is just for compat +Patch11: openwsman-2.8.1-facility-definition.patch +Patch12: openwsman-2.8.1-post-quantum.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -126,20 +131,27 @@ This is a command line tool for the Windows Remote Shell protocol. You can use it to send shell commands to a remote Windows hosts. %prep -%setup -q +%setup -q -c -n %{name} -a 4 +# apply patches for regular source +cd %{name}-%{version} -%patch1 -p1 -b .pamsetup -%patch2 -p1 -b .ruby-binding-build -%patch3 -p1 -b .openssl-1.1-fix -%patch4 -p1 -b .http-status-line -%patch5 -p1 -b .libcurl-error-codes-update -%patch6 -p1 -b .CVE-2019-3816 -%patch7 -p1 -b .CVE-2019-3833 -%patch8 -p1 -b .update-ssleay-conf -%patch9 -p1 -b .http-unauthorized-improve +%patch -P1 -p1 -b .pamsetup +%patch -P2 -p1 -b .ruby-binding-build +%patch -P3 -p1 -b .openssl-1.1-fix +%patch -P4 -p1 -b .http-status-line +%patch -P8 -p1 -b .update-ssleay-conf +%patch -P10 -p1 -b .ssl-certs-gen-changes +%patch -P11 -p1 -b .facility-definition +%patch -P12 -p1 -b .post-quantum + +# apply patches for compatibility source +cd ../%{name}-%{compatver} +%patch -P5 -p1 -b .libcurl-error-codes-update %build -# Removing executable permissions on .c and .h files to fix rpmlint warnings. +# build regular source +cd %{name}-%{version} +# Removing executable permissions on .c and .h files to fix rpmlint warnings. chmod -x src/cpp/WsmanClient.h rm -rf build @@ -166,13 +178,45 @@ make # Make the freshly build openwsman libraries available to build the gem's # binary extension. -export LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib -export CPATH=%{_builddir}/%{name}-%{version}/include/ -export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib/ +export LIBRARY_PATH=%{_builddir}/%{name}/%{name}-%{version}/build/src/lib +export CPATH=%{_builddir}/%{name/}%{name}-%{version}/include/ +export LD_LIBRARY_PATH=%{_builddir}/%{name}/%{name}-%{version}/build/src/lib/ %gem_install -n ./bindings/ruby/%{name}-%{version}.gem +# build compat source +cd ../../%{name}-%{compatver} +# Removing executable permissions on .c and .h files to fix rpmlint warnings. +chmod -x src/cpp/WsmanClient.h + +rm -rf build +mkdir build + +export RPM_OPT_FLAGS="$RPM_OPT_FLAGS -DFEDORA -DNO_SSL_CALLBACK" +export CFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" +export CXXFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" +cd build +cmake \ + -DCMAKE_INSTALL_PREFIX=/usr \ + -DCMAKE_VERBOSE_MAKEFILE=TRUE \ + -DCMAKE_BUILD_TYPE=Release \ + -DCMAKE_C_FLAGS_RELEASE:STRING="$RPM_OPT_FLAGS -fno-strict-aliasing" \ + -DCMAKE_CXX_FLAGS_RELEASE:STRING="$RPM_OPT_FLAGS" \ + -DCMAKE_SKIP_RPATH=1 \ + -DPACKAGE_ARCHITECTURE=`uname -m` \ + -DLIB=%{_lib} \ + -DBUILD_JAVA=no \ + -DBUILD_PYTHON=no \ + -DBUILD_PYTHON3=no \ + -DBUILD_PERL=no \ + -DBUILD_RUBY=no \ + .. + +make + %install +# install regular source +cd %{name}-%{version} cd build # Do not install the ruby extension, we are proviging the rubygem- instead. @@ -184,6 +228,7 @@ rm -f %{buildroot}/%{_libdir}/*.la rm -f %{buildroot}/%{_libdir}/openwsman/plugins/*.la rm -f %{buildroot}/%{_libdir}/openwsman/authenticators/*.la [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsmanplugin.rb +[ -d %{buildroot}/%{ruby_sitelibdir} ] && rm -f %{buildroot}%{ruby_sitelibdir}/openwsmanplugin.rb [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsman.rb mkdir -p %{buildroot}%{_sysconfdir}/init.d install -m 644 etc/openwsman.conf %{buildroot}/%{_sysconfdir}/openwsman @@ -209,6 +254,14 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ +# install compat library +cd ../%{name}-%{compatver} +install build/src/lib/libwsman_client.so.4.0.0 %{buildroot}/%{_libdir} +# create symlink +pushd %{buildroot}/%{_libdir} +ln -s libwsman_client.so.4.0.0 libwsman_client.so.4 +popd + %ldconfig_scriptlets -n libwsman1 %post server @@ -226,25 +279,25 @@ rm -f /var/log/wsmand.log %ldconfig_scriptlets client %files -n libwsman1 -%doc AUTHORS COPYING ChangeLog README.md TODO +%doc %{name}-%{version}/AUTHORS %{name}-%{version}/COPYING %{name}-%{version}/ChangeLog %{name}-%{version}/README.md %{name}-%{version}/TODO %{_libdir}/libwsman.so.* %{_libdir}/libwsman_client.so.* %{_libdir}/libwsman_curl_client_transport.so.* %files -n libwsman-devel -%doc AUTHORS COPYING ChangeLog README.md +%doc %{name}-%{version}/AUTHORS %{name}-%{version}/COPYING %{name}-%{version}/ChangeLog %{name}-%{version}/README.md %{_includedir}/* %{_libdir}/pkgconfig/* %{_libdir}/*.so %files python3 -%doc AUTHORS COPYING ChangeLog README.md +%doc %{name}-%{version}/AUTHORS %{name}-%{version}/COPYING %{name}-%{version}/ChangeLog %{name}-%{version}/README.md %{python3_sitearch}/*.so %{python3_sitearch}/*.py %{python3_sitearch}/__pycache__/* %files -n rubygem-%{gem_name} -%doc AUTHORS COPYING ChangeLog README.md +%doc %{name}-%{version}/AUTHORS %{name}-%{version}/COPYING %{name}-%{version}/ChangeLog %{name}-%{version}/README.md %dir %{gem_instdir} %{gem_libdir} %{gem_extdir_mri} @@ -255,17 +308,17 @@ rm -f /var/log/wsmand.log %doc %{gem_docdir} %files perl -%doc AUTHORS COPYING ChangeLog README.md +%doc %{name}-%{version}/AUTHORS %{name}-%{version}/COPYING %{name}-%{version}/ChangeLog %{name}-%{version}/README.md %{perl_vendorarch}/openwsman.so %{perl_vendorlib}/openwsman.pm %files server -%doc AUTHORS COPYING ChangeLog README.md +%doc %{name}-%{version}/AUTHORS %{name}-%{version}/COPYING %{name}-%{version}/ChangeLog %{name}-%{version}/README.md # Don't remove *.so files from the server package. # the server fails to start without these files. %dir %{_sysconfdir}/openwsman %config(noreplace) %{_sysconfdir}/openwsman/openwsman.conf -%config(noreplace) %{_sysconfdir}/openwsman/ssleay.cnf +%config(noreplace) %verify(not size md5 mtime) %{_sysconfdir}/openwsman/ssleay.cnf %attr(0755,root,root) %{_sysconfdir}/openwsman/owsmangencert.sh %attr(0755,root,root) %{_sysconfdir}/openwsman/owsmantestcert.sh %config(noreplace) %{_sysconfdir}/pam.d/openwsman @@ -282,7 +335,7 @@ rm -f /var/log/wsmand.log %{_mandir}/man8/* %files client -%doc AUTHORS COPYING ChangeLog README.md +%doc %{name}-%{version}/AUTHORS %{name}-%{version}/COPYING %{name}-%{version}/ChangeLog %{name}-%{version}/README.md %{_libdir}/libwsman_clientpp.so.* %config(noreplace) %{_sysconfdir}/openwsman/openwsman_client.conf @@ -290,6 +343,22 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Feb 04 2026 Vitezslav Crhonek - 2.8.1-2 +- Support added for post-quantum cryptography + Resolves: RHEL-127516 +- Fix bogus 'sscg' arguments + Related: RHEL-118292 + +* Thu Oct 23 2025 Vitezslav Crhonek - 2.8.1-1 +- Update to openwsman-2.8.1 + Resolves: RHEL-97643 +- Add libwsman-client.so.4 for backward compatibility + Related: RHEL-97643 + +* Tue Oct 14 2025 Vitezslav Crhonek - 2.6.8-24 +- Update OpenSSL certificates set up + Resolves: RHEL-118292 + * Thu Nov 24 2022 Vitezslav Crhonek - 2.6.8-23 - Improve handling of HTTP 401 Unauthorized Resolves: #2127415