Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

opencryptoki-ccatok-3.22.0-3.el9 RPM for s390x

From CentOS Stream 9 BaseOS for s390x

Name: opencryptoki-ccatok Distribution: CentOS
Version: 3.22.0 Vendor: CentOS
Release: 3.el9 Build date: Fri Feb 16 13:40:06 2024
Group: Unspecified Build host: s390-07.stream.rdu2.redhat.com
Size: 765707 Source RPM: opencryptoki-3.22.0-3.el9.src.rpm
Packager: builder@centos.org
Url: https://github.com/opencryptoki/opencryptoki
Summary: CCA cryptographic devices (secure-key) support for opencryptoki
Opencryptoki implements the PKCS#11 specification v2.20 for a set of
cryptographic hardware, such as IBM 4764 and 4765 crypto cards, and the
Trusted Platform Module (TPM) chip. Opencryptoki also brings a software
token implementation that can be used without any cryptographic
hardware.
This package brings the necessary libraries and files to support CCA
devices in the opencryptoki stack. CCA is an interface to IBM
cryptographic hardware such as IBM 4764 or 4765 that uses the
"co-processor" or "secure-key" path.

Provides

Requires

License

CPL

Changelog

* Fri Feb 16 2024 Than Ngo <than@redhat.com> - 3.22.0-3
  - Fix implicit rejection with RSA keys with empty CKA_PRIVATE_EXPONENT
  Related: RHEL-22792
* Thu Feb 08 2024 Than Ngo <than@redhat.com> - 3.22.0-2
  - timing side-channel in handling of RSA PKCS#1 v1.5 padded ciphertexts (Marvin)
  Resolves: RHEL-22792
* Tue Nov 21 2023 Than Ngo <than@redhat.com> - 3.22.0-1
  - Resolves: RHEL-11412, rebase to 3.22.0
  - Resolves: RHEL-10569, openCryptoki for PKCS #11 3.0
* Fri Jul 14 2023 Than Ngo <than@redhat.com> - 3.21.0-8
  - Resolves: #2222592, p11sak tool: slot option does not accept argument 0 for slot index 0
  - Resolves: #2222596, p11sak fails as soon as there reside non-key objects
* Tue Jun 13 2023 Than Ngo <than@redhat.com> - 3.21.0-5
  - add requirement on selinux-policy >= 38.1.14-1 for pkcsslotd policy sandboxing
  Related: #2160061
* Fri May 26 2023 Than Ngo <than@redhat.com> - 3.21.0-4
  - add verify attributes for opencryptoki.conf to ignore the verification
  
  Related: #2160061
* Mon May 22 2023 Than Ngo <than@redhat.com> - 3.21.0-3
  - Resolves: #2110497, concurrent MK rotation for cca token
  - Resolves: #2110498, concurrent MK rotation for ep11 token
  - Resolves: #2110499, ep11 token: PKCS #11 3.0 - support AES_XTS
  - Resolves: #2111010, cca token: protected key support 
  - Resolves: #2160061, rebase to 3.21.0
  - Resolves: #2160105, pkcsslotd hardening
  - Resolves: #2160107, p11sak support Dilithium and Kyber keys
  - Resolves: #2160109, ica and soft tokens: PKCS #11 3.0 - support AES_XTS
* Mon Jan 30 2023 Than Ngo <than@redhat.com> - 3.19.0-2
  - Resolves: #2044182, Support of ep11 token for new IBM Z Hardware (IBM z16)
* Tue Oct 11 2022 Than Ngo <than@redhat.com> - 3.19.0-1
  - Resolves: #2126294, opencryptoki fails after generating > 500 RSA keys
  - Resolves: #2110314, rebase to 3.19.0
  - Resolves: #2110989, openCryptoki key generation with expected MKVP only on CCA and EP11 tokens
  - Resolves: #2110476, openCryptoki ep11 token: master key consistency
  - Resolves: #2018458, openCryptoki ep11 token: vendor specific key derivation
* Fri Jul 29 2022 Than Ngo <than@redhat.com> - 3.18.0-4
  - Related: #2044179, do not touch opencryptoki.conf if it is in place already and even if it is unchanged
* Tue Jun 07 2022 Than Ngo <than@redhat.com> - 3.18.0-3
  - Related: #2044179, fix json output
* Mon May 09 2022 Than Ngo <than@redhat.com> - 3.18.0-2
  - Related: #2044179, add missing strength.conf
* Mon May 09 2022 Than Ngo <than@redhat.com> - 3.18.0-1
  - Resolves: #2044179, rebase to 3.18.0
  - Resolves: #2068091, pkcsconf -t failed with Segmentation fault in FIPS mode
  - Resolves: #2066763, Dilithium support not available
  - Resolves: #2064697, OpenSSL 3.0 Compatibility for IBM Security Libraries and Tools
  - Resolves: #2044181, support crypto profiles
  - Resolves: #2044180, add crypto counters
* Tue May 03 2022 Than Ngo <than@redhat.com> - 3.17.0-6
  - Resolves: #2066763, Dilithium support not available
* Mon Mar 14 2022 Than Ngo <than@redhat.com> - 3.17.0-5
  - Resolves: #2064697, ICA/EP11: Support libica version 4

Files

/etc/opencryptoki/ccatok.conf
/usr/lib/.build-id
/usr/lib/.build-id/14
/usr/lib/.build-id/14/e57edf940285c198fa6081dfe6c5bc8fb019c3
/usr/lib/.build-id/53
/usr/lib/.build-id/53/16d0d4ff7bbfe755fa3c939490d29c2f1a3e56
/usr/lib64/opencryptoki/stdll/PKCS11_CCA.so
/usr/lib64/opencryptoki/stdll/libpkcs11_cca.la
/usr/lib64/opencryptoki/stdll/libpkcs11_cca.so
/usr/lib64/opencryptoki/stdll/libpkcs11_cca.so.0
/usr/lib64/opencryptoki/stdll/libpkcs11_cca.so.0.0.0
/usr/sbin/pkcscca
/usr/share/doc/opencryptoki-ccatok
/usr/share/doc/opencryptoki-ccatok/README.cca_stdll
/usr/share/man/man1/pkcscca.1.gz
/var/lib/opencryptoki/ccatok
/var/lib/opencryptoki/ccatok/TOK_OBJ


Generated by rpm2html 1.8.1

Fabrice Bellet, Tue May 21 02:44:21 2024