Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

openCryptoki-3.8.2-lp150.3.1 RPM for x86_64

From OpenSuSE Leap 15.0 for x86_64

Name: openCryptoki Distribution: openSUSE Leap 15.0
Version: 3.8.2 Vendor: openSUSE
Release: lp150.3.1 Build date: Thu Apr 19 19:32:29 2018
Group: Productivity/Security Build host: cloud137
Size: 449215 Source RPM: openCryptoki-3.8.2-lp150.3.1.src.rpm
Packager: https://bugs.opensuse.org
Url: https://sourceforge.net/projects/opencryptoki/
Summary: An Implementation of PKCS#11 (Cryptoki) v2.11 for IBM Cryptographic Hardware
The PKCS#11 version 2.11 API implemented for the IBM cryptographic
cards. This package includes support for the IBM 4758 cryptographic
coprocessor (with the PKCS#11 firmware loaded) and the IBM eServer
Cryptographic Accelerator (FC 4960 on pSeries).

Provides

Requires

License

CPL-1.0

Changelog

* Tue Apr 17 2018 mpost@suse.com
  - Added ocki-3.8.2-Fix-Hardware-Feature-Object-validation-and-tests.patch
    (bsc#1086678)
* Fri Mar 09 2018 mpost@suse.com
  - Re-enabled ARM architectures now that gcc6 is in SLE15. (bsc#1084617)
* Thu Nov 30 2017 mpost@suse.com
  - Upgraded to version 3.8.2 (fate#323295, bsc#1066412)
    * v3.8.2
      Update man pages.
      Improve ock_tests for parallel execution.
      Fix FindObjectsInit for hidden HW-feature.
      Fix to allow vendor defined hardware features.
      Fix unresolved symbols.
      Fix tracing.
      Code/project cleanup.
    * v3.8.1
      Fix TPM data-structure reset function.
      Fix error message when dlsym fails.
      Update configure.ac
      Update travis.
    * v3.8.0
      Multi token instance feature.
      Added possibility to run opencryptoki with transactional memory or locks
      (--enable-locks on configure step).
      Updated documentation.
      Fix segfault on ec_test.
      Bunch of small fixes.
* Wed May 31 2017 mpost@suse.com
  - Removed ARM architectures from the build list until gcc6 becomes
    available for SLES. (bsc#1039510).
* Fri May 12 2017 mpost@suse.com
  - Updated to version 3.7.0 (Fate#321451) (bsc#1036640)
    - Update example spec file
    - Performance improvement. Moving from mutexes to transactional memory.
    - Add ECDSA SHA2 support for EP11 and CCA.
    - Fix declaration of inline functions.
    - Fix wrong testcase and ber en/decoding for integers.
    - Check for 'flex' and 'YACC' on configure.
    - EP11 config file rework.
    - Add enable-debug on travis build.
    - Add testcase for C_GetOperationState/C_SetOperationState.
    - Upgrade License to CPL-1.0
    - Ica token: fix openssh/ibmpkcs11 engine/libica crash.
    - Fix segfault and logic in hardware feature test.
    - Fix spelling of documentation and manuals.
    - Fix the retrieval of p from a generated rsa key.
    - Coverity scan fixes - incompatible pointer type and unused variables.
* Tue Apr 11 2017 mpost@suse.com
  - Added libica-tools to the BuildRequires due to repackaging of libica.
* Mon Mar 20 2017 mpost@suse.com
  - Modified the spec file
    - Changed libca3-devel BuildRequires to just libica-devel
    - Check for systemd in the 32bit postun scriptlet.
* Mon Feb 20 2017 mpost@suse.com
  - Upgraded to version 3.6.2 (fate#321451)
    - Support OpenSSL-1.1.
    - Add Travis CI support.
    - Update autotools scripts and documentation.
    - Fix SegFault when a invalid session handle is passed in
      SC_EncryptUpdate and SC_DecryptUpdate.
  - Updated spec file to use libica3-devel instead of libica2-devel.
* Tue Jan 17 2017 mpost@suse.com
  - Upgraded to version 3.6.1 (fate#321451)
    - opencryptoki 3.6.1
    - Fix SOFT token implementation of digest functions.
    - Replace deprecated OpenSSL interfaces.
    - opencryptoki 3.6
    - Replace deprecated libica interfaces.
    - Performance improvement for ICA.
    - Improvement in documentation on system resources.
    - Improvement in testcases.
    - Added support for rc=8, reasoncode=2028 in icsf token.
    - Fix for session handle not set in session issue.
    - Multiple fixes for lock and log directories.
    - Downgraded a syslog error to warning.
    - Multiple fixes based on coverity scan results.
    - Added pkcs11 mapping for icsf reason code 72 for return code 8.
    - opencryptoki 3.5.1
    - Fix Illegal Intruction on pkcscca tool.
    - Removed the following obsolete patches:
    - ocki-3.5-sanity-checking.patch
    - ocki-3.5-icsf-reasoncode72-support.patch
    - ocki-3.5-downgrade-syslogerror.patch
    - ocki-3.5-icsf-sessionhandle-missing-fix.patch
    - ocki-3.5-icsf-reasoncode-2028-added.patch
    - ocki-3.5-added-NULLreturn-check.patch
    - ocki-3.5-create-missing-tpm-token-lock-directory.patch
    - ocki-3.5-fix-pkcscca-calls.patch
* Mon Oct 31 2016 jjolly@suse.com
  - Removed reference to pkcs1_startup from pkcsslotd (bsc#1007081)
* Thu Sep 01 2016 mpost@suse.com
  - Added ocki-3.5-fix-pkcscca-calls.patch (bsc#996867).
* Fri Jul 29 2016 mpost@suse.com
  - Added %doc FAQ to the spec file (bsc#991168).
* Tue Jul 19 2016 mpost@suse.com
  - Added ocki-3.5-create-missing-tpm-token-lock-directory.patch
    (bsc#989602).
* Fri Jul 08 2016 mpost@suse.com
  - Added the following patches (bsc#986854)
    - ocki-3.5-icsf-reasoncode72-support.patch
    - ocki-3.5-icsf-coverity-memoryleakfix.patch
    - ocki-3.5-downgrade-syslogerror.patch
    - ocki-3.5-icsf-sessionhandle-missing-fix.patch
    - ocki-3.5-icsf-reasoncode-2028-added.patch
    - ocki-3.5-added-NULLreturn-check.patch
* Mon Jun 13 2016 mpost@suse.com
  - Added ocki-3.5-sanity-checking.patch (bsc#983496).
  - Added %dir entry for %{_localstatedir}/log/opencryptoki/
    (bsc#983990)
* Wed May 25 2016 mpost@suse.com
  - Upgraded to openCryptoki 3.5 (bsc#978005).
    - Full Coverity scan fixes.
    - Fixes for compiler warnings.
    - Added support for C_GetObjectSize in icsf token.
    - Various bug fixes and memory leak fixes.
    - Removed global read permissions from token files
    - Added missing PKCS#11v2.2 constants.
    - Fix for symbol resolution issue seen in Fedora 22 and 23 for
      ep11 and cca tokens.
    - Improvements in socket read operation when a token comes up.
    - Replaced 32 bit CCA API declarations with latest header from
      version 5.0 libsculcca rpm.
* Thu Apr 14 2016 mpost@suse.com
  - Upgraded to openCryptoki v3.4.1 (Fate#319576, 319585, 319592, 319938).
  - Changed BuildRequires for libica_2_3_0-devel to libica2-devel.
  - Changed BuildRequires for openssl-devel to specify >= 1.0
    Contrary to what the README says, version 0.9.7 isn't
    sufficient.
  - Removed the redundant DESTDIR= parameter from the %make_install
  - Removed the following obsolete patches
    opencryptoki-run-lock.patch (/var/lock and run/lock are actually the
      same place) Also reverted the changed to openCryptoki-tmp.conf to match.
    ocki-3.1_10_0001-ica-sha-update-empty-msg.patch
    ocki-3.1-fix-implicit-decl.patch
    ocki-3.1-fix-init_d-path.patch
    ocki-3.1-fix-libica-link.patch
    ocki-3.2_01_fix-return-type-error.patch
    ocki-3.2_02_ep11-token-incorrectly-copied-the-public-key-object-.patch
    ocki-3.2_03_ICSF-Token-C_SignUpdate-was-sometimes-segfaulting-an.patch
    ocki-3.2_04_CKA_EC_POINT-is-not-required-in-the-ECDSA-private-ke.patch
    ocki-3.2_05_icsf_ldap_handles.patch
    ocki-3.2_06_icsf_sign_verify.patch
  - renamed: ocki-3.1-remove-make-install-chgrp-chmod.patch to
    ocki-3.1-remove-make-install-chgrp.patch
* Fri Nov 06 2015 jjolly@suse.com
  - Get a new ldap handle for each session opened in the icsf token,
      once the user has authenticated. (bsc#953347,LTC#130078)
    - ocki-3.2_05_icsf_ldap_handles.patch
    - ocki-3.2_06_icsf_sign_verify.patch
* Fri Oct 02 2015 jjolly@suse.com
  - Added /var/lib/opencryptoki/lite/TOK_OBJ token directory (bsc#943070)
  - Added ocki-3.2_02_ep11-token-incorrectly-copied-the-public-key-object-.patch
    - Fixed two public key object inclusion in EP11 token (bsc#946808)
  - Added ocki-3.2_03_ICSF-Token-C_SignUpdate-was-sometimes-segfaulting-an.patch
    - Fixed GPF when calling C_SignUpdate using ICFS toekn (bsc#946172)
  - Added ocki-3.2_04_CKA_EC_POINT-is-not-required-in-the-ECDSA-private-ke.patch
    - Fixed failure to import ECDSA because of lack of attribute (bsc#948114)
* Thu Aug 20 2015 jjolly@suse.com
  - Fixed BuildRequires: libica2-devel
  - Added ocki-3.2_01_fix-return-type-error.patch
  - Changing doc/README.ep11_stdll to unix-style EOL
    - Added BuildRequires: dos2unix
  - Removed globbing in %files and specified libraries to include (bsc#942162)
* Tue Aug 18 2015 jjolly@suse.com
  - Updated to openCryptoki v3.2 (FATE#318240)
  - Removed unnecessary patches:
    - ocki-3.1_01_ep11_makefile.patch
    - ocki-3.1_02_ep11_m_init.patch
    - ocki-3.1_03_ock_obj_mgr.patch
    - ocki-3.1_04_ep11_opaque2blob_error_handl.patch
    - ocki-3.1_05_ep11_readme_update.patch
    - ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch
    - ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch
    - ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch
    - ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch
    - ocki-3.1_06_0005-Small-reworks.patch
    - ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch
    - ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch
    - ocki-3.1_07_0001-Man-page-corrections.patch
    - ocki-3.1_08_0001-Add-a-pkcscca-tool-to-help-migrate-cca-private-token.patch
    - ocki-3.1_08_0002-Add-documentation-pkcscca-manpage-and-README.cca_std.patch
    - ocki-3.1_09_0001-Fix-EOL-encoding-in-README.patch
* Tue Apr 07 2015 crrodriguez@opensuse.org
  - Also create parent directory /run/lock/opencryptoki in
    tmpfiles snippet if it does not exists.
* Tue Apr 07 2015 crrodriguez@opensuse.org
  - spec: do not use -D__USE_BSD, a glibc-internal macro
    which no longer has any meaning.
* Tue Apr 07 2015 crrodriguez@opensuse.org
  - spec: use %{_unitdir}  %{_tmpfilesdir)
  - spec: call tmpfiles_create macro, if defined in %post
  - opencryptoki-run-lock.patch, openCryptoki-tmp.conf: use
    /run/lock instead of /var/lock.
* Wed Dec 17 2014 p.drouand@gmail.com
  - Update to version 3.2
    +New pkcscca tool. Currently it assists in migrating cca private token
    objects from opencryptoki version 2 to the clear key encryption method
    used in opencryptoki version 3. Includes a manpage for pkcscca tool.
    Changes to README.cca_stdll to assist in using the CCA token and
    migrating the private token objects.
    + Support for CKM_RSA_PKCS_OAEP and CKM_RSA_PKCS_PSS algorithms.
    + Various bugfixes.
    + New testcases for various crypto algorithms.
  - Only depend on insserv if builded with sysvinit support
  - Remove obsolete patches; merged on upstream release
    + ocki-3.1_01_ep11_makefile.patch
    + ocki-3.1_02_ep11_m_init.patch
    + ocki-3.1_03_ock_obj_mgr.patch
    + ocki-3.1_04_ep11_opaque2blob_error_handl.patch
    + ocki-3.1_05_ep11_readme_update.patch
    + ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch
    + ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch
    + ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch
    + ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch
    + ocki-3.1_06_0005-Small-reworks.patch
    + ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch
    + ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch
    + ocki-3.1_07_0001-Man-page-corrections.patch
    + ocki-3.1_08_0001-Add-a-pkcscca-tool-to-help-migrate-cca-private-token.patch
    + ocki-3.1_08_0002-Add-documentation-pkcscca-manpage-and-README.cca_std.patch
    + ocki-3.1_09_0001-Fix-EOL-encoding-in-README.patch
    + ocki-3.1_10_0001-ica-sha-update-empty-msg.patch
  - Project is now hosted on sourceforge; fix the Url
  - Remove cvs related stuff; tarball is produced by upstream
  - Use %configure macro instead of manually defined options
  - Build with parallel support; use %{?_smp_mflags} macro
* Fri Sep 05 2014 jjolly@suse.com
  - Fixed ica token's SHA update function when passing zero message
    size (bnc#892644)
  - Added patch ocki-3.1_10_0001-ica-sha-update-empty-msg.patch
* Fri Sep 05 2014 jjolly@suse.com
  - Fixed README.ep11_stdll to have Unix-style EOL characters.
  - Added patch ocki-3.1_09_0001-Fix-EOL-encoding-in-README.patch
* Thu Sep 04 2014 jjolly@suse.com
  - Added all files from %src/doc as rpm %doc (bnc#894780)
* Thu Sep 04 2014 jjolly@suse.com
  - Added pkcscca utility and documentation to convert private
    token objects from v2 to v3. (bnc#893757)
  - Added patches:
    - ocki-3.1_08_0001-Add-a-pkcscca-tool-to-help-migrate-cca-private-token.patch
    - ocki-3.1_08_0002-Add-documentation-pkcscca-manpage-and-README.cca_std.patch
* Thu Sep 04 2014 jjolly@suse.com
  - Fixed pkcsslotd and opencryptoki.conf man pages (bnc#889183)
  - Added patch ocki-3.1_07_0001-Man-page-corrections.patch
* Fri Aug 15 2014 sfalken@opensuse.org
  - Specfile Cleanup, Added directory macros in appropriate places
* Thu Jun 26 2014 jjolly@suse.com
  - Several package changes as per bnc#880217
    - Added openCryptoki-tmp.conf for lock directory management
    - Added 'lite' token support
    - Changed from init.d daemon to systemd service
    - Updated macros in %pre %post %preun and %postun sections
    - Added missing icsf and ep11tok directories to %files section
      ocki-3.1_01_ep11_makefile.patch
      ocki-3.1_02_ep11_m_init.patch
  - Patches added:
    ocki-3.1-fix-libica-link.patch
    ocki-3.1_03_ock_obj_mgr.patch
    ocki-3.1_04_ep11_opaque2blob_error_handl.patch
    ocki-3.1_05_ep11_readme_update.patch
    ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch
    ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch
    ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch
    ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch
    ocki-3.1_06_0005-Small-reworks.patch
    ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch
    ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch
* Thu Jun 05 2014 jjolly@suse.com
  - Moved libpkcs11_icsf 32-bit out of s390-specific files
* Thu Jun 05 2014 jjolly@suse.com
  - Made ep11tok.conf and pkcsep11_migrate specific to s390/s390x
  - Added libpkcs11_ep11.so and libpkcs11_icsf.so to 32-bit s390/s390x
* Thu Jun 05 2014 jjolly@suse.com
  - EP11 token available in the opencryptoki V3.1 package  (bnc#879303)
    - Specfile changed to include ep11tok.conf
    - Specfile changed to include pkcsep11_migrate and pkcsicsf tools
    - Specfile changed to BuildRequires openldap2-devel
    - ocki-3.1_06_0001-print_mechanism-ignored-bad-returncodes-from-the-cal.patch
    - print_mechanism() ignored bad returncodes from the called
      function token_specific_get_mechanism_list()
    - ocki-3.1_06_0002-Fix-failure-when-confname-is-not-given-use-default-e.patch
    - Fix failure when confname is not given, use default
      ep11tok.conf instead
    - ocki-3.1_06_0003-Configure-was-checking-for-the-ep11-lib-and-the-m_in.patch
    - Removed check for ep11 lib at configure
    - ocki-3.1_06_0004-The-asm-zcrypt.h-header-file-uses-some-std-int-types.patch
    - Move stdint.h before zcrypt.h to resolve dependencies
    - ocki-3.1_06_0005-Small-reworks.patch
    - testcase fixes and file permission changes
    - ocki-3.1_06_0006-The-31-bit-build-on-s390-showed-an-build-error-at-in.patch
    - Fix for s390 31-bit build error
    - ocki-3.1_06_0007-ep11-is-not-building-because-not-setting-with_zcrypt.patch
    - zcrypt library included in build by default
* Fri Mar 07 2014 jjolly@suse.com
  - Patches applied (bnc#865549)
    - Fixed Makefile to complement common code dependencies
    - switched to official m_init() function based on library change
    - checking the global token object count
    - catch the return code from object_mgr_find_in_map1
    - some README updates about usage and restrictions
* Wed Mar 05 2014 ro@suse.de
  - fix build on x86 (add CCA and TPM to filelist)
  - fix libica detection on s390/s390x to get ICA module built
* Tue Feb 04 2014 jjolly@suse.com
  - Updated to openCryptoki v3.1: See ChangeLog for complete details
    (FATE#315426)
    - opencryptoki-3.1
    - New ep11 token to support IBM Crypto Express adpaters
      (starting with Crypto Express 4S adapters) configured with
      Enterprise PKCS#11(EP11) firmware. (FATE#315330)
    - opencryptoki-3.0
    - New opencryptoki.conf file to replace pk_config_data and
      pkcs11_starup.  The opencryptoki.conf contains slot entry
      information for tokens.
    - Removed pkcs_slot and pkcs11_startup shell scripts.
    - ICA token supports CKM_DES_OFB64, CKM_DES_CFB8, CKM_DES_CFB6
      mechanisms using 3DES keys. (FATE#315323)
    - ICA token supports CKM_DES3_MAC and CKM_DES3_MAC_GENERAL
      mechanisms. (FATE#315323)
    - ICA token supports CKM_AES_OFB, CKM_AES_CFB8, CKM_AES_CFB64,
      CKM_AES_CFB128, CKM_AES_MAC, and CKM_AES_MAC_GENERAL
      mechanisms. (FATE#315323)
    - opencryptoki-2.4.1 (21 Feb 2012)
    - SHA256 support added for CCA token (FATE#315289)
  - Using insserv macros in %post, %preun and %postun sections
  - Cleaned up spec file
  - removed patches:
    - ocki-2.2.6-PIN-backspace.patch
  - added patches:
    - ocki-3.1-fix-implicit-decl.patch
    - ocki-3.1-remove-make-install-chgrp-chmod.patch
    - ocki-3.1-fix-init_d-path.patch
* Tue Feb 04 2014 ro@suse.de
  - add aarch64 to 64bit archs
* Tue Dec 10 2013 dvaleev@suse.com
  - enable ppc64le
* Sat Dec 08 2012 meissner@suse.com
  - remove -o from groupadd
  - fixed sed script to not a grouplist with leading ,
* Sun Nov 27 2011 coolo@suse.com
  - don't package man pages twice
* Sun Nov 27 2011 coolo@suse.com
  - add libtool as buildrequire to avoid implicit dependency
* Mon Sep 27 2010 meissner@suse.de
  - enable TPM support (bnc#641919)

Files

/etc/opencryptoki
/etc/opencryptoki/opencryptoki.conf
/usr/lib/systemd/system/pkcsslotd.service
/usr/lib/tmpfiles.d/opencryptoki.conf
/usr/lib64/opencryptoki
/usr/lib64/opencryptoki/stdll
/usr/sbin/pkcscca
/usr/sbin/pkcsconf
/usr/sbin/pkcsicsf
/usr/sbin/pkcsslotd
/usr/sbin/rcpkcsslotd
/usr/share/doc/packages/openCryptoki
/usr/share/doc/packages/openCryptoki/FAQ
/usr/share/doc/packages/openCryptoki/README.cca_stdll
/usr/share/doc/packages/openCryptoki/README.ep11_stdll
/usr/share/doc/packages/openCryptoki/README.icsf_stdll
/usr/share/doc/packages/openCryptoki/README.pkcscca_migrate
/usr/share/doc/packages/openCryptoki/README.token_data
/usr/share/doc/packages/openCryptoki/README.tpm_stdll
/usr/share/doc/packages/openCryptoki/coding_style.md
/usr/share/doc/packages/openCryptoki/openCryptoki-TFAQ.html
/usr/share/doc/packages/openCryptoki/opencryptoki-howto.md
/usr/share/doc/packages/openCryptoki/system_resources
/usr/share/man/man1/pkcscca.1.gz
/usr/share/man/man1/pkcsconf.1.gz
/usr/share/man/man1/pkcsep11_migrate.1.gz
/usr/share/man/man1/pkcsicsf.1.gz
/usr/share/man/man5/opencryptoki.conf.5.gz
/usr/share/man/man7/opencryptoki.7.gz
/usr/share/man/man8/pkcsslotd.8.gz
/var/lib/opencryptoki
/var/lib/opencryptoki/ccatok
/var/lib/opencryptoki/ccatok/TOK_OBJ
/var/lib/opencryptoki/icsf
/var/lib/opencryptoki/swtok
/var/lib/opencryptoki/swtok/TOK_OBJ
/var/lib/opencryptoki/tpm
/var/log/opencryptoki


Generated by rpm2html 1.8.1

Fabrice Bellet, Sat Apr 9 10:08:57 2022