Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
Name: opencryptoki-ccatok | Distribution: Fedora Project |
Version: 3.24.0 | Vendor: Fedora Project |
Release: 2.fc41 | Build date: Mon Sep 16 16:53:36 2024 |
Group: Unspecified | Build host: buildhw-x86-16.iad2.fedoraproject.org |
Size: 847801 | Source RPM: opencryptoki-3.24.0-2.fc41.src.rpm |
Packager: Fedora Project | |
Url: https://github.com/opencryptoki/opencryptoki | |
Summary: CCA cryptographic devices (secure-key) support for opencryptoki |
Opencryptoki implements the PKCS#11 specification v2.20 for a set of cryptographic hardware, such as IBM 4764 and 4765 crypto cards, and the Trusted Platform Module (TPM) chip. Opencryptoki also brings a software token implementation that can be used without any cryptographic hardware. This package brings the necessary libraries and files to support CCA devices in the opencryptoki stack. CCA is an interface to IBM cryptographic hardware such as IBM 4764 or 4765 that uses the "co-processor" or "secure-key" path.
CPL-1.0
* Fri Sep 13 2024 Than Ngo <than@redhat.com> - 3.24.0-2 - build with --enable-pkcscca_migrate - fix build error due to incompatible pointer types * Fri Sep 13 2024 Than Ngo <than@redhat.com> - 3.24.0-1 - Update to 3.24.0 * Add support for building Opencryptoki on the IBM AIX platform * Add support for the CCA token on non-IBM Z platforms (x86_64, ppc64) * Add support for protecting tokens with a token specific user group * EP11: Add support for combined CKA_EXTRACTABLE and CKA_IBM_PROTKEY_EXTRACTABLE * CCA: Add support for Koblitz curve secp256k1. Requires CCA v7.2 or later * CCA: Add support for IBM Dilithium (CKM_IBM_DILITHIUM). On Linux on IBM Z: Requires CCA v7.1 or later for Round2-65, and CCA v8.0 for the Round 3 variants. On other platforms: Requires CCA v7.2.43 or later for Round2-65, the Round 3 variants are currently not supported * CCA: Add support for RSA-OAEP with SHA224, SHA384, and SHA512 on en-/decrypt. Requires CCA v8.1 or later on Linux on IBM Z, not supported on other platforms * CCA: Add support for PKCS#11 v3.0 SHA3 mechanisms. Requires CCA v8.1 on Linux on IBM Z, not supported on other platforms * ICA: Support new libica AES-GCM api using the KMA instruction on z14 and later * ICA/Soft/ICSF: Add support for PKCS#11 v3.0 SHA3 mechanisms * ICA/Soft: Add support for SHA based key derivation mechanisms * ICA/Soft: Add support for CKD_*_SP800 KDFs for ECDH * EP11/CCA/ICA/Soft: Add support for CKA_ALWAYS_AUTHENTICATE * EP11/CCA: Support live guest relocation for protected key (PKEY) operations * Soft: Experimental support for IBM Dilithium via OpenSSL OQS provider * ICSF: Add support for SHA-2 mechanisms * ICSF: Performance improvements for attribute retrieval * p11sak: Add support for exporting a key or certificate as URI-PEM file * p11sak: Import/export of IBM Dilithium keys in 'oqsprovider' format PEM files * p11sak: Add option to show the master key verification patterns of secure keys * Bug fixes - Remove i686 support as upsrtream will get rid of 32-bit support, https://github.com/opencryptoki/opencryptoki/issues/174 - Remove lockdir.patch * Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.23.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Wed Feb 07 2024 Than Ngo <than@redhat.com> - 3.23.0-1 - 3.23.0 * EP11: Add support for FIPS-session mode * Updates to harden against RSA timing attacks * Bug fixes * Tue Jan 30 2024 Dan HorĂ¡k <dan[at]danny.cz> - 3.22.0-4 - fix all errors and warnings (rhbz#2261419) * Thu Jan 25 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.22.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.22.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Sep 21 2023 Than Ngo <than@redhat.com> - 3.22.0-1 - update to 3.22.0 * Thu Jul 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 3.21.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Mon Jul 17 2023 Than Ngo <than@redhat.com> - 3.21.0-5 - p11sak tool: slot option does not accept argument 0 for slot index 0 - p11sak fails as soon as there reside non-key objects * Thu May 25 2023 Than Ngo <than@redhat.com> - 3.21.0-4 - add verify attributes for opencryptoki.conf to ignore the verification * Mon May 22 2023 Than Ngo <than@redhat.com> - 3.21.0-3 - drop p11_kit_support - fix handling of user name - fix user confirmation prompt behavior when stdin is closed * Tue May 16 2023 Than Ngo <than@redhat.com> - 3.21.0-2 - add missing /var/lib/opencryptoki/HSM_MK_CHANGE * Mon May 15 2023 Than Ngo <than@redhat.com> - 3.21.0-1 - update to 3.21.0 * Tue Feb 14 2023 Than Ngo <than@redhat.com> - 3.20.0-2 - migrated to SPDX license * Mon Feb 13 2023 Than Ngo <than@redhat.com> - 3.20.0-1 - update to 3.20.0 - drop unnecessary opencryptoki-3.11.0-group.patch * Wed Feb 08 2023 Than Ngo <than@redhat.com> - 3.19.0-3 - Add support of ep11 token for new IBM Z Hardware (IBM z16) * Thu Jan 19 2023 Fedora Release Engineering <releng@fedoraproject.org> - 3.19.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Tue Oct 11 2022 Than Ngo <than@redhat.com> - 3.19.0-1 - update to 3.19.0 * Wed Sep 14 2022 Florian Weimer <fweimer@redhat.com> - 3.18.0-5 - Add missing build dependency on systemd-rpm-macros
/etc/opencryptoki/ccatok.conf /usr/lib/.build-id /usr/lib/.build-id/2c /usr/lib/.build-id/2c/5da3abfa4c05d33fdd74f15497e52ea4e68e4e /usr/lib/.build-id/c5 /usr/lib/.build-id/c5/66b40e23488e95673424c9568ec0ab03735d8a /usr/lib64/opencryptoki/stdll/PKCS11_CCA.so /usr/lib64/opencryptoki/stdll/libpkcs11_cca.so /usr/lib64/opencryptoki/stdll/libpkcs11_cca.so.0 /usr/lib64/opencryptoki/stdll/libpkcs11_cca.so.0.0.0 /usr/sbin/pkcscca /usr/share/doc/opencryptoki-ccatok /usr/share/doc/opencryptoki-ccatok/README.cca_stdll /usr/share/man/man1/pkcscca.1.gz /var/lib/opencryptoki/ccatok /var/lib/opencryptoki/ccatok/TOK_OBJ
Generated by rpm2html 1.8.1
Fabrice Bellet, Fri Nov 1 03:28:00 2024