- Add generate-cargo-lock-file.patch to fix the build system in OBS - Add keylime.conf.diff to adjust the default config file - Adjust build requirements - Add firewalld XML rules - Add systemd keylime_agent.service - Fix license tag - Update to version 0.0.1+git.1626706730.a009476: * libarchive-devel is needed to build on Fedora * Accept sets of U and V keys; use new Key types * Output mask info * Fix for race condition bug * Do not resend pubkey to CV after attestation * Run payload script from a shell * Write out data and run payload * Decrypt payload after key handlers find symm key * Add handler for U and V keys * Add helper functions for handling U and V keys * Some TPM fixes for IMA PCR validation * Do not flush AK context as this causes an error * Fix bug in revocation service * Drop references to vmask * Better documentation of consts * Do not fail if EK cert is not present in TPM NV * Add more verbose logging to better match Python agent * Remove verify stub as we are not using it * tests: Don't pass --allow-signing to swtpm_setup * Fix typos * Add dependency for libzmq3-dev / zeromq-devel * Fix new clippy lints * Add handling for Identity and Integrity quotes * Add Quote functionality * Add marshaling functions for TPM structs OBS-URL: https://build.opensuse.org/request/show/908894 OBS-URL: https://build.opensuse.org/package/show/security/rust-keylime?expand=0&rev=3
13 lines
567 B
XML
13 lines
567 B
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<service>
|
|
<short>Keylime</short>
|
|
<description>Keylime is a remote attestation tool that requires access to several ports.</description>
|
|
<port protocol="tcp" port="443"/><!-- Webapp -->
|
|
<port protocol="tcp" port="8881"/><!-- Verifier -->
|
|
<port protocol="tcp" port="8888"/><!-- CFSSL -->
|
|
<port protocol="tcp" port="8890"/><!-- Registrar -->
|
|
<port protocol="tcp" port="8891"/><!-- Registrar TLS -->
|
|
<port protocol="tcp" port="8992"/><!-- Revocation -->
|
|
<port protocol="tcp" port="9002"/><!-- Agent -->
|
|
</service>
|