Matthias Gerstner
57ab8ba31f
+ Security - Fixed CVE-2024-29040 + Fixed - fapi: Fix length check on FAPI auth callbacks - mu: Correct error message for errors - tss2-rc: fix unknown laer handler dropping bits. - fapi: Fix deviation from CEL specification (template_value was used instead of template_data). - fapi: Fix json syntax error in FAPI profiles which was ignored by json-c. - build: fix build fail after make clean. - mu: Fix unneeded size check in TPM2B unmarshaling. - fapi: Fix missing parameter encryption. - build: Fix failed build with --disable-vendor. - fapi: Fix flush of persistent handles. - fapi: Fix test provisioning with template with self generated certificate disabled. - fapi: Fix error in Fapi_GetInfo it TPM supports SHA3 hash algs. - fapi: Revert pcr extension for EV_NO_ACTION events. - fapi: Fix strange error messages if nv, ext, or policy path does not exits. - fapi: Fix segfault caused by wrong allocation of pcr policy. - esys: Fix leak in Esys_EvictControl for persistent handles. - tss2-tcti: tcti-libtpms: fix test failure on big-endian platform. - esys: Add reference counting for Esys_TR_FromTPMPublic. - esys: Fix HMAC error if session bind key has an auth value with a trailing 0. - fapi: fix usage of self signed certificates in TPM. - fapi: Usage of self signed certificates. - fapi: A segfault after the error handling of non existing keys. - fapi: Fix several leaks. - fapi: Fix error handling for policy execution. - fapi: Fix usage of persistent handles (should not be flushed) - fapi: Fix test provisioning with template (skip test without self generated certificate). OBS-URL: https://build.opensuse.org/package/show/security/tpm2-0-tss?expand=0&rev=137
811 lines
37 KiB
Plaintext
811 lines
37 KiB
Plaintext
-------------------------------------------------------------------
|
|
Fri May 3 14:14:50 UTC 2024 - Matthias Gerstner <matthias.gerstner@suse.com>
|
|
|
|
Update to version 4.1:
|
|
|
|
+ Security
|
|
|
|
- Fixed CVE-2024-29040
|
|
|
|
+ Fixed
|
|
|
|
- fapi: Fix length check on FAPI auth callbacks
|
|
- mu: Correct error message for errors
|
|
- tss2-rc: fix unknown laer handler dropping bits.
|
|
- fapi: Fix deviation from CEL specification (template_value was used instead of template_data).
|
|
- fapi: Fix json syntax error in FAPI profiles which was ignored by json-c.
|
|
- build: fix build fail after make clean.
|
|
- mu: Fix unneeded size check in TPM2B unmarshaling.
|
|
- fapi: Fix missing parameter encryption.
|
|
- build: Fix failed build with --disable-vendor.
|
|
- fapi: Fix flush of persistent handles.
|
|
- fapi: Fix test provisioning with template with self generated certificate disabled.
|
|
- fapi: Fix error in Fapi_GetInfo it TPM supports SHA3 hash algs.
|
|
- fapi: Revert pcr extension for EV_NO_ACTION events.
|
|
- fapi: Fix strange error messages if nv, ext, or policy path does not exits.
|
|
- fapi: Fix segfault caused by wrong allocation of pcr policy.
|
|
- esys: Fix leak in Esys_EvictControl for persistent handles.
|
|
- tss2-tcti: tcti-libtpms: fix test failure on big-endian platform.
|
|
- esys: Add reference counting for Esys_TR_FromTPMPublic.
|
|
- esys: Fix HMAC error if session bind key has an auth value with a trailing 0.
|
|
- fapi: fix usage of self signed certificates in TPM.
|
|
- fapi: Usage of self signed certificates.
|
|
- fapi: A segfault after the error handling of non existing keys.
|
|
- fapi: Fix several leaks.
|
|
- fapi: Fix error handling for policy execution.
|
|
- fapi: Fix usage of persistent handles (should not be flushed)
|
|
- fapi: Fix test provisioning with template (skip test without self generated certificate).
|
|
- fapi: Fix pcr extension for EV_NO_ACTION
|
|
- test: Fix fapi-key-create-policy-signed-keyedhash with P_ECC384 profile
|
|
- tcti_spi_helper_transmit: ensure FIFO is accessed only after TPM reports commandReady bit is set
|
|
- fapi: Fix read large system eventlog (> UINT16_MAX).
|
|
- esys tests: Fix layer check for TPM2_RC_COMMAND_CODE (for /dev/tpmrm0)
|
|
- test: unit: tcti-libtpms: fix test failed at 32-bit platforms.
|
|
- fapi: Fix possible null pointer dereferencing in Fapi_List.
|
|
- sys: Fix size check in Tss2_Sys_GetCapability.
|
|
- esys: Fix leak in Esys_TR_FromTPMPublic.
|
|
- esys: fix unchecked return value in esys crypto.
|
|
- fapi: Fix wrong usage of local variable in provisioning.
|
|
- fapi: Fix memset 0 in ifapi_json_TPMS_POLICYNV_deserialize.
|
|
- fapi: Fix possible out of bound array access in IMA parser.
|
|
- tcti device: Fix possible unmarshalling from uninitialized variable.
|
|
- fapi: Fix error checking authorization of signing key.
|
|
- fapi: Fix cleanup of policy sessions.
|
|
- fapi: Eventlog H-CRTM events and different localities.
|
|
- fapi: Fix missing synchronization of quote and eventlog.
|
|
- faii: Fix invalid free in Fapi_Quote with empty eventlog.
|
|
|
|
+ Added
|
|
|
|
- tcti: LetsTrust-TPM2Go TCTI module spi-ltt2go.
|
|
- mbedtls: add sha512 hmac.
|
|
- fapi: Enable usage of external keys for Fapi_Encrypt.
|
|
- fapi: Support download of AMD certificates.
|
|
- tcti: Add USB TPM (FTDI MPSSE USB to SPI bridge) TCTI module.
|
|
- fapi: The recreation of primaries (except EK) in the owner hierarchy instead the endorsement hierarchy is fixed.
|
|
- rc: New TPM return codes added.
|
|
- fapi: Further Nuvoton certificates added.
|
|
- tpm_types/esys: Add support for Attestable TPM changes in latest TPM spec.
|
|
- tcti: Add '/dev/tcm0' to default conf
|
|
- fapi: New Nuvoton certificates added.
|
|
- esys: Fix leak in Esys_TR_FromTPMPublic.
|
|
|
|
+ Removed
|
|
|
|
- Testing on Ubuntu 18.04 as it's near EOL (May 2023).
|
|
|
|
- tpm2-tss.keyring: added Andreas Fuchs 0x8F4F9A45D7FFEE74 key, documented
|
|
in upstream repo, which was used for signing this new release tarball.
|
|
|
|
-------------------------------------------------------------------
|
|
Sat Jan 13 17:45:03 UTC 2024 - Callum Farmer <gmbr3@opensuse.org>
|
|
|
|
- Fix tmpfiles %ghost file names
|
|
|
|
-------------------------------------------------------------------
|
|
Sat Dec 16 16:41:48 UTC 2023 - Callum Farmer <gmbr3@opensuse.org>
|
|
|
|
- Move tmpfiles config to different package:
|
|
* tmpfiles_create was being called with bad input (version ?)
|
|
* it avoids breaking SLPP for libtss2-fapi1 (hence the prior
|
|
warning in spec)
|
|
- tss sysusers requires should be pre not post
|
|
|
|
-------------------------------------------------------------------
|
|
Mon Nov 27 10:41:32 UTC 2023 - Ludwig Nussel <lnussel@suse.com>
|
|
|
|
- libtss2-fapi1 requires system-user-tss for tmpfile creation
|
|
|
|
-------------------------------------------------------------------
|
|
Mon Jul 24 02:34:00 UTC 2023 - William Brown <william.brown@suse.com>
|
|
|
|
- Require openssl-3 over openssl-1 to assist migration of applications
|
|
to newer openssl-3.
|
|
|
|
-------------------------------------------------------------------
|
|
Thu Feb 16 14:41:06 UTC 2023 - Alberto Planas Dominguez <aplanas@suse.com>
|
|
|
|
- Drop 0001-tss2_rc-ensure-layer-number-is-in-bounds.patch as was
|
|
already merged upstream
|
|
- Update to 4.0.1
|
|
+ Fixed:
|
|
* A buffer overflow in tss2-rc as CVE-2023-22745.
|
|
- Update to 4.0.0
|
|
+ Fixed:
|
|
* tcti-ldr: Use heap instead of stack when tcti initialize
|
|
* Fix usage of NULL pointer if Esys_TR_SetAuth is calles with
|
|
ESYS_TR_NONE.
|
|
* Conditionally check user/group manipulation commands.
|
|
* Store VERSION into the release tarball.
|
|
* When using DESTDIR for make einstall, do not invoke
|
|
systemd-sysusers and systemd-tmpfiles.
|
|
* esys_iutil: fix possible NPD.
|
|
* Tss2_Sys_Flushcontext: flushHandle was encoded as a handleArea
|
|
handle and not as parameter one, this affected the contents of
|
|
cpHash.
|
|
* esys: fix allow usage of HMAC sessions for
|
|
Esys_TR_FromTPMPublic.
|
|
* fapi: fix usage of policy_nv with a TPM nv index.
|
|
* linking tcti for libtpms against tss2-tctildr. It should be
|
|
linked against tss2-mu.
|
|
* build: Remove erroneous trailing comma in linker option. Bug
|
|
#2391.
|
|
* fapi: fix encoding of complex tpm2bs in authorize nv,
|
|
duplication select and policy template policies. Now the complex
|
|
and TPMT or TPMS representations can be used. Bug #2383
|
|
* The error message for unsupported FAPI curves was in hex without
|
|
a leading 0x, make it integer output to clarify.
|
|
* Documentation that had various scalar out pointers as "callee
|
|
allocated".
|
|
* test: build with opaque FILE structure like in musl libc.
|
|
* Transient endorsement keys were not recreated according to the
|
|
EK credential profile.
|
|
* Evict control for a persistent EK failed during provisioning if
|
|
an auth value for the storage hierarchy was set.
|
|
* The authorization of the storage hierarchy is now added. Fixes
|
|
FAPI: Provisioning error if an auth value is needed for the
|
|
storage hierarchy #2438.
|
|
* Usage of a second profile in a path was not possible because the
|
|
default profile was always used.
|
|
* The setting of an empty auth value for Fapi_Provision was fixed.
|
|
* JSON encoding of a structure TPMS_POLICYAUTHORIZATION used the
|
|
field keyPEMhashAlg instead of hashAlg as defined in "TCG TSS
|
|
2.0 JSON Data Types and Policy Language Specification". Rename
|
|
to hashAlg but preserve support for reading keyPEMhashAlg for
|
|
backwards compatibility.
|
|
* fapi: PolicySecret did not work with keys as secret object.
|
|
* Esys_PCR_SetAuthValue: remembers the auth like other SetAutg
|
|
ESAPI functions.
|
|
* tests: esys-pcr-auth-value.int moved to destructive tests.
|
|
* FAPI: Fix double free if keystore is corrupted.
|
|
* Marshaling of TPMU_CAPABILITIES data, only field
|
|
intelPttProperty was broken before.a
|
|
* Spec deviation in Fapi_GetDescription caused description to be
|
|
NULL when it should be empty string. This is API breaking but
|
|
considered a bug since it deviated from the FAPI spec.
|
|
* FAPI: undefined reference to curl_url_strerror when using curl
|
|
less than 7.80.0.
|
|
* FAPI: Fixed support for EK templates in NV inidices per the
|
|
spec, see #2518 for details.
|
|
* FAPI: fix NPD in ifapi_curl logging.
|
|
* FAPI: Improve documentation fapi-profile
|
|
* FAPI: Fix CURL HTTP handling.
|
|
* FAPI: Return FAPI_RC_IO_ERROR if a policy does not exist in
|
|
keystore.
|
|
+ Added:
|
|
* TPM version 1.59 support.
|
|
* ci: ubuntu-22.04 added.
|
|
* mbedTLS 3.0 is supported by ESAPI.
|
|
* Add CreationHash to JSON output for usage between applications
|
|
not using the FAPI keystore, like command line tools.
|
|
* Reduced code size for SAPI.
|
|
* Support for Runtime Switchable ESAPI Crypto Backend via
|
|
Esys_SetCryptoCallbacks.
|
|
* Testing for TCG EK Credential Profile TPM 2.0, Version 2.4
|
|
Rev. 3, 2021 for the low and high address range of EK templates.
|
|
* tss2-rc: Tss2_RC_DecodeInfo function for parsing TSS2_RC into
|
|
the various bit fields.
|
|
* FAPI support for P_ECC384 profile.
|
|
* tss2-rc: Tss2_RC_DecodeInfoError: Function to get a human
|
|
readable error from a TSS2_RC_INFO returned by
|
|
Tss2_RC_DecodeInfo
|
|
* tcti: Generic SPI driver, implementors only need to connect to
|
|
acquire/release, transmit/receive, and sleep/timeout functions.
|
|
* FAPI: Add event logging for Firmware and IMA Events. See #2170
|
|
for details.
|
|
* FAPI: Fix Fapi_ChangeAuth updates on hierarchy objects not being
|
|
reflected across profiles.
|
|
* FAPI: Allow keyedhash keys in PolicySigned.
|
|
* ESAPI: Support sha512 for mbedtls crypto backend.
|
|
* TPM2B_MAX_CAP_BUFFER and mu routines
|
|
* vendor field to TPMU_CAPABILTIIES
|
|
* FAPI: support for PolicyTemplate
|
|
+ Changed
|
|
* libmu soname from 0:0:0 to 0:1:0.
|
|
* tss2-sys soname from 1:0:0 to 1:1:0
|
|
* tss2-esys: from 0:0:0 to 0:1:0
|
|
* FAPI ignores vendor properties on Fapi_GetInfo
|
|
* FAPI Event Logging JSON format, See #2170 for details.
|
|
+ Removed
|
|
* Dead struct TPMS_ALGORITHM_DESCRIPTION
|
|
* Dead field intelPttProperty from TPMU_CAPABILITIES
|
|
* Dead code Tss2_MU_TPMS_ALGORITHM_DESCRIPTION_Marshal
|
|
* Dead code Tss2_MU_TPMS_ALGORITHM_DESCRIPTION_Unmarshal
|
|
|
|
-------------------------------------------------------------------
|
|
Fri Jan 20 11:10:30 UTC 2023 - Matthias Gerstner <matthias.gerstner@suse.com>
|
|
|
|
- add 0001-tss2_rc-ensure-layer-number-is-in-bounds.patch: fixes
|
|
CVE-2023-22745 (bsc#1207325): Buffer Overlow in TSS2_RC_Decode. Overly large
|
|
RC values passed to the TSS2 function could lead to memory overread or
|
|
memory overread.
|
|
This patch is not yet part of any upstream git tag.
|
|
|
|
-------------------------------------------------------------------
|
|
Mon Jul 11 11:19:36 UTC 2022 - Alberto Planas Dominguez <aplanas@suse.com>
|
|
|
|
- Revert "Add version the configuration file tpm2-tss-fapi.conf"
|
|
This generate whitelist problems in rpmlint.
|
|
|
|
-------------------------------------------------------------------
|
|
Fri Jul 8 11:52:40 UTC 2022 - Alberto Planas Dominguez <aplanas@suse.com>
|
|
|
|
- Update to 3.2.0
|
|
+ Fixed
|
|
* FAPI: fix curl_url_set call
|
|
* FAPI: Fix usage of curl url (Should fix Ubuntu 22.04)
|
|
* Fix buffer upcast leading to misalignment
|
|
* Fix check whether SM3 is available
|
|
* Update git.mk to support R/O src-dir
|
|
* Fixed file descriptor leak when tcti initialization failed.
|
|
* 32 Bit builds of the integration tests.
|
|
* Primary key creation, in some cases the unique field was not
|
|
cleared before calling create primary.
|
|
* Primary keys was used for signing the object were cleared after
|
|
loading. So access e.g. to the certificate did not work.
|
|
* Primary keys created with Fapi_Create with an auth value, the
|
|
auth_value was not used in inSensitive to recreate the primary
|
|
key. Now the auth value callback is used to initialize
|
|
inSensitive.
|
|
* The not possible usage of policies for primary keys generated
|
|
with Fapi_CreatePrimary has been fixed.
|
|
* An infinite loop when parsing erroneous JSON was fixed in FAPI.
|
|
* A buffer overflow in ESAPI xor parameter obfuscation was fixed.
|
|
* Certificates could be read only once in one application The
|
|
setting the init state of the state automaton for getting
|
|
certificates was fixed.
|
|
* A double free when executing policy action was fixed.
|
|
* A leak in Fapi_Quote was fixed.
|
|
* The wrong file locking in FAPI IO was fixed.
|
|
* Enable creation of tss group and user on systems with busybox
|
|
for fapi.
|
|
* One fapi integration test did change the auth value of the
|
|
storage hierarchy.
|
|
* A leak in fapi crypto with ossl3 was fixed.
|
|
* Add initial camelia support to FAPI
|
|
* Fix tests of fapi PCR
|
|
* Fix tests of ACT functionality if not supported by pTPM
|
|
* Fix compiler (unused) warning when building without debug
|
|
logging
|
|
* Fix leaks in error cases of integration tests
|
|
* Fix memory leak after ifapi_init_primary_finish failed
|
|
* Fix double-close of stream in FAPI
|
|
* Fix segfault when ESYS_TR_NONE is passed to Esys_TR_GetName
|
|
* Fix the authorization of hierarchy objects used in policy
|
|
secret.
|
|
* Fix check of qualifying data in Fapi_VerifyQuote.
|
|
* Fix some leaks in FAPI error cases.
|
|
* Make scripts compatible with non-posix shells where test does
|
|
not know -a and -o.
|
|
* Fix usage of variable not initialized when fapi keystore is
|
|
empty.
|
|
+ Added
|
|
* Add additional IFX root CAs
|
|
* Added support for SM2, SM3 and SM4.
|
|
* Added support for OpenSSL 3.0.0.
|
|
* Added authPolicy field to the TPMU_CAPABILITIES union.
|
|
* Added actData field to the TPMU_CAPABILITIES union.
|
|
* Added TPM2_CAP_AUTH_POLICIES
|
|
* Added TPM2_CAP_ACT constants.
|
|
* Added updates to the marshalling and unmarshalling of the
|
|
TPMU_CAPABILITIES union.
|
|
* Added updated to the FAPI serializations and deserializations of
|
|
the TPMU_CAPABILITIES union and associated types.
|
|
* Add CODE_OF_CONDUCT
|
|
* tcti-mssim and tcti-swtpm gained support for UDX communication
|
|
* Missing constant for TPM2_RH_PW
|
|
+ Removed
|
|
* Removed support for OpenSSL < 1.1.0.
|
|
* Marked TPMS_ALGORITHM_DESCRIPTION and corresponding MU routines
|
|
as deprecated.
|
|
* Those were errorous typedefs that are not use and not useful. So
|
|
we will remove this with 3.3
|
|
* Marked TPM2_RS_PW as deprecated. Use TPM2_RH_PW instead.
|
|
|
|
- Update to 3.1.1
|
|
+ Fixed
|
|
* Fixed file descriptor leak when tcti initialization failed.
|
|
* Primary key creation, in some cases the unique field was not
|
|
cleared before calling create primary.
|
|
* Primary keys was used for signing the object were cleared after
|
|
loading. So access e.g. to the certificate did not work.
|
|
* Primary keys created with Fapi_Create with an auth value, the
|
|
auth_value was not used in inSensitive to recreate the primary
|
|
key. Now the auth value callback is used to initialize
|
|
inSensitive.
|
|
* The not possible usage of policies for primary keys generated
|
|
with Fapi_CreatePrimary has been fixed.
|
|
* An infinite loop when parsing erroneous JSON was fixed in FAPI.
|
|
* A buffer overflow in ESAPI xor parameter obfuscation was fixed.
|
|
* Certificates could be read only once in one application The
|
|
setting the init state of the state automaton for getting
|
|
certificates was fixed.
|
|
* A double free when executing policy action was fixed.
|
|
* A leak in Fapi_Quote was fixed.
|
|
* The wrong file locking in FAPI IO was fixed.
|
|
* One fapi integration test did change the auth value of the
|
|
storage hierarchy.
|
|
* Fix test of FAPI PCR
|
|
* Fix leaks in error cases of integration tests
|
|
* Fix segfault when ESYS_TR_NONE is passed to Esys_TR_GetName
|
|
* Fix the authorization of hierarchy objects used in policy
|
|
secret.
|
|
* Fix check of qualifying data in Fapi_VerifyQuote.
|
|
* Fix some leaks in FAPI error cases.
|
|
* Fix usage of variable not initialized when fapi keystore is
|
|
empty.
|
|
+ Added
|
|
* Add additional IFX root CAs
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Dec 8 16:57:58 UTC 2021 - Alberto Planas Dominguez <aplanas@suse.com>
|
|
|
|
- Version 3.1.0 includes:
|
|
+ cover update to 2.4.5 (jsc#SLE-17366)
|
|
+ cover update to 2.3.0 (jsc#SLE-9515)
|
|
+ fix policy session for TPM2_PolicyAuthValue (bsc#1160736)
|
|
- Add version the configuration file tpm2-tss-fapi.conf
|
|
|
|
-------------------------------------------------------------------
|
|
Thu Jul 15 15:51:04 UTC 2021 - Callum Farmer <gmbr3@opensuse.org>
|
|
|
|
- Remove conflicting sysusers.d file
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Jul 14 15:11:55 UTC 2021 - Callum Farmer <gmbr3@opensuse.org>
|
|
|
|
- Clean spec file
|
|
- Add new library libtss2-tcti-pcap0
|
|
- Update to 3.1.0:
|
|
* Fix FAPI PolicyPCR not instatiating correctly (CVE-2020-24455)
|
|
* Fixed possible access outside the array in ifapi_calculate_tree
|
|
* Added pcap TCTI
|
|
* Added GlobalSign TPM Root CA certs to FAPI cert store
|
|
* Changed EncryptDecrypt mode type to align with TPM2.0 spec 1.59
|
|
* Added two new TPM commands TPM2_CC_CertifyX509,
|
|
and TPM2_CC_ACT_SetTimeout
|
|
|
|
-------------------------------------------------------------------
|
|
Mon Jun 28 06:52:53 UTC 2021 - Marcus Meissner <meissner@suse.com>
|
|
|
|
- small services fixes and comments
|
|
|
|
-------------------------------------------------------------------
|
|
Thu Jan 28 09:18:58 UTC 2021 - Matthias Gerstner <matthias.gerstner@suse.com>
|
|
|
|
- update to 3.0.3:
|
|
- changes in 3.0.3:
|
|
* Fix Regression in Fapi_List
|
|
* Fix memory leak in policy calculation
|
|
- changes in 3.0.2:
|
|
* FAPI: Fix setting of the system flag of NV objects
|
|
* This will let NV object metadata be created system-wide always instead of
|
|
* locally in the user. Existing metadata will remain in the user directory.
|
|
* It can be moved to the corresponding systemstore manually if needed.
|
|
* FAPI: Fix policy searching, when a policyRef was provided
|
|
* FAPI: Accept EK-Certs without CRL dist point
|
|
* FAPI: Fix return codes of Fapi_List
|
|
* FAPI: Fix memleak in policy execution
|
|
* FAPI: Fix coverity NULL-pointer check
|
|
* FAPI: Set the written flag of NV objects in FAPI PolicyNV commands
|
|
* FAPI: Fix deleting of policy files.
|
|
* FAPI: Fix wrong file loading during object search.
|
|
* Fapi: Fix memory leak
|
|
* Fapi: Fix potential NULL-Dereference
|
|
* Fapi: Remove superfluous NULL check
|
|
* Fix a memory leak in async keystore load.
|
|
|
|
-------------------------------------------------------------------
|
|
Thu Oct 22 11:38:52 UTC 2020 - Matthias Gerstner <matthias.gerstner@suse.com>
|
|
|
|
- move the tcti-fapi tmpfiles.d config file into the libtss2-fapi1 sub-package.
|
|
- improve the descriptions of new libraries (fapi1, cmd0, swtpm0)
|
|
- adjust baselibs.conf to match new library versions and added libraries
|
|
|
|
-------------------------------------------------------------------
|
|
Mon Oct 19 13:30:39 UTC 2020 - Guillaume GARDET <guillaume.gardet@opensuse.org>
|
|
|
|
- Update to 3.0.1, changelog at:
|
|
https://github.com/tpm2-software/tpm2-tss/blob/3.0.x/CHANGELOG.md
|
|
- Update libtss2-sys0 to libtss2-sys1
|
|
- Add new libs:
|
|
* libtss2-fapi1
|
|
* libtss2-tcti-cmd0
|
|
* libtss2-tcti-swtpm0
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Feb 19 19:37:14 UTC 2020 - Martin Hauke <mardnh@gmx.de>
|
|
|
|
- Update to version 2.3.3
|
|
* Fixed mixing salted and unsalted sessions in the same ESAPI
|
|
context
|
|
* Removed use of VLAs from TPML marshal code
|
|
* Added check for object node before calling compute_session_value
|
|
function
|
|
* Fixed auth calculation in Esys_StartAuthSession called with
|
|
optional parameters
|
|
* Fixed compute_encrypted_salt error handling in
|
|
Esys_StartAuthSession
|
|
* Fixed exported symbols map for libtss2-mu
|
|
|
|
-------------------------------------------------------------------
|
|
Fri Jan 31 11:51:03 UTC 2020 - Michal Suchanek <msuchanek@suse.com>
|
|
|
|
- Use system-users for tss user creation (boo#1162360).
|
|
|
|
-------------------------------------------------------------------
|
|
Fri Jan 24 14:13:01 UTC 2020 - Dominique Leuenberger <dimstar@opensuse.org>
|
|
|
|
- BuildRequire pkgconfig(udev) instead of udev: allow OBS to
|
|
shortcut through the -mini flavor.
|
|
|
|
-------------------------------------------------------------------
|
|
Sun Dec 29 21:06:27 UTC 2019 - Martin Hauke <mardnh@gmx.de>
|
|
|
|
- update to upstream version 2.3.2:
|
|
- changes since version 2.3.0:
|
|
- Fix unit tests on S390 architectures
|
|
- Fixed HMAC generation for policy sessions
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Dec 11 11:01:44 UTC 2019 - matthias.gerstner@suse.com
|
|
|
|
- update to upstream version 2.3.0:
|
|
- changes in version 2.3.0:
|
|
- tss2-tctildr: A new library that helps with tcti initialization
|
|
Recommend to use this in place of custom tcti loading code now !
|
|
- tss2-rc: A new library that provides textual representations for return
|
|
codes
|
|
- Option to disable NIST-deprecated crypto (--disable-weak-crypto)
|
|
- Support Esys_TR_FromTPMPublic on sessions (for use in Esys_FlushContext)
|
|
- map-files with correct symbol lists for tss2-sys and tss2-esys
|
|
This may lead to unresolved symbols in linked applications
|
|
- Support to call Tss2_Sys_Execute repeatedly on certain errors
|
|
- Reduced RAM consumption in Esys due to Tss2_Sys_Execute change
|
|
- Automated session attribution clearing for esys (decrypt and encrypt)
|
|
per cmd
|
|
- Removed libtss2-mu from "Requires" field of libtss2-esys.pc
|
|
Needs to be added explicitely now
|
|
- All fixes from 2.2.1, 2.2.2 and 2.2.3
|
|
- Fixed SPDX License Identifiers
|
|
- Fixed Null-pointer problems in tcti-tbs
|
|
- Fixed Default locality for tcti-mssim set to LOC_0
|
|
- Fixed coverity and valgrind leaks detected in test programs (not library
|
|
code)
|
|
|
|
-------------------------------------------------------------------
|
|
Fri Aug 23 12:06:22 UTC 2019 - matthias.gerstner@suse.com
|
|
|
|
- update to upstream version 2.2.3:
|
|
- changes in version 2.2.3:
|
|
* Fix computation of session name
|
|
* Fixed PolicyPassword handling of session Attributes
|
|
* Fixed windows build from dist ball
|
|
* Fixed default tcti configure option
|
|
* Fixed nonce size calculation in ESYS sessions
|
|
- changes in version 2.2.2:
|
|
* Fixed wrong encryption flag in EncryptDecrypt
|
|
* Fixing openssl engine invocation
|
|
|
|
-------------------------------------------------------------------
|
|
Fri Apr 26 10:37:23 UTC 2019 - mvetter@suse.com
|
|
|
|
- bsc#1130588: Require shadow instead of old pwdutils
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Mar 6 10:06:35 UTC 2019 - matthias.gerstner@suse.com
|
|
|
|
- update to upstream version 2.2.1:
|
|
- changes from version 2.2.0:
|
|
- Fixed leak of hkey on success in iesys_cryptossl_hmac_start
|
|
- Fixed NULL ptr issues in Esys_HMAC_Start, Esys_HierarchyChangeAuth and Esys_NV_ChangeAuth
|
|
- Fixed NULL ptr issue in sequenceHandleNode
|
|
- Fixed NULL ptr auth handling in Esys_TR_SetAuth
|
|
- Fixed NULL auth handling in iesys_compute_session_value
|
|
- Fixed marshaling of TPM2Bs with sub types.
|
|
- Fixed NULL ptr session handling in Esys_TRSess_SetAttributes
|
|
- Fixed the way size of the hmac value of a session without authorization
|
|
- Added missing MU functions for TPM2_NT type
|
|
- Added missing MU functions for TPMA_ID_OBJECT type
|
|
- Added missing type TPM2_NT into tss2_tpm2_types.h
|
|
- Fixed wrong typename _ID_OBJECT in tss2_tpm2_types.h
|
|
- Fixed build breakage when --with-maxloglevel is not 'trace'
|
|
- Fixed build breakage in generated configure script when CFLAGS is set
|
|
- Fixed configure scritp ERROR_IF_NO_PROG macro
|
|
- Changed TPM2B type unmarshal to use sizeof of the dest buffer instead of dest
|
|
- Fixed unmarshaling of the TPM2B type with invalid size
|
|
- Removed dead code defect detected by coverity from Esys_TRSess_GetNonceTPM
|
|
- Added support for QNX build
|
|
- Added support for partial reads in device TCTI
|
|
- changes from version 2.1.1:
|
|
- Fixed leak of hkey on success in iesys_cryptossl_hmac_start
|
|
- Fixed NULL ptr issues in Esys_HMAC_Start, Esys_HierarchyChangeAuth and Esys_NV_ChangeAuth
|
|
- Fixed NULL ptr issue in sequenceHandleNode
|
|
- Fixed NULL ptr auth handling in Esys_TR_SetAuth
|
|
- Fixed NULL auth handling in iesys_compute_session_value
|
|
- Fixed marshaling of TPM2Bs with sub types.
|
|
- Fixed NULL ptr session handling in Esys_TRSess_SetAttributes
|
|
- Fixed the way size of the hmac value of a session without authorization
|
|
- Added missing MU functions for TPM2_NT type
|
|
- Added missing MU functions for TPMA_ID_OBJECT type
|
|
- Added missing type TPM2_NT into tss2_tpm2_types.h
|
|
- Fixed wrong typename _ID_OBJECT in tss2_tpm2_types.h
|
|
- Fixed build breakage when --with-maxloglevel is not 'trace'
|
|
- Fixed build breakage in generated configure script when CFLAGS is set
|
|
- Fixed configure scritp ERROR_IF_NO_PROG macro
|
|
- Changed TPM2B type unmarshal to use sizeof of the dest buffer instead of dest
|
|
- Fixed unmarshaling of the TPM2B type with invalid size
|
|
- Removed dead code defect detected by coverity from Esys_TRSess_GetNonceTPM
|
|
- changes from version 2.1.0:
|
|
- Fixed handling of the default TCTI
|
|
- Changed logging to be ISO-C99 compatible
|
|
- Fixed leak of dlopen handle
|
|
- Fixed logging of a response header tag in Tss2_Sys_Execute
|
|
- Fixed marshaling of TPM2B parameters in SAPI commands
|
|
- Fixed unnecessary warning in Esys_Startup
|
|
- Fixed warnings in doxygen documentation
|
|
- Added Esys_Free wrapper function for systems using different C runtime libraries
|
|
- Added Windows TBS TCTI
|
|
- Added non-blocking mode of operation in tcti-device
|
|
- Added tests for Esys_HMAC and Esys_Hash
|
|
- Enabled integration tests on physical TPM device
|
|
- Added openssl libcrypto backend
|
|
- Added Doxygen documentation to integration tests
|
|
- Refactored SetDecryptParam
|
|
- Enabled OpenSSL crypto backend by default
|
|
- changes from 2.0.2:
|
|
- Fixed NULL ptr issues in Esys_HMAC_Start, Esys_HierarchyChangeAuth and Esys_NV_ChangeAuth
|
|
- Fixed NULL ptr issue in sequenceHandleNode
|
|
- Fixed NULL ptr auth handling in Esys_TR_SetAuth
|
|
- Fixed NULL auth handling in iesys_compute_session_value
|
|
- Fixed marshaling of TPM2Bs with sub types.
|
|
- Fixed NULL ptr session handling in Esys_TRSess_SetAttributes
|
|
- Fixed the way size of the hmac value of a session without authorization
|
|
- Added missing MU functions for TPM2_NT type
|
|
- Added missing MU functions for TPMA_ID_OBJECT type
|
|
- Added missing type TPM2_NT into tss2_tpm2_types.h
|
|
- Fixed wrong typename _ID_OBJECT in tss2_tpm2_types.h
|
|
- Fixed build breakage when --with-maxloglevel is not 'trace'
|
|
- Fixed build breakage in generated configure script when CFLAGS is set
|
|
- Fixed configure scritp ERROR_IF_NO_PROG macro
|
|
- Changed TPM2B type unmarshal to use sizeof of the dest buffer instead of dest
|
|
- Fixed unmarshaling of the TPM2B type with invalid size
|
|
- Removed dead code defect detected by coverity from Esys_TRSess_GetNonceTPM
|
|
- introduce _service file for syncing with upstream tags
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Sep 26 15:41:27 UTC 2018 - matthias.gerstner@suse.com
|
|
|
|
- update to upstream version 2.0.1 (FATE#324477):
|
|
- Fixed problems with doxygan failing make distcheck
|
|
- Fixed conversion of gcrypt mpi numbers to binary data
|
|
- Fixed an error in parsing socket address in MSSIM TCTI
|
|
- Fixed compilation error with --disable-tcti-mssim
|
|
- Added initialization function for gcrypt to suppress warning
|
|
- Fixed invalid type base type while marshaling TPMI_ECC_CURVE in Tss2_Sys_ECC_Parameters
|
|
- Fixed invalid RSA encryption with exponent equal to 0
|
|
- Fixed checking of return codes in ESAPI commands
|
|
- Added checks for programs required by the test harness @ configure time
|
|
- Fixed warning on TPM2_RC_INITIALIZE rc after a Startup in Esys_Startup
|
|
- Checked for 1.2 TPM type response
|
|
- Changed constants values in esys header file to unsigned
|
|
-------------------------------------------------------------------
|
|
Tue Sep 18 09:04:31 UTC 2018 - matthias.gerstner@suse.com
|
|
|
|
- also process udev triggers for tpmrm subsystem, otherwise /dev/tpmrm0 isn't
|
|
properly updated (at least on SLES-12-SP4)
|
|
|
|
-------------------------------------------------------------------
|
|
Thu Jul 5 15:40:23 UTC 2018 - matthias.gerstner@suse.com
|
|
|
|
- added all librares to baselibs.conf to satisfy 32-bit dependencies of esys0
|
|
and sys0
|
|
|
|
-------------------------------------------------------------------
|
|
Tue Jul 3 07:56:18 UTC 2018 - matthias.gerstner@suse.com
|
|
|
|
- Explicitly require udev to fix missing ownership for /usr/lib/udev.
|
|
|
|
-------------------------------------------------------------------
|
|
Fri Jun 29 10:55:58 UTC 2018 - matthias.gerstner@suse.com
|
|
|
|
- update to new major version 2.0.0:
|
|
- version_fix.patch: removed, we're now using the distribution tarballs
|
|
where this problem shouldn't happen
|
|
- this update introduces an incompatible ABI to the previous version.
|
|
all libraries have been renamed so there is not really a relation to
|
|
the old version any more.
|
|
- upstream changelog:
|
|
## [2.0.0] - 2018-06-20
|
|
### Added
|
|
- Implementation of the Marshal/Unmarshal library (libtss2-mu)
|
|
- Implementation of the Enhanced System API (libtss2-esys aka ESAPI)
|
|
- New implemetation of the TPM Command Transmission Interface (TCTI) for:
|
|
- communication with Linux TPM2 device driver: libtss2-tcti-device
|
|
- communication with Microsoft software simulator: libtss2-tcti-mssim
|
|
- New directory layout (API break)
|
|
- Updated documentation with new doxygen and updated man pages
|
|
- Support for Windows build with Visual Studio and clang, currently limited
|
|
to libtss2-mu and libtss2-sys
|
|
- Implementation of the new Attached Component (AC) commands
|
|
- Implementation of the new TPM2_PolicyAuthorizeNV command
|
|
- Implementation of the new TPM2_CreateLoaded command
|
|
- Implementation of the new TPM2_PolicyTemplate command
|
|
- Addition of _Complete functions to all TPM commands
|
|
- New logging framework
|
|
- Added const qualifiers to API input pointers (API break)
|
|
- Cleaned up headers and remove implementation.h and tpm2.h (API break)
|
|
### Changed
|
|
- Converted all cpp files to c, removed dependency on C++ compiler.
|
|
- Cleaned out a number of marshaling functions from the SAPI code.
|
|
- Update Linux / Unix OS detection to use non-obsolete macros.
|
|
- Changed TCTI macros to CamelCase (API break)
|
|
- Changed TPMA_types to unsigned int with defines instead of bitfield structs (API/ABI break)
|
|
- Changed Get/SetCmd/RspAuths to new parameter types (API/ABI break)
|
|
- Fixed order of parameters in AC commands: Input command authorizations
|
|
now come after the input handles, but still before the command parameters.
|
|
### Removed
|
|
- Removed all sysapi/sysapi_utils/*arshal_TPM*.c files
|
|
### Fixed
|
|
- Updated invalid number of handles in TPM2_PolicyNvWritten and TPM2_TestParms
|
|
- Updated PlatformCommand function from libtss2-tcti-mssim to no longer send
|
|
CANCEL_OFF before every command.
|
|
- Expanded TPM2B macros and removed TPM2B_TYPE1 and TPM2B_TYPE2 macros
|
|
- Fixed wrong return type for Tss2_Sys_Finalize (API break).
|
|
|
|
## [1.4.0] - 2018-03-02
|
|
### Added
|
|
- Attached Component commands from the last public review spec.
|
|
### Fixed
|
|
- Essential files missing from release tarballs are now included.
|
|
- Version string generation has been moved from configure.ac to the
|
|
bootstrap script. It is now stored in a file named `VERSION` that is
|
|
shipped in the release tarball.
|
|
- We've stopped shipping the built man page for InitSocketTcti.3 and now
|
|
ship the source.
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Mar 7 14:48:50 UTC 2018 - matthias.gerstner@suse.com
|
|
|
|
- removed leftover comment from dropped reproducable.patch
|
|
|
|
-------------------------------------------------------------------
|
|
Thu Feb 22 09:41:46 UTC 2018 - matthias.gerstner@suse.com
|
|
|
|
- update to upstream version 1.3.0:
|
|
- support for reproducable builds
|
|
- improved documentation / manual pages
|
|
- various stability bugfixes
|
|
- EncryptDecrypt2 command is now implemented
|
|
- removed reproducible.patch. This is now included upstream.
|
|
- added version_fix.patch to fix package config version numbers.
|
|
|
|
-------------------------------------------------------------------
|
|
Fri Sep 1 14:27:33 UTC 2017 - matthias.gerstner@suse.com
|
|
|
|
- fix the "fix", turns out only the unversioned symlink's supposed to go into
|
|
-devel.
|
|
|
|
-------------------------------------------------------------------
|
|
Thu Jul 20 13:51:38 UTC 2017 - matthias.gerstner@suse.com
|
|
|
|
- no longer install the udev rule, it's now part of the new tpm2.0-abrmd
|
|
package.
|
|
- fixed a warning regarding a missing dependency of the devel package to the
|
|
main package
|
|
- correctly package library symlinks only in the devel package, the library
|
|
itself only in the library package. Was mixed up before.
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Jul 19 14:10:02 UTC 2017 - matthias.gerstner@suse.com
|
|
|
|
- removed tpm2-0-tss-configure.patch, it was just a hack, fixed by requiring
|
|
autoconf-archive, see https://github.com/01org/TPM2.0-TSS/issues/227.
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Jul 19 11:13:43 UTC 2017 - matthias.gerstner@suse.com
|
|
|
|
- Updated to upstream version 1.1.0
|
|
- With this version the resourcemgr daemon is dropped from this package. It
|
|
is replaced by a completely new implementation found in a new package
|
|
tpm2.0-abrmd. this package will only consist of the libraries any more.
|
|
|
|
- Changed
|
|
- tpmclient, disabled all tests that rely on the old resourcemgr.
|
|
- Fixed
|
|
- Fixed definition of PCR_LAST AND TRANSIENT_LAST macros.
|
|
- Removed
|
|
- tpmtest
|
|
- resourcemgr, replacement is in new repo: https://github.com/01org/tpm2-abrmd
|
|
|
|
-------------------------------------------------------------------
|
|
Sat May 27 05:07:22 UTC 2017 - bwiedemann@suse.com
|
|
|
|
- Add reproducible.patch to sort input files to make build reproducible
|
|
(boo#1041090)
|
|
|
|
-------------------------------------------------------------------
|
|
Thu May 11 15:13:49 UTC 2017 - matthias.gerstner@suse.com
|
|
|
|
- create tss user account and install udev rule to fix startup of resourcemgr
|
|
(bnc#1038586)
|
|
|
|
-------------------------------------------------------------------
|
|
Wed May 10 13:33:16 CEST 2017 - mgerstner@suse.com
|
|
|
|
- remove unnecessary dependency of libsapi0 to trousers. trousers has nothing
|
|
to do with tpm2-tss.
|
|
|
|
-------------------------------------------------------------------
|
|
Tue Apr 11 14:26:14 UTC 2017 - meissner@suse.com
|
|
|
|
- fixed typo in resourcemgr.service (bsc#1031004)
|
|
|
|
-------------------------------------------------------------------
|
|
Thu Feb 16 13:35:44 UTC 2017 - jengelh@inai.de
|
|
|
|
- Remove --with-pic which is only for static libs.
|
|
- Fix an improper Requires line.
|
|
- Split libtcti* from libsapi0; these are independentlty
|
|
developable units.
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Feb 8 13:43:55 UTC 2017 - meissner@suse.com
|
|
|
|
- Updated to 1.0 (FATE#321508)
|
|
- Added
|
|
- Travis-CI integration with GitHub
|
|
- Unit tests for primitive (un)?marshal functions.
|
|
- Example systemd unit for resourcemgr.
|
|
- Allow for unit tests to be enabled selectively.
|
|
- added pkg-config files for libraries
|
|
- Changed
|
|
- move simulator initialization code to socket TCTI init function.
|
|
- socket TCTI finalize no longer frees context
|
|
- rename libtss2 to libsapi
|
|
- rename libtcti_device to libtcti-device
|
|
- rename libtcti_socket to libtcti-socket
|
|
- move $(includedir)/tss to $(includedir)/sapi
|
|
- Move default compiler flags to config.site file.
|
|
- Fixed
|
|
- Fix run away resourcemgr threads by closing client sockets when resourcemgr recv() call returns 0.
|
|
- Set MSG_NOSIGNAL for client connections to avoid SIGPIPE killing resourcemgr.
|
|
- Fixes to handling of persistent objects by resourcemgr.
|
|
- Removed
|
|
- Semicolon from TPMA_* macros definitions.
|
|
- Windows build files.
|
|
- SAPI_CLIENT macro tests.
|
|
- Security
|
|
- Fix buffer overflow in resourcemgr.
|
|
- use sample resourcemanager.service
|
|
- tpm2-0-tss-configure.patch: fix weird error.
|
|
|
|
-------------------------------------------------------------------
|
|
Thu Aug 25 14:09:35 UTC 2016 - meissner@suse.com
|
|
|
|
- Remove type=forking from service file (bsc#995554)
|
|
|
|
-------------------------------------------------------------------
|
|
Sat Aug 6 19:28:27 UTC 2016 - meissner@suse.com
|
|
|
|
- added a systemd unit service file (FATE#315631)
|
|
|
|
-------------------------------------------------------------------
|
|
Fri May 6 19:45:29 UTC 2016 - jengelh@inai.de
|
|
|
|
- Correct package naming to be in line with shared library guideline
|
|
- Remove unused systemd build and runtime dependencies
|
|
(FATE#315631)
|
|
|
|
-------------------------------------------------------------------
|
|
Fri Apr 8 07:54:36 UTC 2016 - dimstar@opensuse.org
|
|
|
|
- Fix rpm group of library package: libs belong, per definition, to
|
|
the group "System/Libraries". (FATE#315631)
|
|
|
|
-------------------------------------------------------------------
|
|
Wed Feb 24 10:22:38 UTC 2016 - meissner@suse.com
|
|
|
|
- initial import of the tpm 2.0 tss stack (FATE#315631)
|
|
|