forked from pool/openCryptoki
Compare commits
25 Commits
| Author | SHA256 | Date | |
|---|---|---|---|
| 50f918c479 | |||
| 385978d731 | |||
| a4136eb6b0 | |||
| c3bf64bbeb | |||
| 2adac5327d | |||
| 5109b8e9c7 | |||
| c1572a29e7 | |||
| 148c16ad39 | |||
| a8fc1c77d5 | |||
| fb5379acfa | |||
| 06c7a2b6cb | |||
| c0c363b296 | |||
| f63b6c5588 | |||
| 1b384ad0c5 | |||
| 5ef07f9781 | |||
| e2c621380b | |||
| dd70f3c654 | |||
| a8259b2ab7 | |||
| 331c79661a | |||
| 734886bc1f | |||
| be36dcd909 | |||
| e29b370f5e | |||
| bf201b0bdc | |||
| 9fe6016626 | |||
| 1cfa0e9e91 |
@@ -1,21 +1,26 @@
|
||||
--- Makefile.am 2023-05-15 14:42:55.000000000 +0200
|
||||
+++ Makefile-3.21.am 2023-05-25 17:13:36.266936832 +0200
|
||||
@@ -39,14 +39,9 @@
|
||||
--- a/Makefile.am 2025-11-11 08:58:19.000000000 +0100
|
||||
+++ b/Makefile.am 2025-11-12 10:21:00.563936369 +0100
|
||||
@@ -51,19 +51,9 @@
|
||||
include doc/doc.mk
|
||||
|
||||
install-data-hook:
|
||||
-if AIX
|
||||
- lsgroup $(pkcs_group) > /dev/null || $(GROUPADD) -a pkcs11
|
||||
- lsuser $(pkcsslotd_user) > /dev/null || $(USERADD) -g $(pkcs_group) -d $(DESTDIR)$(RUN_PATH)/opencryptoki -c "Opencryptoki pkcsslotd user" $(pkcsslotd_user)
|
||||
-else
|
||||
- getent group $(pkcs_group) > /dev/null || $(GROUPADD) -r $(pkcs_group)
|
||||
- getent passwd $(pkcsslotd_user) >/dev/null || $(USERADD) -r -g $(pkcs_group) -d /run/opencryptoki -s /sbin/nologin -c "Opencryptoki pkcsslotd user" $(pkcsslotd_user)
|
||||
$(MKDIR_P) $(DESTDIR)/run/opencryptoki/
|
||||
- $(CHOWN) $(pkcsslotd_user):$(pkcs_group) $(DESTDIR)/run/opencryptoki/
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)/run/opencryptoki/
|
||||
$(CHMOD) 0710 $(DESTDIR)/run/opencryptoki/
|
||||
- getent passwd $(pkcsslotd_user) >/dev/null || $(USERADD) -r -g $(pkcs_group) -d $(RUN_PATH)/opencryptoki -s /sbin/nologin -c "Opencryptoki pkcsslotd user" $(pkcsslotd_user)
|
||||
-endif
|
||||
$(MKDIR_P) $(DESTDIR)$(RUN_PATH)/opencryptoki/
|
||||
- $(CHOWN) $(pkcsslotd_user):$(pkcs_group) $(DESTDIR)$(RUN_PATH)/opencryptoki/
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(RUN_PATH)/opencryptoki/
|
||||
$(CHMOD) 0710 $(DESTDIR)$(RUN_PATH)/opencryptoki/
|
||||
$(MKDIR_P) $(DESTDIR)$(localstatedir)/lib/opencryptoki
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki
|
||||
$(CHMOD) 0770 $(DESTDIR)$(localstatedir)/lib/opencryptoki
|
||||
if ENABLE_LIBRARY
|
||||
$(MKDIR_P) $(DESTDIR)$(libdir)/opencryptoki/stdll
|
||||
@@ -66,19 +61,15 @@
|
||||
@@ -83,19 +73,15 @@
|
||||
endif
|
||||
if ENABLE_PKCSHSM_MK_CHANGE
|
||||
$(MKDIR_P) $(DESTDIR)$(localstatedir)/lib/opencryptoki/HSM_MK_CHANGE
|
||||
@@ -24,7 +29,7 @@
|
||||
endif
|
||||
if ENABLE_CCATOK
|
||||
cd $(DESTDIR)$(libdir)/opencryptoki/stdll && \
|
||||
ln -fs libpkcs11_cca.so PKCS11_CCA.so
|
||||
ln -fs libpkcs11_cca.$(SHLIBEXT) PKCS11_CCA.$(SHLIBEXT)
|
||||
$(MKDIR_P) $(DESTDIR)$(localstatedir)/lib/opencryptoki/ccatok/TOK_OBJ
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/ccatok/TOK_OBJ
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/ccatok
|
||||
@@ -35,9 +40,9 @@
|
||||
$(CHMOD) 0770 $(DESTDIR)$(lockdir)/ccatok
|
||||
test -f $(DESTDIR)$(sysconfdir)/opencryptoki || $(MKDIR_P) $(DESTDIR)$(sysconfdir)/opencryptoki || true
|
||||
test -f $(DESTDIR)$(sysconfdir)/opencryptoki/ccatok.conf || $(INSTALL) -m 644 $(srcdir)/usr/lib/cca_stdll/ccatok.conf $(DESTDIR)$(sysconfdir)/opencryptoki/ccatok.conf || true
|
||||
@@ -87,12 +78,9 @@
|
||||
@@ -104,12 +90,9 @@
|
||||
cd $(DESTDIR)$(libdir)/opencryptoki/stdll && \
|
||||
ln -fs libpkcs11_ep11.so PKCS11_EP11.so
|
||||
ln -fs libpkcs11_ep11.$(SHLIBEXT) PKCS11_EP11.$(SHLIBEXT)
|
||||
$(MKDIR_P) $(DESTDIR)$(localstatedir)/lib/opencryptoki/ep11tok/TOK_OBJ
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/ep11tok/TOK_OBJ
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/ep11tok
|
||||
@@ -48,16 +53,21 @@
|
||||
$(CHMOD) 0770 $(DESTDIR)$(lockdir)/ep11tok
|
||||
test -f $(DESTDIR)$(sysconfdir)/opencryptoki || $(MKDIR_P) $(DESTDIR)$(sysconfdir)/opencryptoki || true
|
||||
test -f $(DESTDIR)$(sysconfdir)/opencryptoki/ep11tok.conf || $(INSTALL) -m 644 $(srcdir)/usr/lib/ep11_stdll/ep11tok.conf $(DESTDIR)$(sysconfdir)/opencryptoki/ep11tok.conf || true
|
||||
@@ -100,30 +88,24 @@
|
||||
@@ -117,34 +100,28 @@
|
||||
endif
|
||||
if ENABLE_P11SAK
|
||||
test -f $(DESTDIR)$(sysconfdir)/opencryptoki || $(MKDIR_P) $(DESTDIR)$(sysconfdir)/opencryptoki || true
|
||||
- test -f $(DESTDIR)$(sysconfdir)/opencryptoki/p11sak_defined_attrs.conf || $(INSTALL) -g $(pkcs_group) -m 0640 $(srcdir)/usr/sbin/p11sak/p11sak_defined_attrs.conf $(DESTDIR)$(sysconfdir)/opencryptoki/p11sak_defined_attrs.conf || true
|
||||
+ test -f $(DESTDIR)$(sysconfdir)/opencryptoki/p11sak_defined_attrs.conf || $(INSTALL) -m 0640 $(srcdir)/usr/sbin/p11sak/p11sak_defined_attrs.conf $(DESTDIR)$(sysconfdir)/opencryptoki/p11sak_defined_attrs.conf || true
|
||||
+ test -f $(DESTDIR)$(sysconfdir)/opencryptoki/p11sak_defined_attrs.conf || $(INSTALL) -m 0640 $(srcdir)/usr/sbin/p11sak/p11sak_defined_attrs.conf $(DESTDIR)$(sysconfdir)/opencryptoki/p11sak_defined_attrs.conf || true
|
||||
endif
|
||||
if ENABLE_P11KMIP
|
||||
test -f $(DESTDIR)$(sysconfdir)/opencryptoki || $(MKDIR_P) $(DESTDIR)$(sysconfdir)/opencryptoki || true
|
||||
- test -f $(DESTDIR)$(sysconfdir)/opencryptoki/p11kmip.conf || $(INSTALL) -g $(pkcs_group) -m 0640 $(srcdir)/usr/sbin/p11kmip/p11kmip.conf $(DESTDIR)$(sysconfdir)/opencryptoki/p11kmip.conf || true
|
||||
+ test -f $(DESTDIR)$(sysconfdir)/opencryptoki/p11kmip.conf || $(INSTALL) -m 0640 $(srcdir)/usr/sbin/p11kmip/p11kmip.conf $(DESTDIR)$(sysconfdir)/opencryptoki/p11kmip.conf || true
|
||||
endif
|
||||
if ENABLE_ICATOK
|
||||
cd $(DESTDIR)$(libdir)/opencryptoki/stdll && \
|
||||
ln -fs libpkcs11_ica.so PKCS11_ICA.so
|
||||
ln -fs libpkcs11_ica.$(SHLIBEXT) PKCS11_ICA.$(SHLIBEXT)
|
||||
$(MKDIR_P) $(DESTDIR)$(localstatedir)/lib/opencryptoki/lite/TOK_OBJ
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/lite/TOK_OBJ
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/lite
|
||||
@@ -69,7 +79,7 @@
|
||||
endif
|
||||
if ENABLE_SWTOK
|
||||
cd $(DESTDIR)$(libdir)/opencryptoki/stdll && \
|
||||
ln -fs libpkcs11_sw.so PKCS11_SW.so
|
||||
ln -fs libpkcs11_sw.$(SHLIBEXT) PKCS11_SW.$(SHLIBEXT)
|
||||
$(MKDIR_P) $(DESTDIR)$(localstatedir)/lib/opencryptoki/swtok/TOK_OBJ
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/swtok/TOK_OBJ
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/swtok
|
||||
@@ -80,9 +90,9 @@
|
||||
$(CHMOD) 0770 $(DESTDIR)$(lockdir)/swtok
|
||||
endif
|
||||
if ENABLE_TPMTOK
|
||||
@@ -131,10 +113,8 @@
|
||||
@@ -152,10 +129,8 @@
|
||||
cd $(DESTDIR)$(libdir)/opencryptoki/stdll && \
|
||||
ln -fs libpkcs11_tpm.so PKCS11_TPM.so
|
||||
ln -fs libpkcs11_tpm.$(SHLIBEXT) PKCS11_TPM.$(SHLIBEXT)
|
||||
$(MKDIR_P) $(DESTDIR)$(localstatedir)/lib/opencryptoki/tpm
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/tpm
|
||||
$(CHMOD) 0770 $(DESTDIR)$(localstatedir)/lib/opencryptoki/tpm
|
||||
@@ -91,9 +101,9 @@
|
||||
$(CHMOD) 0770 $(DESTDIR)$(lockdir)/tpm
|
||||
endif
|
||||
if ENABLE_ICSFTOK
|
||||
@@ -142,16 +122,14 @@
|
||||
@@ -163,16 +138,14 @@
|
||||
cd $(DESTDIR)$(libdir)/opencryptoki/stdll && \
|
||||
ln -fs libpkcs11_icsf.so PKCS11_ICSF.so
|
||||
ln -fs libpkcs11_icsf.$(SHLIBEXT) PKCS11_ICSF.$(SHLIBEXT)
|
||||
$(MKDIR_P) $(DESTDIR)$(localstatedir)/lib/opencryptoki/icsf
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(localstatedir)/lib/opencryptoki/icsf
|
||||
$(CHMOD) 0770 $(DESTDIR)$(localstatedir)/lib/opencryptoki/icsf
|
||||
@@ -107,11 +117,11 @@
|
||||
- test -f $(DESTDIR)$(sysconfdir)/opencryptoki/strength.conf || $(INSTALL) -m 640 -o root -g $(pkcs_group) -T $(srcdir)/doc/strength-example.conf $(DESTDIR)$(sysconfdir)/opencryptoki/strength.conf || true
|
||||
+ test -f $(DESTDIR)$(sysconfdir)/opencryptoki/strength.conf || $(INSTALL) -m 640 -o root -T $(srcdir)/doc/strength-example.conf $(DESTDIR)$(sysconfdir)/opencryptoki/strength.conf || true
|
||||
endif
|
||||
if !AIX
|
||||
$(MKDIR_P) $(DESTDIR)/etc/ld.so.conf.d
|
||||
echo "$(libdir)/opencryptoki" >\
|
||||
@@ -162,7 +140,6 @@
|
||||
@echo "Remember you must run ldconfig before using the above settings"
|
||||
@@ -185,7 +158,6 @@
|
||||
@echo "--------------------------------------------------------------"
|
||||
endif
|
||||
$(MKDIR_P) $(DESTDIR)$(lockdir) $(DESTDIR)$(logdir)
|
||||
- $(CHGRP) $(pkcs_group) $(DESTDIR)$(lockdir) $(DESTDIR)$(logdir)
|
||||
$(CHMOD) 0770 $(DESTDIR)$(lockdir) $(DESTDIR)$(logdir)
|
||||
BIN
openCryptoki-3.23.0.tar.gz
LFS
BIN
openCryptoki-3.23.0.tar.gz
LFS
Binary file not shown.
BIN
openCryptoki-3.26.0.tar.gz
LFS
Normal file
BIN
openCryptoki-3.26.0.tar.gz
LFS
Normal file
Binary file not shown.
113
openCryptoki-CVE-2026-22791-commit-e37e912.patch
Normal file
113
openCryptoki-CVE-2026-22791-commit-e37e912.patch
Normal file
@@ -0,0 +1,113 @@
|
||||
From e37e9127deeeb7bf3c3c4d852c594256c57ec3a8 Mon Sep 17 00:00:00 2001
|
||||
From: Ingo Franzki <ifranzki@linux.ibm.com>
|
||||
Date: Thu, 8 Jan 2026 10:48:29 +0100
|
||||
Subject: [PATCH] COMMON: Fix CKM_ECDH_AES_KEY_WRAP buffer size calculation
|
||||
with compressed keys
|
||||
|
||||
When a C_WrapKey with CKM_ECDH_AES_KEY_WRAP is performed, and the EC public
|
||||
key used with it uses a compressed EC point, then the size of the wrapped
|
||||
key material is calculated wrongly. This may lead to an out-of-bounds write
|
||||
when the caller provides a buffer of that calculated size.
|
||||
|
||||
The temporary EC key generated internally by this mechanism is always
|
||||
uses an uncompressed EC point, but the buffer size is erroneously calculated
|
||||
using the EC point of the supplied EC public key. Thus, in case a compressed
|
||||
EC point is supplied, the buffer size calculation results in a too short
|
||||
buffer.
|
||||
|
||||
Fix this by calculating the buffer size using the EC point of the internally
|
||||
generated EC key, because this is what is later on written to the buffer.
|
||||
|
||||
Fixes: 785d7577e1477d12fbe235554e7e7b24f2de34b7
|
||||
Reported-by: Pavel Kohout of Aisle Research, www.aisle.com
|
||||
Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com>
|
||||
---
|
||||
usr/lib/common/mech_ec.c | 54 ++++++++++++++++++++--------------------
|
||||
1 file changed, 27 insertions(+), 27 deletions(-)
|
||||
|
||||
diff --git a/usr/lib/common/mech_ec.c b/usr/lib/common/mech_ec.c
|
||||
index 2399c1cfb..ce031ec0c 100644
|
||||
--- a/usr/lib/common/mech_ec.c
|
||||
+++ b/usr/lib/common/mech_ec.c
|
||||
@@ -1758,6 +1758,31 @@ CK_RV ecdh_aes_key_wrap(STDLL_TokData_t *tokdata, SESSION *sess,
|
||||
goto done;
|
||||
}
|
||||
|
||||
+ /* Get the (raw) size of the generated EC point */
|
||||
+ rc = object_mgr_find_in_map1(tokdata, ec_publ_key_handle,
|
||||
+ &pub_key_obj, READ_LOCK);
|
||||
+ if (rc != CKR_OK) {
|
||||
+ TRACE_ERROR("Failed to acquire key from EC public key handle.\n");
|
||||
+ if (rc == CKR_OBJECT_HANDLE_INVALID)
|
||||
+ rc = CKR_KEY_HANDLE_INVALID;
|
||||
+ goto done;
|
||||
+ }
|
||||
+
|
||||
+ rc = template_attribute_get_non_empty(pub_key_obj->template, CKA_EC_POINT,
|
||||
+ &ec_point);
|
||||
+ if (rc != CKR_OK) {
|
||||
+ TRACE_DEVEL("Failed to get CKA_EC_POINT.\n");
|
||||
+ goto done;
|
||||
+ }
|
||||
+
|
||||
+ rc = ber_decode_OCTET_STRING((CK_BYTE *)ec_point->pValue,
|
||||
+ &pub_ec_point, &pub_ec_point_len, &field_len);
|
||||
+ if (rc != CKR_OK || field_len != ec_point->ulValueLen) {
|
||||
+ rc = CKR_FUNCTION_FAILED;
|
||||
+ TRACE_DEVEL("Failed to decode CKA_EC_POINT.\n");
|
||||
+ goto done;
|
||||
+ }
|
||||
+
|
||||
/* Perform ECDH to derive a shared AES key */
|
||||
ecdh_params.kdf = params->kdf;
|
||||
ecdh_params.pSharedData = params->pSharedData;
|
||||
@@ -1813,7 +1838,7 @@ CK_RV ecdh_aes_key_wrap(STDLL_TokData_t *tokdata, SESSION *sess,
|
||||
}
|
||||
|
||||
/* Calculate the final length of the wrapped key data */
|
||||
- total_len = ecdh_params.ulPublicDataLen + wrapped_key_len;
|
||||
+ total_len = pub_ec_point_len + wrapped_key_len;
|
||||
|
||||
if (length_only) {
|
||||
*out_data_len = total_len;
|
||||
@@ -1831,31 +1856,6 @@ CK_RV ecdh_aes_key_wrap(STDLL_TokData_t *tokdata, SESSION *sess,
|
||||
* Copy the (raw) EC point of the public transport EC key as first part of
|
||||
* the wrapped key data.
|
||||
*/
|
||||
- rc = object_mgr_find_in_map1(tokdata, ec_publ_key_handle,
|
||||
- &pub_key_obj, READ_LOCK);
|
||||
- if (rc != CKR_OK) {
|
||||
- TRACE_ERROR("Failed to acquire key from EC public key handle.\n");
|
||||
- if (rc == CKR_OBJECT_HANDLE_INVALID)
|
||||
- return CKR_KEY_HANDLE_INVALID;
|
||||
- else
|
||||
- return rc;
|
||||
- }
|
||||
-
|
||||
- rc = template_attribute_get_non_empty(pub_key_obj->template, CKA_EC_POINT,
|
||||
- &ec_point);
|
||||
- if (rc != CKR_OK) {
|
||||
- TRACE_DEVEL("Failed to get CKA_EC_POINT.\n");
|
||||
- goto done;
|
||||
- }
|
||||
-
|
||||
- rc = ber_decode_OCTET_STRING((CK_BYTE *)ec_point->pValue,
|
||||
- &pub_ec_point, &pub_ec_point_len, &field_len);
|
||||
- if (rc != CKR_OK || field_len != ec_point->ulValueLen) {
|
||||
- rc = CKR_FUNCTION_FAILED;
|
||||
- TRACE_DEVEL("Failed to decode CKA_EC_POINT.\n");
|
||||
- goto done;
|
||||
- }
|
||||
-
|
||||
memcpy(out_data, pub_ec_point, pub_ec_point_len);
|
||||
|
||||
/*
|
||||
@@ -1864,7 +1864,7 @@ CK_RV ecdh_aes_key_wrap(STDLL_TokData_t *tokdata, SESSION *sess,
|
||||
*/
|
||||
rc = encr_mgr_encrypt(tokdata, sess, FALSE, &aeskw_ctx,
|
||||
in_data, in_data_len,
|
||||
- out_data + ecdh_params.ulPublicDataLen,
|
||||
+ out_data + pub_ec_point_len,
|
||||
&wrapped_key_len);
|
||||
if (rc != CKR_OK) {
|
||||
TRACE_ERROR("Failed to encrypt the to-be-wrapped key: %s (0x%lx)\n",
|
||||
@@ -1,3 +1,144 @@
|
||||
-------------------------------------------------------------------
|
||||
Fri Jan 16 08:33:23 UTC 2026 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
- Applied a patch (bsc#1256673, CVE-2026-22791)
|
||||
* openCryptoki-CVE-2026-22791-commit-e37e912.patch
|
||||
- Modified the .spec file for Immutable Mode (jsc#PED-14798)
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Wed Nov 12 09:04:02 UTC 2025 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
- Upgrade openCryptoki to 3.26 (jsc#PED-14609)
|
||||
* Soft: Add support for RSA keys up to 16K bits.
|
||||
* CCA: Add support for RSA keys up to 8K bits (requires CCA v8.4 or v7.6 or later).
|
||||
* p11sak: Add support for generating RSA keys up to 16K bits.
|
||||
* Soft/ICA: Add support for SHA512/224 and SHA512/256 key derivation mechanism (CKM_SHA512_224_KEY_DERIVATION and CKM_SHA512_256_KEY_DERIVATION).
|
||||
* Soft/ICA/CCA/EP11: Add support for SHA-HMAC key types CKK_SHAxxx_HMAC and key gen mechanisms CKM_SHAxxx_KEY_GEN.
|
||||
* p11sak: Add support for SHA-HMAC key types and key generation.
|
||||
* p11sak: Add support for key wrap and unwrap commands to export and import private and secret keys by means of key wrapping/unwrapping
|
||||
with various key wrapping mechanism.
|
||||
* p11kmip: Add support for using an HSM-protected TLS client key via a PKCS#11 provider.
|
||||
* p11sak: Add support for exporting non-sensitive private keys to password protected PEM files.
|
||||
* Add support for canceling an operation via NULL mechanism pointer at C_XxxInit() call as an alternative to C_SessionCancel() (PKCS#11 v3.0).
|
||||
* EP11: Add support for pairing friendly BLS12-381 EC curve for sign/verify using CKM_IBM_ECDSA_OTHER and signature/public key aggregation using CKM_IBM_EC_AGGREGATE.
|
||||
* p11sak: Add support for generating BLS12-381 EC keys.
|
||||
* EP11: Add support for IBM-specific ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and
|
||||
a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16).
|
||||
* CCA: Add support for IBM-specific ML-DSA and ML-KEM key types and mechanisms (requires CCA v8.4 or later).
|
||||
* Soft: Add support for IBM-specific ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or the OQS-provider must be configured).
|
||||
* p11sak: Add support for IBM-specific ML-DSA and ML-KEM key types.
|
||||
* Bug fixes.
|
||||
- Removed obsolete patches
|
||||
* ocki-3.25-remove-make-install-chgrp.patch
|
||||
* ocki-3.25-PKCSSLOTD-Remove-the-use-of-MD5.patch
|
||||
- Applied a new patch for version 3.26
|
||||
* ocki-3.26-remove-make-install-chgrp.patch
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Thu Aug 14 04:56:04 UTC 2025 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
- Applied a patch (bsc#1248002)
|
||||
* ocki-3.25-PKCSSLOTD-Remove-the-use-of-MD5.patch
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Tue Jul 29 07:27:20 UTC 2025 - Andreas Schwab <schwab@suse.de>
|
||||
|
||||
- Add riscv64 to openCryptoki_64bit_arch
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Mon Jun 16 09:43:23 UTC 2025 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
- Upgrade openCryptoki to version 3.25 (jsc#PED-3361)
|
||||
* Updates/add supports
|
||||
- ICA/Soft: Add support for PKCS#11 v3.0 SHAKE key derivation
|
||||
- EP11: Add support for PKCS#11 v3.0 SHA3 and SHA3-HMAC mechanisms
|
||||
- EP11: Add support for PKCS#11 v3.0 SHA3 mechanisms and MGFs for RSA-OAEP
|
||||
- EP11: Add support for PKCS#11 v3.0 SHA3 variants of RSA-PKCS and ECDSA mechanisms
|
||||
- CCA: Add support for CCA AES CIPHER secure key types
|
||||
- CCA: Add support for the CKM_ECDH1_DERIVE mechanism
|
||||
- Soft/ICA: Add support for the CKM_AES_KEY_WRAP[_*] mechanisms
|
||||
- CCA/Soft/ICA: Add support for the CKM_RSA_AES_KEY_WRAP mechanism
|
||||
- Soft/ICA: Add support for the CKM_ECDH_AES_KEY_WRAP mechanism
|
||||
- ICA: Report mechanisms dependent on if libica is in FIPS mode
|
||||
- P11KMIP: Add a tool for import and exporting PKCS#11 keys to a KMIP server
|
||||
- EP11: Add support for opaque secure key blob import via C_CreateObject
|
||||
- Soft/ICA: Add support for key wrapping with AES-GCM
|
||||
- CCA: Add support for newer CCA versions on s390x and non-s390x platforms
|
||||
- CCA: Add support for CKM_AES_GCM (single-part operations only)
|
||||
* Amended the .spec file
|
||||
* Removed obsolete patches:
|
||||
- ocki-3.24-remove-group-from-tests.patch
|
||||
- ocki-3.24-remove-make-install-chgrp.patch
|
||||
* Applied a new patch for version 3.25
|
||||
- ocki-3.25-remove-make-install-chgrp.patch
|
||||
* Bug fixes
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Wed Dec 11 07:25:11 UTC 2024 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
- Moved pkcshsm_mk_change from openCryptoki-devel to openCryptoki
|
||||
(jsc#PED-10291, jsc#PED-10290)
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Tue Dec 10 07:08:59 UTC 2024 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
- Amended the .spec file (jsc#PED-10291, jsc#PED-10290)
|
||||
* Changed attributes - %attr(0640,root,%{pkcs_group}) - of files below:
|
||||
- %{_sysconfdir}/opencryptoki/strength.conf
|
||||
- %{_sysconfdir}/opencryptoki/p11sak_defined_attrs.conf
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Thu Nov 21 10:42:00 UTC 2024 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
- Amended the .spec file (jsc#PED-10291, jsc#PED-10290)
|
||||
- Improved handling of user/group. use existing user/group if they
|
||||
exist. create user/group if not (bsc#1225876)
|
||||
- Applied additional patch
|
||||
* ocki-3.24-remove-group-from-tests.patch
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Fri Oct 4 08:11:35 UTC 2024 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
- Amended the .spec file (jsc#PED-10241)
|
||||
- Updated the %configure flags for i586
|
||||
- Implemented a logic to exclude i586 arch
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Fri Sep 20 08:33:19 UTC 2024 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
- Upgrade openCryptoki to version 3.24
|
||||
(jsc#PED-10291, jsc#PED-10290, jsc#PED-10241)
|
||||
* Add support for building Opencryptoki on the IBM AIX platform
|
||||
* Add support for the CCA token on non-IBM Z platforms (x86_64, ppc64)
|
||||
* Add support for protecting tokens with a token specific user group
|
||||
* EP11: Add support for combined CKA_EXTRACTABLE and CKA_IBM_PROTKEY_EXTRACTABLE
|
||||
* CCA: Add support for Koblitz curve secp256k1. Requires CCA v7.2 or later
|
||||
* CCA: Add support for IBM Dilithium (CKM_IBM_DILITHIUM).
|
||||
- On Linux on IBM Z: Requires CCA v7.1 or later for Round2-65, and
|
||||
CCA v8.0 for the Round 3 variants.
|
||||
- On other platforms:
|
||||
Requires CCA v7.2.43 or later for Round2-65, the Round 3 variants are currently not supported
|
||||
* CCA: Add support for RSA-OAEP with SHA224, SHA384, and SHA512 on en-/decrypt.
|
||||
- Requires CCA v8.1 or later on Linux on IBM Z, not supported on other platforms
|
||||
* CCA: Add support for PKCS#11 v3.0 SHA3 mechanisms.
|
||||
- Requires CCA v8.1 on Linux on IBM Z, not supported on other platforms
|
||||
* ICA: Support new libica AES-GCM api using the KMA instruction on z14 and later
|
||||
* ICA/Soft/ICSF: Add support for PKCS#11 v3.0 SHA3 mechanisms
|
||||
* ICA/Soft: Add support for SHA based key derivation mechanisms
|
||||
* ICA/Soft: Add support for CKD_*_SP800 KDFs for ECDH
|
||||
* EP11/CCA/ICA/Soft: Add support for CKA_ALWAYS_AUTHENTICATE
|
||||
* EP11/CCA: Support live guest relocation for protected key (PKEY) operations
|
||||
* Soft: Experimental support for IBM Dilithium via OpenSSL OQS provider
|
||||
* ICSF: Add support for SHA-2 mechanisms
|
||||
* ICSF: Performance improvements for attribute retrieval
|
||||
* p11sak: Add support for exporting a key or certificate as URI-PEM file
|
||||
* p11sak: Import/export of IBM Dilithium keys in 'oqsprovider' format PEM files
|
||||
* p11sak: Add option to show the master key verification patterns of secure keys
|
||||
* Bug fixes
|
||||
- Amended the .spec file
|
||||
- Removed obsolete patch ocki-3.23-remove-make-install-chgrp.patchi
|
||||
- Added a new patch ocki-3.24-remove-make-install-chgrp.patch
|
||||
|
||||
-------------------------------------------------------------------
|
||||
Thu Jul 18 06:07:40 UTC 2024 - Nikolay Gueorguiev <nikolay.gueorguiev@suse.com>
|
||||
|
||||
@@ -1239,5 +1380,3 @@ Tue Feb 5 11:01:16 CET 2002 - froh@suse.de
|
||||
Wed Jan 30 16:20:48 CET 2002 - froh@suse.de
|
||||
|
||||
- initial version
|
||||
|
||||
-------------------------------------------------------------------
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
#
|
||||
# spec file for package openCryptoki
|
||||
#
|
||||
# Copyright (c) 2024 SUSE LLC
|
||||
# Copyright (c) 2026 SUSE LLC
|
||||
#
|
||||
# All modifications and additions to the file contributed by third parties
|
||||
# remain the property of their copyright owners, unless otherwise agreed
|
||||
@@ -19,7 +19,7 @@
|
||||
%define openCryptoki_32bit_arch %{ix86} s390 ppc %{arm}
|
||||
# support in the workings for: ppc64
|
||||
# no support in sight for: ia64
|
||||
%define openCryptoki_64bit_arch s390x ppc64 ppc64le x86_64 aarch64
|
||||
%define openCryptoki_64bit_arch s390x ppc64 ppc64le x86_64 aarch64 riscv64
|
||||
# autobuild:/work/cd/lib/misc/group
|
||||
# openCryptoki pkcs11:x:64:
|
||||
%define pkcs11_group_id 64
|
||||
@@ -27,7 +27,7 @@
|
||||
%define oc_cvs_tag opencryptoki
|
||||
|
||||
Name: openCryptoki
|
||||
Version: 3.23.0
|
||||
Version: 3.26.0
|
||||
Release: 0
|
||||
Summary: An Implementation of PKCS#11 (Cryptoki) v2.11 for IBM Cryptographic Hardware
|
||||
License: CPL-1.0
|
||||
@@ -39,8 +39,9 @@ Source2: openCryptoki-TFAQ.html
|
||||
Source3: openCryptoki-rpmlintrc
|
||||
# Patch 0 is needed because group pkcs11 doesn't exist in the build environment
|
||||
# and because we don't want(?) various file and directory permissions to be 0700.
|
||||
Patch000: ocki-3.23-remove-make-install-chgrp.patch
|
||||
Patch000: ocki-3.26-remove-make-install-chgrp.patch
|
||||
#
|
||||
Patch010: openCryptoki-CVE-2026-22791-commit-e37e912.patch
|
||||
#
|
||||
BuildRequires: bison
|
||||
BuildRequires: dos2unix
|
||||
@@ -51,7 +52,7 @@ BuildRequires: libitm1
|
||||
BuildRequires: libtool
|
||||
BuildRequires: libudev-devel
|
||||
BuildRequires: openldap2-devel
|
||||
BuildRequires: openssl-devel >= 1.0
|
||||
BuildRequires: openssl-devel >= 1.1.1
|
||||
BuildRequires: pkgconfig
|
||||
BuildRequires: trousers-devel
|
||||
BuildRequires: pkgconfig(systemd)
|
||||
@@ -67,25 +68,27 @@ Provides: group(pkcs11)
|
||||
ExclusiveArch: %{openCryptoki_32bit_arch} %{openCryptoki_64bit_arch}
|
||||
%{?systemd_requires}
|
||||
%ifarch s390 s390x
|
||||
BuildRequires: libica-devel
|
||||
BuildRequires: libica-devel >= 3.3
|
||||
BuildRequires: libica-tools
|
||||
%endif
|
||||
|
||||
%description
|
||||
The PKCS#11 version 2.11 API implemented for the IBM cryptographic
|
||||
cards. This package includes support for the IBM 4758 cryptographic
|
||||
coprocessor (with the PKCS#11 firmware loaded) and the IBM eServer
|
||||
Cryptographic Accelerator (FC 4960 on pSeries).
|
||||
Opencryptoki implements the PKCS#11 specification v2.20 for a set of
|
||||
cryptographic hardware, such as IBM 4764 and 4765 crypto cards, and the
|
||||
Trusted Platform Module (TPM) chip. Opencryptoki also brings a software
|
||||
token implementation that can be used without any cryptographic
|
||||
hardware.
|
||||
This package contains the Slot Daemon (pkcsslotd) and general utilities.
|
||||
|
||||
%package devel
|
||||
Summary: Development files for openCryptoki, a PKCS#11 implementation for IBM hardware
|
||||
Group: Development/Languages/C and C++
|
||||
Requires: glibc-devel
|
||||
Requires: libopenssl-devel
|
||||
Requires: libopenssl-devel >= 1.1.1
|
||||
Requires: openldap2-devel
|
||||
Requires: trousers-devel
|
||||
%ifarch s390 s390x
|
||||
Requires: libica-devel
|
||||
Requires: libica-devel >= 3.3
|
||||
%endif
|
||||
|
||||
%description devel
|
||||
@@ -93,6 +96,9 @@ The PKCS#11 version 2.01 API implemented for the IBM cryptographic
|
||||
cards. This package includes support for the IBM 4758 cryptographic
|
||||
co-processor (with the PKCS#11 firmware loaded) and the IBM eServer
|
||||
Cryptographic Accelerator (FC 4960 on pSeries).
|
||||
This package contains the development header files for building
|
||||
opencryptoki and PKCS#11 based applications
|
||||
|
||||
|
||||
%ifarch %{openCryptoki_32bit_arch}
|
||||
%package 32bit
|
||||
@@ -136,7 +142,7 @@ Cryptographic Accelerator (FC 4960 on pSeries).
|
||||
|
||||
%prep
|
||||
# setup -q -n %{oc_cvs_tag}-%{version}
|
||||
%autosetup -p 0 -n %{oc_cvs_tag}-%{version}
|
||||
%autosetup -p 1 -n %{oc_cvs_tag}-%{version}
|
||||
|
||||
cp %{SOURCE2} .
|
||||
|
||||
@@ -150,9 +156,13 @@ cp %{SOURCE2} .
|
||||
--enable-locks \
|
||||
%endif
|
||||
%ifarch s390 s390x
|
||||
--enable-pkcsep11_migrate
|
||||
--enable-icatok --enable-ccatok --enable-ep11tok --enable-pkcsep11_migrate
|
||||
%else
|
||||
--disable-ccatok
|
||||
%ifnarch i586
|
||||
--disable-icatok --enable-ccatok --disable-ep11tok --disable-pkcsep11_migrate --enable-pkcscca_migrate
|
||||
%else
|
||||
--disable-icatok --disable-ccatok --disable-ep11tok --disable-pkcsep11_migrate --disable-pkcscca_migrate
|
||||
%endif
|
||||
%endif
|
||||
|
||||
make %{?_smp_mflags}
|
||||
@@ -161,10 +171,25 @@ dos2unix doc/README.ep11_stdll
|
||||
%install
|
||||
%make_install
|
||||
install -d %{buildroot}%{_includedir}
|
||||
install -d %{buildroot}%{_localstatedir}/lib/opencryptoki
|
||||
# Move data templates from /var to /usr/share/opencryptoki for tmpfiles to use
|
||||
install -d %{buildroot}%{_datadir}/opencryptoki/templates
|
||||
install -d %{buildroot}%{_initddir}
|
||||
install -d %{buildroot}%{_sbindir}
|
||||
install -d %{buildroot}%{_prefix}/lib/tmpfiles.d
|
||||
# Define the tmpfiles.d configuration
|
||||
cat > %{buildroot}%{_prefix}/lib/tmpfiles.d/opencryptoki.conf <<EOF
|
||||
# Type Path Mode UID GID Age Argument
|
||||
d /var/lib/opencryptoki 0755 root pkcs11 - -
|
||||
d /var/lib/opencryptoki/swtok 0770 root pkcs11 - -
|
||||
d /var/lib/opencryptoki/swtok/TOK_OBJ 0770 root pkcs11 - -
|
||||
d /var/lib/opencryptoki/tpm 0770 root pkcs11 - -
|
||||
d /var/lib/opencryptoki/icsf 0770 root pkcs11 - -
|
||||
d /var/log/opencryptoki 0770 root pkcs11 - -
|
||||
L+ /etc/pkcs11 - - - - /var/lib/opencryptoki
|
||||
EOF
|
||||
# Remove manual directory creation in %install that belongs in /var
|
||||
rm -rf %{buildroot}%{_localstatedir}/lib/opencryptoki
|
||||
rm -rf %{buildroot}%{_localstatedir}/log/opencryptoki
|
||||
#
|
||||
mkdir -p %{buildroot}%{_datadir}/opencryptoki
|
||||
cp %{buildroot}%{_datadir}/doc/opencryptoki/*.conf %{buildroot}%{_datadir}/opencryptoki
|
||||
@@ -182,29 +207,20 @@ rm -f %{buildroot}%{_libdir}/opencryptoki/methods
|
||||
# openCryptoki pkcs11:x:64:
|
||||
# openCryptoki pkcsslotd:x:64:
|
||||
getent group %{pkcs_group} 2>/dev/null || %{_sbindir}/groupadd -g %{pkcs11_group_id} -r %{pkcs_group} 2>/dev/null || true
|
||||
getent passwd pkcsslotd 2>/dev/null || %{_sbindir}/useradd -g %{pkcs11_group_id} -r pkcsslotd -s /sbin/nologin -d /run/opencryptoki 2>/dev/null || true
|
||||
getent passwd pkcsslotd 2>/dev/null || %{_sbindir}/useradd -g %{pkcs_group} -r pkcsslotd -s /sbin/nologin -d /run/opencryptoki 2>/dev/null || true
|
||||
%{_sbindir}/usermod -a -G %{pkcs_group} root
|
||||
|
||||
%preun
|
||||
%{service_del_preun pkcsslotd.service}
|
||||
|
||||
%post
|
||||
# Symlink from /var/lib/opencryptoki to /etc/pkcs11
|
||||
if [ ! -L %{_sysconfdir}/pkcs11 ] ; then
|
||||
if [ -e %{_sysconfdir}/pkcs11/pk_config_data ] ; then
|
||||
mv %{_sysconfdir}/pkcs11/* %{_localstatedir}/lib/opencryptoki
|
||||
cd %{_sysconfdir} && rm -rf pkcs11 && \
|
||||
ln -sf %{_localstatedir}/lib/opencryptoki pkcs11
|
||||
fi
|
||||
fi
|
||||
# Use the systemd-tmpfiles macro to ensure directories are created on next boot/transaction
|
||||
%tmpfiles_create %{_tmpfilesdir}/opencryptoki.conf
|
||||
/sbin/ldconfig
|
||||
%{?tmpfiles_create:%tmpfiles_create %{_tmpfilesdir}/opencryptoki.conf}
|
||||
%{service_add_post pkcsslotd.service}
|
||||
|
||||
%postun
|
||||
if [ -L %{_sysconfdir}/pkcs11 ] ; then
|
||||
rm %{_sysconfdir}/pkcs11
|
||||
fi
|
||||
/sbin/ldconfig
|
||||
%{service_del_postun pkcsslotd.service}
|
||||
|
||||
%ifarch %{openCryptoki_32bit_arch}
|
||||
@@ -213,6 +229,7 @@ if [ -L %{_sysconfdir}/pkcs11 ] ; then
|
||||
rm %{_sysconfdir}/pkcs11
|
||||
fi
|
||||
%{service_del_postun pkcsslotd.service}
|
||||
/sbin/ldconfig
|
||||
|
||||
%post 32bit
|
||||
# Old library name links
|
||||
@@ -244,19 +261,20 @@ ln -sf %{_libdir}/opencryptoki/libopencryptoki.so %{_prefix}/lib/pkcs11/PKCS11_A
|
||||
%dir %{_datadir}/doc/opencryptoki
|
||||
%doc %{_datadir}/doc/opencryptoki/policy-example.conf
|
||||
%doc %{_datadir}/doc/opencryptoki/strength-example.conf
|
||||
%doc %{_datadir}/doc/opencryptoki/README.token_data
|
||||
%doc %{_datadir}/doc/opencryptoki/opencryptoki-howto.md
|
||||
%dir %{_datadir}/opencryptoki
|
||||
%{_datadir}/opencryptoki/policy-example.conf
|
||||
%{_datadir}/opencryptoki/strength-example.conf
|
||||
# configuration directory
|
||||
%dir %{_sysconfdir}/opencryptoki
|
||||
%config %{_sysconfdir}/opencryptoki/opencryptoki.conf
|
||||
%config %attr(640,root,%{pkcs_group}) %{_sysconfdir}/opencryptoki/strength.conf
|
||||
%config %attr(640,root,%{pkcs_group}) %{_sysconfdir}/opencryptoki/p11sak_defined_attrs.conf
|
||||
%config %{_sysconfdir}/opencryptoki/p11kmip.conf
|
||||
%attr(0640,root,%{pkcs_group}) %config %{_sysconfdir}/opencryptoki/strength.conf
|
||||
%attr(0640,root,%{pkcs_group}) %config %{_sysconfdir}/opencryptoki/p11sak_defined_attrs.conf
|
||||
%ifarch s390 s390x
|
||||
%config %{_sysconfdir}/opencryptoki/ccatok.conf
|
||||
%config %{_sysconfdir}/opencryptoki/ep11cpfilter.conf
|
||||
%config %{_sysconfdir}/opencryptoki/ep11tok.conf
|
||||
%{_sbindir}/pkcsep11_migrate
|
||||
%endif
|
||||
%{_sbindir}/p11sak
|
||||
%{_unitdir}/pkcsslotd.service
|
||||
@@ -264,42 +282,35 @@ ln -sf %{_libdir}/opencryptoki/libopencryptoki.so %{_prefix}/lib/pkcs11/PKCS11_A
|
||||
%{_sbindir}/rcpkcsslotd
|
||||
# utilities
|
||||
%ifarch s390 s390x
|
||||
%{_sbindir}/pkcsep11_migrate
|
||||
%{_sbindir}/pkcsep11_session
|
||||
%endif
|
||||
%ifnarch i586
|
||||
%config %{_sysconfdir}/opencryptoki/ccatok.conf
|
||||
%{_sbindir}/pkcscca
|
||||
%endif
|
||||
%{_sbindir}/p11kmip
|
||||
%{_sbindir}/pkcsslotd
|
||||
%{_sbindir}/pkcsconf
|
||||
%{_sbindir}/pkcsicsf
|
||||
%{_sbindir}/pkcsstats
|
||||
%{_sbindir}/pkcstok_migrate
|
||||
%{_sbindir}/pkcstok_admin
|
||||
%dir %{_libdir}/opencryptoki
|
||||
%dir %{_libdir}/opencryptoki/stdll
|
||||
# State and lock directories
|
||||
%dir %attr(755,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki
|
||||
%ifarch s390 s390x
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/ccatok
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/ccatok/TOK_OBJ
|
||||
%endif
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/swtok
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/swtok/TOK_OBJ
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/tpm
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/icsf
|
||||
%ifarch s390 s390x
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/ep11tok
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/ep11tok/TOK_OBJ
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/lite
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki/lite/TOK_OBJ
|
||||
%endif
|
||||
%dir %attr(770,root,%{pkcs_group}) %{_localstatedir}/log/opencryptoki/
|
||||
%{_mandir}/man*/*
|
||||
%{_sbindir}/pkcshsm_mk_change
|
||||
#
|
||||
%{_prefix}/lib/tmpfiles.d/opencryptoki.conf
|
||||
# Ensure we don't package files in /var directly
|
||||
%ghost %dir %attr(755,root,%{pkcs_group}) %{_localstatedir}/lib/opencryptoki
|
||||
|
||||
%files devel
|
||||
%dir %{_libdir}/opencryptoki
|
||||
%dir %{_libdir}/opencryptoki/stdll
|
||||
%{_includedir}/opencryptoki
|
||||
%{_libdir}/pkgconfig/opencryptoki.pc
|
||||
###
|
||||
%{_sbindir}/pkcshsm_mk_change
|
||||
|
||||
%ifarch %{openCryptoki_32bit_arch}
|
||||
%files 32bit
|
||||
@@ -312,6 +323,10 @@ ln -sf %{_libdir}/opencryptoki/libopencryptoki.so %{_prefix}/lib/pkcs11/PKCS11_A
|
||||
%{_libdir}/opencryptoki/stdll/libpkcs11_cca.so
|
||||
%ghost %{_libdir}/opencryptoki/stdll/PKCS11_CCA.so
|
||||
%endif
|
||||
%ifnarch i586
|
||||
%{_libdir}/opencryptoki/stdll/libpkcs11_cca.so
|
||||
%endif
|
||||
%ghost %{_libdir}/opencryptoki/stdll/PKCS11_CCA.so
|
||||
%{_libdir}/opencryptoki/stdll/libpkcs11_tpm.so
|
||||
%ghost %{_libdir}/opencryptoki/stdll/PKCS11_TPM.so
|
||||
%{_libdir}/opencryptoki/stdll/libpkcs11_sw.so
|
||||
|
||||
Reference in New Issue
Block a user