1
0
Commit Graph

51 Commits

Author SHA256 Message Date
Ana Guerrero
65eef2ffc3 Accepting request 1200675 from security
OBS-URL: https://build.opensuse.org/request/show/1200675
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=23
2024-09-13 12:33:41 +00:00
Wolfgang Frisch
46cbc7f57c - update to 2.6.1:
* cmd: Fix performing bio verification
  * ykcs11: Fix handling ED25519 and X25519 keys

OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=49
2024-09-12 14:58:39 +00:00
Ana Guerrero
cc0238cb8e Accepting request 1196034 from security
OBS-URL: https://build.opensuse.org/request/show/1196034
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=22
2024-08-26 20:10:49 +00:00
Torsten Gruner
c947cc7c2b - update to 2.6.0:
* cmd: Add support for biometric verification and match policy
  * ykcs11: Add support for PKCS11 3.0
  * ykpiv: cmd: ykcs11: Improve error traceability
  * ykpiv: cmd: ykcs11: Fix minor bugs
  * build: Make building with zlib optional

OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=47
2024-08-26 08:50:42 +00:00
Dominique Leuenberger
30ed852650 Accepting request 1173398 from security
OBS-URL: https://build.opensuse.org/request/show/1173398
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=21
2024-05-11 16:23:42 +00:00
Torsten Gruner
9fe14be8a5 Accepting request 1172684 from home:wfrisch:branches:security
- update to 2.5.2:
  * cmd: Fix signing selfsigned certificate for ED25519 key.
- update cmake-flags-upstream-issue-474.patch

OBS-URL: https://build.opensuse.org/request/show/1172684
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=45
2024-05-11 07:20:15 +00:00
Ana Guerrero
32d6a44269 Accepting request 1146792 from security
OBS-URL: https://build.opensuse.org/request/show/1146792
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=20
2024-02-15 20:01:21 +00:00
Torsten Gruner
84f5c9d586 Accepting request 1146768 from home:wfrisch:branches:security
- update to 2.5.1:
  * ykpiv: cmd: ykcs11: Fix buffer size for key import.
- add cmake-flags-upstream-issue-474.patch: 
  proper fix for the cmake flags issue
- remove temporary-cmake-flags-fix.patch

OBS-URL: https://build.opensuse.org/request/show/1146768
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=43
2024-02-15 11:02:54 +00:00
Ana Guerrero
a2502cb563 Accepting request 1145505 from security
OBS-URL: https://build.opensuse.org/request/show/1145505
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=19
2024-02-09 22:54:49 +00:00
Torsten Gruner
546257bdfe Accepting request 1145140 from home:wfrisch:branches:security
- update to 2.5.0:
  * ykpiv: cmd: ykcs11: Add support for RSA3072 and RSA4096 key types.
    Available in firmware 5.7.0 and newer
  * ykpiv: cmd: Add support for ED25519 and X25519 key types.
    Available in firmware 5.7.0 and newer
  * ykpiv: cmd: Add support for deleting keys.
    Available in firmware 5.7.0 and newer
  * ykpiv: cmd: Add support for moving keys between slots.
    Available in firmware 5.7.0 and newer
- add temporary-cmake-flags-fix.patch
  The included cmake modules are buggy. This patch should be removed once the
  root cause is fixed in upstream.

OBS-URL: https://build.opensuse.org/request/show/1145140
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=41
2024-02-09 17:58:54 +00:00
Ana Guerrero
b013667efd Accepting request 1134036 from security
OBS-URL: https://build.opensuse.org/request/show/1134036
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=18
2023-12-19 22:16:47 +00:00
Torsten Gruner
e10cdff67a Accepting request 1133745 from home:dirkmueller:Factory
- update to 2.4.2:
  * ykpiv: Fix potential type casting bug.
  * ykpiv: ykcs11: Fix building on certain architectures.
  * ykpiv: cmd: Add support for compressing certificate upon
    import
  * ykcs11: Increase maximum number of slots to handle
    overflow
  * ykcs11: Add support for CKA_COPYABLE and CKA_DESTROYABLE
    attributes

  * tests: Improved tests
  - Add attest action When used on a slot with a generated key,
  - Properly handle DER encoding in ECDSA signatures.
  - Add ykcs11.
  - Use PCSC transactions when sending and receiving data
  COPYING files says package is under GPL-3.0+.
    Revert the check for parity and just set parity before the weak check.

OBS-URL: https://build.opensuse.org/request/show/1133745
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=39
2023-12-19 13:29:39 +00:00
Dominique Leuenberger
a30995f340 Accepting request 1069381 from security
OBS-URL: https://build.opensuse.org/request/show/1069381
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=17
2023-03-04 21:43:41 +00:00
Torsten Gruner
1f9e952201 Accepting request 1069319 from home:dirkmueller:Factory
- update to 2.3.1:
  * ykpiv: Add support for T=0 smartcards
  * ykpiv: ykcs11: Minor code optimization
  * ykpiv: ykcs11: Improve logging
  * ykpiv: ykcs11: Improve error handling
  * ykpiv: ykcs11: Fix minor bugs
  * ykcs11: Add support for several PKCS11 Attributes
  * ykcs11: Add support for CKM_ECDSA_SHA512 mechanism
  * ykcs11: Fix incorrect value for public key attributes
    CKA_PRIVATE, CKA_SENSITIVE, CKA_ALWAYS_SENSITIVE,
    CKA_EXTRACTABLE and CKA_NEVER_EXTRACTABLE
  * doc: Minor documentation improvement

OBS-URL: https://build.opensuse.org/request/show/1069319
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=37
2023-03-04 06:30:21 +00:00
Dominique Leuenberger
edfcee736a Accepting request 1040035 from security
OBS-URL: https://build.opensuse.org/request/show/1040035
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=16
2022-12-06 13:23:04 +00:00
Torsten Gruner
3984b88bd9 Accepting request 1039843 from home:dirkmueller:Factory
- update to 2.3.0:
  * ykpiv: Add support for AES management keys
  * ykpiv: Better handling of connection reset
  * ykpiv: Add support for T=0 protocol
  * ykcs11: Support YubiKeys in NFC readers
  * ykcs11: Support touch and PIN policies for imported private keys
  * ykcs11: Support touch and PIN policy when generating keys
  * ykcs11: Set length to -1 on function fail
  * ykcs11: Ignore CKA_NAME_HASH_ALGORITHM and CKA_HASH_OF_SUBJECT_PUBLIC_KEY for certificates
  * cmd: Support attestation in selfsign certificates
  * build: Compile cleanly with openssl 1.1 and 3
- add keyring

OBS-URL: https://build.opensuse.org/request/show/1039843
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=35
2022-12-04 19:43:38 +00:00
Dominique Leuenberger
b22c45d766 Accepting request 950455 from security
OBS-URL: https://build.opensuse.org/request/show/950455
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=15
2022-02-01 15:59:52 +00:00
Torsten Gruner
9034b3b730 Accepting request 950309 from home:dirkmueller:Factory
- update to 2.2.1:
  * ykpiv: Minor bug fixes
  * ykcs11: Improved handling of object attributes
  * ykcs11: Update flags for EC related mechanisms
  * ykcs11: Minor bug fixes
  * test: Improved testing
  * doc: Improved documentation

OBS-URL: https://build.opensuse.org/request/show/950309
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=34
2022-02-01 14:37:49 +00:00
Richard Brown
e3c29e620d Accepting request 876131 from security
OBS-URL: https://build.opensuse.org/request/show/876131
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=14
2021-03-02 11:36:18 +00:00
Torsten Gruner
504faa7337 Accepting request 875814 from home:dirkmueller:Factory
- update to 2.2.0:
  * ykpiv: Increased SO version
  * ykpiv: Fixed minor memory leaks
  * ykpiv: Improved error handling
  * ykpiv: Improved handling of PCSC card validation
  * ykcs11: Updated Cryptoki version
  * ykcs11: Support for CKM_ECDH1_DERIVE mechanism info
  * ykcs11: Support for destroying ECDH derived keys
  * ykcs11: Improved handling of PIN after device re-connection
  * ykcs11: Improved debug logging
  * cmd: Improved parsing of certificate Distinguished Name to allow an escape character
  * cmd: Warning to discourage generating RSA1024 keys
  * build: Use of platform standard installation path when building yubico-piv-tool
  * tests: Improved testing
  * Replaced building with autotool with building with cmake
  * Security update for YSA-2020-02
  * ykpiv: Fixed potential memory leaks
  * ykpiv: Use PIN-protected MGMT key if the device is configured that way
  * ykpiv: Added attestation to CSR if requested
  * ykpiv: Fixed compatibility with LibreSSL
  * ykcs11: Improved handling of error codes
  * ykcs11: Improved handling of examples in the PKCS11 specifications
  * ykcs11: Added the possibility to have debug output as a runtime setting
  * ykcs11: Added support to unblock PIN with PUK
  * ykcs11: Make C_SetPIN backwards compatible while also allowing unblock PIN
  * tests: Improved tests 
- run tests
- add pthread-link.patch

OBS-URL: https://build.opensuse.org/request/show/875814
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=32
2021-03-02 06:16:17 +00:00
Dominique Leuenberger
9f0aac7d0b Accepting request 782604 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/782604
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=13
2020-03-08 21:24:19 +00:00
94d65bd980 - Version 2.0.0
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=30
2020-03-01 00:15:48 +00:00
Dominique Leuenberger
7aed3b8719 Accepting request 707080 from security
OBS-URL: https://build.opensuse.org/request/show/707080
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=12
2019-06-03 16:56:47 +00:00
Karol Babioch
7b7db64f0a Accepting request 707077 from home:kbabioch:branches:security
- Version 1.7.0 (released 2019-04-03)
  * Add ykpiv_get_serial() to API.
  * Add version and serial to status output.
  * FASC-N fixes for CHUID.
  * ykcs11: Fix ECDSA signatures.
  * Make selfsigned X.509 extensions have correct extensions to match openssl.
  * Security fixes.
  * Documentation fixes.
  * Try to clear memory that might contain secrets.

OBS-URL: https://build.opensuse.org/request/show/707077
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=28
2019-06-03 08:34:04 +00:00
Dominique Leuenberger
48b24bfa0b Accepting request 638988 from security
OBS-URL: https://build.opensuse.org/request/show/638988
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=11
2018-10-01 07:07:57 +00:00
Karol Babioch
9ded637636 Accepting request 638984 from home:jengelh:branches:security
- Rename %soname to %sover to better reflect its use.
- Fix RPM groups.

OBS-URL: https://build.opensuse.org/request/show/638984
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=26
2018-09-28 09:27:16 +00:00
Torsten Gruner
681f0e6f32 Accepting request 638743 from home:kbabioch:branches:security
- Version 1.6.2 (released 2018-09-14)
  - Compare reader names case insensitive
  - Fix certificate and certificate request signatures with OpenSSL 1.1

OBS-URL: https://build.opensuse.org/request/show/638743
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=25
2018-09-27 18:11:29 +00:00
Dominique Leuenberger
64ab095060 Accepting request 631989 from security
OBS-URL: https://build.opensuse.org/request/show/631989
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=10
2018-08-29 10:26:49 +00:00
Torsten Gruner
48f05ee31e Accepting request 631937 from home:kbabioch:branches:security
- Version 1.6.1 (released 2018-08-17)
  - Compilation warning fixes for OpenSSL 1.1 builds
  - Fix length when encoding exactly 0xff bytes
  - Check length of objects correctly before storing in buffer
  - Check length of certificate correctly when storing
- Version 1.6.0 (released 2018-08-08)
  - Security release to mitigate YSA-2018-03 (YSA-2018-03, CVE-2018-14779,
    CVE-2018-14780, bsc#1104809, bsc#1104811)
  - Allow building against LibreSSL
  - Bugfixes in OpenSSL 1.1 code
  - Fix compilation warnings
  - Fix ykcs11 key generation to work with OpenSSL 1.1
  - Ykcs11 compatibility fixes
- Make use of %license macro instead of %doc for COPYING
- Applied spec-cleaner

OBS-URL: https://build.opensuse.org/request/show/631937
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=23
2018-08-28 13:31:16 +00:00
Dominique Leuenberger
a9b252fc15 Accepting request 547083 from security
OBS-URL: https://build.opensuse.org/request/show/547083
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=9
2017-12-04 09:01:51 +00:00
Torsten Gruner
bd68da49a4 Accepting request 547082 from home:Simmphonie:yubico
- Version 1.5.0 (released 2017-11-29)
  - API additions: Higher-level "util" API added to libykpiv.
  - Added ykpiv_attest(), ykpiv_get_pin_retries(), ykpiv_set_pin_retries()
  - Added functions for using existing PCSC card handle.
  - Support using custom memory allocator.
  - Documentation updates. make doxygen for HTML format.
  - Expanded automated tests for hardware devices, moved to make hwcheck.
  - OpenSSL 1.1 support
  - Moderate internal refactoring. Many small bugs fixed.

OBS-URL: https://build.opensuse.org/request/show/547082
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=21
2017-12-01 11:46:22 +00:00
Torsten Gruner
71f214a0a3 Accepting request 544051 from home:Simmphonie:yubico
- Version 1.4.4 (released 2017-10-17)
  - Documentation updates.
  - Add pin caching to work around disconnect problems.
  - Disable RSA key generation on YubiKey 4 before 4.3.5. See https://yubi.co/ysa201701/ for details.
- Version 1.4.3 (released 2017-04-18)
  - Encode RSA x509 certificates correctly.
  - Documentation updates.
  - In ykcs11 return CKA_MODULUS correctly for private keys.
  - In ykcs11 fix for signature size approximation.
  - Fix PSS signatures in ykcs11.
  - Add a CLI flag --stdin-input to make batch execution easier.

OBS-URL: https://build.opensuse.org/request/show/544051
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=20
2017-11-22 06:12:40 +00:00
Dominique Leuenberger
df7d912579 Accepting request 419766 from security
1

OBS-URL: https://build.opensuse.org/request/show/419766
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=8
2016-08-18 07:18:11 +00:00
Torsten Gruner
9c2c224a8b Accepting request 419765 from home:Simmphonie:yubico
OBS-URL: https://build.opensuse.org/request/show/419765
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=18
2016-08-17 14:32:51 +00:00
Dominique Leuenberger
7228a8434a Accepting request 396832 from security
1

OBS-URL: https://build.opensuse.org/request/show/396832
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=7
2016-06-02 07:36:38 +00:00
Torsten Gruner
ad448a65a9 Accepting request 396529 from home:Simmphonie:yubico
OBS-URL: https://build.opensuse.org/request/show/396529
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=16
2016-05-19 14:02:44 +00:00
Dominique Leuenberger
6a174a5522 Accepting request 391590 from security
1

OBS-URL: https://build.opensuse.org/request/show/391590
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=6
2016-04-28 14:56:57 +00:00
Torsten Gruner
07899c8247 Accepting request 391588 from home:Simmphonie:yubico
OBS-URL: https://build.opensuse.org/request/show/391588
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=14
2016-04-25 20:56:22 +00:00
Dominique Leuenberger
7402220465 Accepting request 346240 from security
1

OBS-URL: https://build.opensuse.org/request/show/346240
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=5
2015-11-26 16:04:30 +00:00
Torsten Gruner
e3725b2fc8 Accepting request 346228 from home:Simmphonie:yubico
OBS-URL: https://build.opensuse.org/request/show/346228
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=12
2015-11-25 14:59:29 +00:00
Dominique Leuenberger
3c818089f7 Accepting request 344190 from security
1

OBS-URL: https://build.opensuse.org/request/show/344190
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=4
2015-11-16 17:51:21 +00:00
Torsten Gruner
3b3c19257f Accepting request 344186 from home:Simmphonie:yubico
OBS-URL: https://build.opensuse.org/request/show/344186
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=10
2015-11-13 10:39:28 +00:00
Dominique Leuenberger
cd9960d832 Accepting request 343396 from security
1

OBS-URL: https://build.opensuse.org/request/show/343396
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=3
2015-11-11 09:31:54 +00:00
Torsten Gruner
3b41472d1b Accepting request 343393 from home:Simmphonie:yubico
OBS-URL: https://build.opensuse.org/request/show/343393
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=8
2015-11-10 11:54:48 +00:00
Stephan Kulow
3c7e4ad425 Accepting request 335877 from security
1

OBS-URL: https://build.opensuse.org/request/show/335877
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=2
2015-10-08 06:24:18 +00:00
Torsten Gruner
db7a4c251b Accepting request 335876 from home:Simmphonie:yubico
OBS-URL: https://build.opensuse.org/request/show/335876
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=6
2015-10-02 09:42:06 +00:00
Stephan Kulow
e040d39612 Accepting request 304392 from security
add yubikey stuff to factory

OBS-URL: https://build.opensuse.org/request/show/304392
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/yubico-piv-tool?expand=0&rev=1
2015-05-15 05:42:46 +00:00
Torsten Gruner
7bb27b690e Accepting request 304205 from home:dec16180:ldig:branches:security
license update: GPL-3.0+
COPYING files says package is under GPL-3.0+.

OBS-URL: https://build.opensuse.org/request/show/304205
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=4
2015-04-28 07:31:20 +00:00
fc58cbac90 Accepting request 293264 from home:Simmphonie:yubico
OBS-URL: https://build.opensuse.org/request/show/293264
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=3
2015-03-29 10:44:25 +00:00
900325875e Accepting request 286372 from home:Simmphonie:yubico
OBS-URL: https://build.opensuse.org/request/show/286372
OBS-URL: https://build.opensuse.org/package/show/security/yubico-piv-tool?expand=0&rev=2
2015-02-20 15:35:12 +00:00