Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

opencryptoki-icatok-3.25.0-4.fc43 RPM for s390x

From Fedora Rawhide for s390x / o

Name: opencryptoki-icatok Distribution: Fedora Project
Version: 3.25.0 Vendor: Fedora Project
Release: 4.fc43 Build date: Tue Jul 29 16:21:57 2025
Group: Unspecified Build host: buildvm-s390x-19.s390.fedoraproject.org
Size: 710433 Source RPM: opencryptoki-3.25.0-4.fc43.src.rpm
Packager: Fedora Project
Url: https://github.com/opencryptoki/opencryptoki
Summary: ICA cryptographic devices (clear-key) support for opencryptoki
Opencryptoki implements the PKCS#11 specification  v3.0 and partially v3.1
for a set of cryptographic hardware, such as IBM 4767, 4768, 4769 and 4770
crypto cards, and the Trusted Platform Module (TPM) chip. Opencryptoki also
brings a software token implementation that can be used without any cryptographic
hardware.
This package brings the necessary libraries and files to support ICA
devices in the opencryptoki stack. ICA is an interface to IBM
cryptographic hardware such as IBM 4767, 4768, 4769 and 4770 that uses the
"accelerator" or "clear-key" path.

Provides

Requires

License

CPL-1.0

Changelog

* Tue Jul 29 2025 Than Ngo <than@redhat.com> - 3.25.0-4
  - Require openssl >= 3.5.1
  - Fix incorrect effective group id of pkcsslotd daemon
  - Fix covscan findings
  - Fix detection of EC curve not supported by OpenSSL-3.5.x
  - Fix the image mode issue again as bootc expects to use /run/lock
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 3.25.0-3
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue Jun 10 2025 Than Ngo <than@redhat.com> - 3.25.0-2
  - Enable testsuite
* Tue Jun 10 2025 Than Ngo <than@redhat.com> - 3.25.0-1
  - Update to 3.25.0
  - Drop patches which are included in upstream
  - Adapt p11sak patch
  - Fix RPM build warnings
  - Add jq and openssl in Build Requirement, required for testcases
* Tue Apr 29 2025 Than Ngo <than@redhat.com> - 3.24.0-9
  - Fix, opencryptoki doesn't work in image mode
* Wed Mar 12 2025 Than Ngo <than@redhat.com> - 3.24.0-8
  - Fix rpminspect issue
* Thu Feb 27 2025 Than Ngo <than@redhat.com> - 3.24.0-7
  - Fix, opencryptoki tokens are deleted on reboot
* Tue Feb 11 2025 Than Ngo <than@redhat.com> - 3.24.0-6
  - Remove call to
* Tue Feb 04 2025 Than Ngo <than@redhat.com> - 3.24.0-5
  - Use tmpfiles to change file ownership for image mode
* Tue Feb 04 2025 Than Ngo <than@redhat.com> - 3.24.0-4
  - Fix opencryptoki for image mode
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 3.24.0-3
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Sep 13 2024 Than Ngo <than@redhat.com> - 3.24.0-2
  - build with --enable-pkcscca_migrate
  - fix build error due to incompatible pointer types
* Fri Sep 13 2024 Than Ngo <than@redhat.com> - 3.24.0-1
  - Update to 3.24.0
    * Add support for building Opencryptoki on the IBM AIX platform
    * Add support for the CCA token on non-IBM Z platforms (x86_64, ppc64)
    * Add support for protecting tokens with a token specific user group
    * EP11: Add support for combined CKA_EXTRACTABLE and CKA_IBM_PROTKEY_EXTRACTABLE
    * CCA: Add support for Koblitz curve secp256k1. Requires CCA v7.2 or later
    * CCA: Add support for IBM Dilithium (CKM_IBM_DILITHIUM).
      On Linux on IBM Z: Requires CCA v7.1 or later for Round2-65, and CCA v8.0 for the Round 3 variants.
      On other platforms: Requires CCA v7.2.43 or later for Round2-65, the Round 3 variants are currently not supported
    * CCA: Add support for RSA-OAEP with SHA224, SHA384, and SHA512 on en-/decrypt. Requires CCA v8.1 or later on Linux on IBM Z, not supported on other platforms
    * CCA: Add support for PKCS#11 v3.0 SHA3 mechanisms. Requires CCA v8.1 on Linux on IBM Z, not supported on other platforms
    * ICA: Support new libica AES-GCM api using the KMA instruction on z14 and later
    * ICA/Soft/ICSF: Add support for PKCS#11 v3.0 SHA3 mechanisms
    * ICA/Soft: Add support for SHA based key derivation mechanisms
    * ICA/Soft: Add support for CKD_*_SP800 KDFs for ECDH
    * EP11/CCA/ICA/Soft: Add support for CKA_ALWAYS_AUTHENTICATE
    * EP11/CCA: Support live guest relocation for protected key (PKEY) operations
    * Soft: Experimental support for IBM Dilithium via OpenSSL OQS provider
    * ICSF: Add support for SHA-2 mechanisms
    * ICSF: Performance improvements for attribute retrieval
    * p11sak: Add support for exporting a key or certificate as URI-PEM file
    * p11sak: Import/export of IBM Dilithium keys in 'oqsprovider' format PEM files
    * p11sak: Add option to show the master key verification patterns of secure keys
    * Bug fixes
  - Remove i686 support as upsrtream will get rid of 32-bit support, https://github.com/opencryptoki/opencryptoki/issues/174
  - Remove lockdir.patch
* Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.23.0-2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Wed Feb 07 2024 Than Ngo <than@redhat.com> - 3.23.0-1
  - 3.23.0
     * EP11: Add support for FIPS-session mode
     * Updates to harden against RSA timing attacks
     * Bug fixes
* Tue Jan 30 2024 Dan HorĂ¡k <dan[at]danny.cz> - 3.22.0-4
  - fix all errors and warnings (rhbz#2261419)
* Thu Jan 25 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.22.0-3
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.22.0-2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Thu Sep 21 2023 Than Ngo <than@redhat.com> - 3.22.0-1
  - update to 3.22.0

Files

/usr/lib/.build-id
/usr/lib/.build-id/19
/usr/lib/.build-id/19/9d8db212a6953205b847101158da7051ef2727
/usr/lib/tmpfiles.d/opencryptoki-icatok.conf
/usr/lib64/opencryptoki/stdll/PKCS11_ICA.so
/usr/lib64/opencryptoki/stdll/libpkcs11_ica.so
/usr/lib64/opencryptoki/stdll/libpkcs11_ica.so.0
/usr/lib64/opencryptoki/stdll/libpkcs11_ica.so.0.0.0
/var/lib/opencryptoki/lite
/var/lib/opencryptoki/lite/TOK_OBJ


Generated by rpm2html 1.8.1

Fabrice Bellet, Fri Oct 24 01:49:52 2025