6b35cb3cf158584a9408d44b9b6796564e8e1882 |
|
17-Feb-2015 |
Richard PALO <richard@NetBSD.org> |
5591 initialisation inversion of component order in cmd-crypto/elfsign.c
5620 cstyle updates for cmd/cmd-crypto and lib/libkmf
Reviewed by: Dan McDonald <danmcd@omniti.com>
Reviewed by: David Höppner <0xffea@gmail.com>
Reviewed by: Josef "Jeff" Sipek <jeffpc@josefsipek.net>
Approved by: Dan McDonald <danmcd@omniti.com> |
2c9a247fb01631b3eb3b85a1127e72f0b60ae108 |
|
23-Apr-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6944179 kmf_sign_cert needs more info about signing algorithm
6944121 KMF should add Basic-Constraint when keyCertSign EKU is set
6943253 pktool should ask to overwrite a CSR file if it already exists
6943234 pktool online help wrongly suggests we can delete a key based on its subject-DN
6940180 certClass should be called privClass (or just class) in KMFPK11_FindPrikeyByCert()
6940146 kmf_sign_data() returns KMF_ERR_INTERNAL but the PKCS#11 plugin returns KMF_ERR_MISSING_ERRCODE
6938522 kmf_openssl.so.1 clobbers OpenSSL locking callbacks |
e65e5c2d2f32a99e8c5f740cabae9075dab03ce7 |
|
22-Mar-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
PSARC 2010/032 EC and SHA2 for KMF
6902640 pktool/KMF needs to support ECDSA keys and certificates
6787016 pktool can offer the ability to generate RSA keypairs |
4165f46543b20d435f7ef0aced6239f7e97b12ff |
|
08-Oct-2009 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6887337 pktool gencert should use SHA1 instead of MD5 |
a44b45c8fa54b3a79a2de076aa2d8c48cd75dee4 |
|
23-Mar-2009 |
Huie-Ying Lee <Huie-Ying.Lee@Sun.COM> |
6814522 pktool gencert/gencsr should remove keypair if there is an error |
577f4726f2ea5aeaa2cf3dd65aca52869834b137 |
|
16-Jun-2008 |
wyllys <none@none> |
6710916 pktool needs to report error when "dir" option is present but not necessary |
448b8615fe9e8af757530284920a235430ead7e8 |
|
20-May-2008 |
wyllys <none@none> |
PSARC 2008/306 pktool CLI update (dir option correction)
6670712 cert of dsa type with key pair can not signcsr of rsa type, viceversa.
6670714 pktool gencert keystore=nss and keytype=dsa FAIL, parameter error
6670715 pktool gencsr keystore=nss and token="install" (something not "internal") core dumped
6670725 pktool signcsr command fails to update the keyusage values.
6699535 pktool operations should not have "dir" option for file-based keystore
6700175 fix for 6654080 is not complete |
fa60c371cd00bdca17de2ff18fe3e64d051ae61b |
|
03-Apr-2008 |
wyllys <none@none> |
6669251 KMF needs to support empty PINs
6669357 KMF pkcs11 incorrectly sets some attributes when creating certificates and keys
6679525 [CLI] Subcommands in pktool's help are overtranslated
6680520 pktool needs to prompt for PIN more often |
d00756ccb34596a328f8a15d1965da5412d366d0 |
|
21-Feb-2008 |
wyllys <none@none> |
PSARC 2008/037 new EKU support for pktool and kmfcfg
6648052 pktool(1) could allow certificate signing and verification
6652751 kmf_get_kmf_error_str() doesn't know about KMF_ERR_ATTR_NOT_FOUND
6654080 kmf_verify_data() should use algorithm from the cert if KMF_ALGORITHM_INDEX_ATTR is missing
6654205 kmf_find_prikey_by_cert() should be public
6654910 kmf_validate_cert() won't get over non-existent x509v3 extensions in TA
6660235 Command summary on pktool help should be localizable.
6660622 KMF needs API to determine format of raw data |
2cbed7292737821015ab481353eb10e8346b2c05 |
|
10-Oct-2007 |
wyllys <none@none> |
6612107 pktool list objtype=cert Serial: oddity
6612173 pktool interactive mode should ask more questions
6612636 pktool delete is inconsistent
6613494 pktool fails creation outkey = in dir= if there is a file/dir in current dir of same name |
30a5e8fa1253cb33980ee4514743cf683f584b4e |
|
14-Sep-2007 |
wyllys <none@none> |
PSARC 2007/426 KMFAPI Interface Taxonomy Change
PSARC 2007/465 pktool symmetric key enhancements
6546405 KMF Interfaces need to be extensible
6547894 pktool should be more detailed
6590232 pktool should import and export generic keys |
985be8f145003c39bf82ad09a81ad394e4d7d4b6 |
|
26-Jan-2007 |
wyllys <none@none> |
6507361 pktool help doesn't
6514823 kmfcfg is misspelled in exec_attr
6515109 Error message when using "pktool gencert" should use 'serial' instead of 'serno' |
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8 |
|
11-Nov-2006 |
wyllys <none@none> |
PSARC 2005/074 Solaris Key Management Framework
6224192 Solaris needs unified key management interfaces
--HG--
rename : usr/src/cmd/cmd-crypto/pktool/biginteger.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/biginteger.h
rename : usr/src/cmd/cmd-crypto/pktool/derparse.c => deleted_files/usr/src/cmd/cmd-crypto/pktool/derparse.c
rename : usr/src/cmd/cmd-crypto/pktool/derparse.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/derparse.h
rename : usr/src/cmd/cmd-crypto/pktool/osslcommon.c => deleted_files/usr/src/cmd/cmd-crypto/pktool/osslcommon.c
rename : usr/src/cmd/cmd-crypto/pktool/osslcommon.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/osslcommon.h
rename : usr/src/cmd/cmd-crypto/pktool/p12common.c => deleted_files/usr/src/cmd/cmd-crypto/pktool/p12common.c
rename : usr/src/cmd/cmd-crypto/pktool/p12common.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/p12common.h |