6b35cb3cf158584a9408d44b9b6796564e8e1882 |
|
17-Feb-2015 |
Richard PALO <richard@NetBSD.org> |
5591 initialisation inversion of component order in cmd-crypto/elfsign.c
5620 cstyle updates for cmd/cmd-crypto and lib/libkmf
Reviewed by: Dan McDonald <danmcd@omniti.com>
Reviewed by: David Höppner <0xffea@gmail.com>
Reviewed by: Josef "Jeff" Sipek <jeffpc@josefsipek.net>
Approved by: Dan McDonald <danmcd@omniti.com> |
fc2613b0a10c787c0f90e9b36f170183746c63f8 |
|
27-Jul-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
PSARC 2010/269 KMF Certificate Validation Enhancements
6963018 kmf_validate_cert should put more flags into the output attribute in case of an error
6939226 allow one KMF session to choose from multiple trusted anchors to validate a certificate |
f5880f733dae6fbca929002abbce77c9c77dbf6a |
|
21-Jun-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6961704 KMF generates certificates with bad signatures |
2c9a247fb01631b3eb3b85a1127e72f0b60ae108 |
|
23-Apr-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6944179 kmf_sign_cert needs more info about signing algorithm
6944121 KMF should add Basic-Constraint when keyCertSign EKU is set
6943253 pktool should ask to overwrite a CSR file if it already exists
6943234 pktool online help wrongly suggests we can delete a key based on its subject-DN
6940180 certClass should be called privClass (or just class) in KMFPK11_FindPrikeyByCert()
6940146 kmf_sign_data() returns KMF_ERR_INTERNAL but the PKCS#11 plugin returns KMF_ERR_MISSING_ERRCODE
6938522 kmf_openssl.so.1 clobbers OpenSSL locking callbacks |
e65e5c2d2f32a99e8c5f740cabae9075dab03ce7 |
|
22-Mar-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
PSARC 2010/032 EC and SHA2 for KMF
6902640 pktool/KMF needs to support ECDSA keys and certificates
6787016 pktool can offer the ability to generate RSA keypairs |
9f0bc604621fbb9b9b038e6de7da8f9c46e28608 |
|
09-Jan-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6914632 libkmf has unused functions that should be removed
6914613 libelfsign still uses deprecated libkmf API |
4165f46543b20d435f7ef0aced6239f7e97b12ff |
|
08-Oct-2009 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6887337 pktool gencert should use SHA1 instead of MD5 |
2225707c7e7edf7c636ed349df2592ef85329cdd |
|
18-Jul-2009 |
Valerie Bubb Fenwick <Valerie.Fenwick@Sun.COM> |
6852240 libelfsign should use pkcs11_softtoken instead of OpenSSL for FIPS-140 integrity checking
6851814 tools elfsign is unnecessarily linked against pkcs11_softtoken |
448b8615fe9e8af757530284920a235430ead7e8 |
|
20-May-2008 |
wyllys <none@none> |
PSARC 2008/306 pktool CLI update (dir option correction)
6670712 cert of dsa type with key pair can not signcsr of rsa type, viceversa.
6670714 pktool gencert keystore=nss and keytype=dsa FAIL, parameter error
6670715 pktool gencsr keystore=nss and token="install" (something not "internal") core dumped
6670725 pktool signcsr command fails to update the keyusage values.
6699535 pktool operations should not have "dir" option for file-based keystore
6700175 fix for 6654080 is not complete |
d00756ccb34596a328f8a15d1965da5412d366d0 |
|
21-Feb-2008 |
wyllys <none@none> |
PSARC 2008/037 new EKU support for pktool and kmfcfg
6648052 pktool(1) could allow certificate signing and verification
6652751 kmf_get_kmf_error_str() doesn't know about KMF_ERR_ATTR_NOT_FOUND
6654080 kmf_verify_data() should use algorithm from the cert if KMF_ALGORITHM_INDEX_ATTR is missing
6654205 kmf_find_prikey_by_cert() should be public
6654910 kmf_validate_cert() won't get over non-existent x509v3 extensions in TA
6660235 Command summary on pktool help should be localizable.
6660622 KMF needs API to determine format of raw data |
85b5e720b6ec2a46e28202e7e7be913a889bca0e |
|
12-Jan-2008 |
wyllys <none@none> |
6643119 kmf_validate_cert() should download CRL only when the previous one has expired (fix lint) |
646cf3c6c5f9a3403fe9d15809bbbb2441deb1e2 |
|
11-Jan-2008 |
wyllys <none@none> |
6630137 Un-initialized variable caused a wrong branch in KMFPK11_StoreKey
6643119 kmf_validate_cert() should download CRL only when the previous one has expired |
431deaa01ac039d796fdfaf86b909a75e7d9ac48 |
|
07-Dec-2007 |
hylee <none@none> |
PSARC 2007/604 KMF Pluggability Enhancements
6621224 KMF Dynamic Plugin Support
6621231 pktool list keystore=file dir=/tmp/test prints out incorrect output |
5b3e1433c6213363bcb6387e66fc84ee9ff21a5d |
|
28-Nov-2007 |
wyllys <none@none> |
6620497 KMF does not build proper PKCS12 PDUs
6624214 kmf_get_cert_extn can leak memory
6629477 libkmf is crashed in OpenSSL_StoreKey if keytype is not KMF_RSA or KMF_DSA |
30a5e8fa1253cb33980ee4514743cf683f584b4e |
|
14-Sep-2007 |
wyllys <none@none> |
PSARC 2007/426 KMFAPI Interface Taxonomy Change
PSARC 2007/465 pktool symmetric key enhancements
6546405 KMF Interfaces need to be extensible
6547894 pktool should be more detailed
6590232 pktool should import and export generic keys |
6adaf03e130142c9de7b6c050f0d0b1df4e73044 |
|
19-Apr-2007 |
wyllys <none@none> |
6547594 KMF incorrectly processes pkcs12 files
6547853 KMF is too strict about KeyUsage |
9b37d29632d2cb262ba42f1d804f85fcb0aa3709 |
|
15-Mar-2007 |
wyllys <none@none> |
6531818 libkmf has too many dependencies on libpkcs11
6534811 KMF openssl verify routine should test for NULL hash method.
6534827 KMF_ReadInputFile should not require a handle |
02744e811b15322c5f109827a116c33bfe3438b5 |
|
03-Mar-2007 |
wyllys <none@none> |
6523959 KMF needs keystore specific Verify operations
--HG--
rename : usr/src/lib/libkmf/include/oidsalg.h => deleted_files/usr/src/lib/libkmf/include/oidsalg.h |
5363b1129db4ee42d2c9736898eab4670580bec7 |
|
22-Feb-2007 |
hylee <none@none> |
6525220 KMF_ValidateCert() and KMF_FindCertInCRL() should take a subject certificate as input |
9a7670889e9c36ec355371e6b02f2d9084f040dc |
|
17-Jan-2007 |
haimay <none@none> |
6509342 Code licenses for KMF need to be cleaned up. |
71593db26bb6ef7b739cffe06d53bf990cac112c |
|
12-Jan-2007 |
wyllys <none@none> |
6501154 kssladm could use KMF
--HG--
rename : usr/src/cmd/cmd-inet/usr.sbin/kssl/kssladm/openssl_util.c => usr/src/cmd/cmd-inet/usr.sbin/kssl/kssladm/ksslutil.c |
31558a356540225e286233d63c122a35e4a4bd22 |
|
27-Nov-2006 |
wyllys <none@none> |
6495595 KMF incorrectly checks the CA constraint
6495596 KMF_OpenSSL plugin incorrectly clears memory from returned cert list. |
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8 |
|
11-Nov-2006 |
wyllys <none@none> |
PSARC 2005/074 Solaris Key Management Framework
6224192 Solaris needs unified key management interfaces
--HG--
rename : usr/src/cmd/cmd-crypto/pktool/biginteger.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/biginteger.h
rename : usr/src/cmd/cmd-crypto/pktool/derparse.c => deleted_files/usr/src/cmd/cmd-crypto/pktool/derparse.c
rename : usr/src/cmd/cmd-crypto/pktool/derparse.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/derparse.h
rename : usr/src/cmd/cmd-crypto/pktool/osslcommon.c => deleted_files/usr/src/cmd/cmd-crypto/pktool/osslcommon.c
rename : usr/src/cmd/cmd-crypto/pktool/osslcommon.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/osslcommon.h
rename : usr/src/cmd/cmd-crypto/pktool/p12common.c => deleted_files/usr/src/cmd/cmd-crypto/pktool/p12common.c
rename : usr/src/cmd/cmd-crypto/pktool/p12common.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/p12common.h |