5830 want arc4random(3C) suite5802 want getentropy(3C)5803 want getrandom(2)5804 want explicit_bzero(3C)5805 want MC_INHERIT_ZERO5806 uuid_generate can leak its cache in edge conditionsReviewed
5830 want arc4random(3C) suite5802 want getentropy(3C)5803 want getrandom(2)5804 want explicit_bzero(3C)5805 want MC_INHERIT_ZERO5806 uuid_generate can leak its cache in edge conditionsReviewed by: Jerry Jelinek <jerry.jelinek@joyent.com>Reviewed by: Joshua M. Clulow <josh@sysmgr.org>Reviewed by: Josef 'Jeff' Sipek <josef.sipek@nexenta.com>Reviewed by: Garrett D'Amore <garrett@damore.org>Approved by: Garrett D'Amore <garrett@damore.org>
show more ...
995 boot message: No randomness provider enabled for /dev/randomReviewed by: Garrett D'Amore <garrett@damore.org>Reviewed by: Dan McDonald <danmcd@nexenta.com>Reviewed by: Hans Rosenfeld <hans.ros
995 boot message: No randomness provider enabled for /dev/randomReviewed by: Garrett D'Amore <garrett@damore.org>Reviewed by: Dan McDonald <danmcd@nexenta.com>Reviewed by: Hans Rosenfeld <hans.rosenfeld@nexenta.com>Reviewed by: Boris Protopopov <boris.protopopov@nexenta.com>Approved by: Garrett D'Amore <garrett@damore.org>
349 hang during network boot (circular kcf dependency)Reviewed by: richlowe@richlowe.netReviewed by: gwr@nexenta.comReviewed by: bryancantrill@nexenta.comApproved by: gwr@nexenta.com
6 Need open kcfdReviewed by: gwr@nexenta.com, richlowe@richlowe.net, matt@greenviolet.netApproved by: richlowe@richlowe.net
6966188 missing mutex_exit call if error occurs while gathering random bytes
PSARC/2010/146 EOF unnecessary elfsign and kCF options6855881 clean up unnecessary technology from elfsign and kcf
6719591 non-exploitable integer wraparound issue in copyin_key() [external report]
FWARC 2008/613 KT IOS Performance Counters APIFWARC 2008/615 KT Perf Reg HV APIFWARC 2009/434 KT IOS Performance Counters API UpdateFWARC 2009/567 Parallel Boot HV APIsPSARC 2009/177 Solaris supp
FWARC 2008/613 KT IOS Performance Counters APIFWARC 2008/615 KT Perf Reg HV APIFWARC 2009/434 KT IOS Performance Counters API UpdateFWARC 2009/567 Parallel Boot HV APIsPSARC 2009/177 Solaris support for Rainbow Falls platformsPSARC 2009/389 Sun4v faulted SP events extensionPSARC 2009/533 CRYPTO_HMAC_NO_UPDATE - A new KCF SPI flagPSARC 2009/605 more sun4v platform-independent cpu/mem FMA eventsPSARC 2009/649 Generic PCIe root complex FMA events6704999 extend xaui enum to work in platform independent world6773223 RFE: guest epkt for faulted SP6773225 RFE: Diagnosis of a faulted SP6797776 Solaris support for Rainbow Falls platforms
PSARC/2009/447 Kernel Cryptographic Framework support for FIPS 140-26703950 Solaris cryptographic framework needs to implement changes for FIPS-140-2 compliance
6882364 networking wedged up behind blocked taskq_thread() worker
6826942 Need an optimized GCM leveraging Intel's PCMULQDQ instruction
PSARC 2009/347 cryptoadm(1M) enhancement for FIPS-140 mode6787364 Administration and policy configuration changes to support FIPS 140-26867384 Solaris Crypto Framework needs to implement self tests
PSARC 2009/347 cryptoadm(1M) enhancement for FIPS-140 mode6787364 Administration and policy configuration changes to support FIPS 140-26867384 Solaris Crypto Framework needs to implement self tests for FIPS 140-2 compliance
6786946 kcf should check the key sizes before passing a job to a provider6831413 multiple SCF providers advertise wrong boundaries for CKM_DES3_{CBC,ECB}{,_PAD} key lengths
6836582 kcf_limit_hwrng tunable can be removed
4781345 me_mutex lock in kcf_mech_entry_t can be broken up6771819 Use of atomic increment in KCF causes scaling problems on multi-socket T2 systems6705174 C_EncryptInit scaling issues on T2plus681
4781345 me_mutex lock in kcf_mech_entry_t can be broken up6771819 Use of atomic increment in KCF causes scaling problems on multi-socket T2 systems6705174 C_EncryptInit scaling issues on T2plus6813873 assertion failed: (prov_desc)->pd_refcnt != 0, file: ../../common/crypto/core/kcf_prov_tabs.c, line
6803803 rnd_chpoll() should not reject (EINVAL) events==0
6799258 Continuous RNG test sometimes fails to compare 160-bit blocks
6790685 stubs for random_add_pseudo_entropy() are missing
PSARC 2007/001 lofi(7d) crypto support4926125 lofi(7d) should support encrypted block devices6236948 need userland interface to list crypto algorithms available to kernel consumers
6703956 Solaris cryptographic framework needs a FIPS-186-2 certifiable RNG
PSARC/2007/213 Support KCF Providers with Limited Digest Capability6473274 pkcs11_kernel should support multipart ops even for hardware that has only single part6534615 For extra credit, dprov coul
PSARC/2007/213 Support KCF Providers with Limited Digest Capability6473274 pkcs11_kernel should support multipart ops even for hardware that has only single part6534615 For extra credit, dprov could make HMAC mechanisms work for PKCS #11 clients6541772 usr/src/cmd/mdb/common/modules/crypto/sched_impl.c should not include stdlib.h6542759 HMAC mechanisms broken in sha2 kernel module
PSARC/2007/093 Crypto Context sharing between providers6494834 support check for threshold when using hardware providers even for multi-part requests
6509484 Needless calls to KCF_PROV_REFHOLD() in some routines
6488985 kcf_submit_request() should handle the EMPTYQ case for a hardware provider6478655 kcf should not log complaints as frequently as it does6470608 /dev/urandom should provide data blocks large
6488985 kcf_submit_request() should handle the EMPTYQ case for a hardware provider6478655 kcf should not log complaints as frequently as it does6470608 /dev/urandom should provide data blocks larger then 1040 bytes6478016 crypto_mechanism32_t should be available from sys/crypto/spi.h
PSARC/2006/540 Crypto event notification update6385143 Support usage of non-extractable keys6466686 need events to support session based clients6466693 need a routine to get provider information g
PSARC/2006/540 Crypto event notification update6385143 Support usage of non-extractable keys6466686 need events to support session based clients6466693 need a routine to get provider information given a provider handle6465847 ksslcfg reports service to be online even when there is an error6469846 dprov needs to set CKF_LOGIN_REQUIRED
12