5591 initialisation inversion of component order in cmd-crypto/elfsign.c5620 cstyle updates for cmd/cmd-crypto and lib/libkmfReviewed by: Dan McDonald <danmcd@omniti.com>Reviewed by: David Höppner
5591 initialisation inversion of component order in cmd-crypto/elfsign.c5620 cstyle updates for cmd/cmd-crypto and lib/libkmfReviewed by: Dan McDonald <danmcd@omniti.com>Reviewed by: David Höppner <0xffea@gmail.com>Reviewed by: Josef "Jeff" Sipek <jeffpc@josefsipek.net>Approved by: Dan McDonald <danmcd@omniti.com>
show more ...
4027 remove CLOSED_BUILD4028 remove CLOSED_IS_PRESENT4029 remove tonic build bitsReviewed by: Andy Stormont <andyjstormont@gmail.com>Reviewed by: Richard Lowe <richlowe@richlowe.net>Approved by:
4027 remove CLOSED_BUILD4028 remove CLOSED_IS_PRESENT4029 remove tonic build bitsReviewed by: Andy Stormont <andyjstormont@gmail.com>Reviewed by: Richard Lowe <richlowe@richlowe.net>Approved by: Richard Lowe <richlowe@richlowe.net>
4072 make clobber leaves trashReviewed by: Albert Lee <trisk@nexenta.com>Reviewed by: Dan McDonald <danmcd@nexenta.com>Reviewed by: Marcel Telka <marcel.telka@nexenta.com>Reviewed by: Richard Low
4072 make clobber leaves trashReviewed by: Albert Lee <trisk@nexenta.com>Reviewed by: Dan McDonald <danmcd@nexenta.com>Reviewed by: Marcel Telka <marcel.telka@nexenta.com>Reviewed by: Richard Lowe <richlowe@richlowe.net>Approved by: Garrett D'Amore <garrett@damore.org>
3915 Add adjuncts support to the buildReviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Richard Lowe <richlowe@richlowe.net>Approved by: Dan McDonald <danmcd@nexenta.com>
3887 Enlarge data buffer in digest/mac to boost performanceReviewed by: Saso Kiselkov <skiselkov.ml@gmail.com>Reviewed by: Garrett D'Amore <garrett@damore.org>Approved by: Dan McDonald <danmcd@nex
3887 Enlarge data buffer in digest/mac to boost performanceReviewed by: Saso Kiselkov <skiselkov.ml@gmail.com>Reviewed by: Garrett D'Amore <garrett@damore.org>Approved by: Dan McDonald <danmcd@nexenta.com>
3310 root CA certs should be removed from illumos-gateReviewed by: Garrett D'Amore <garrett@damore.org>Approved by: Dan McDonald <danmcd@nexenta.com>
2933 compiler warning gags need better granularityReviewed by: Eric Schrock <eric.schrock@delphix.com>Approved by: Garrett D'Amore <garrett@damore.org>
1665 Illumos wont build against openssl 1.0.0Reviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Keith Wesolowski <keith.wesolowski@joyent.com>Reviewed by: Joshua M. Clulow <josh@sysmgr.org>
1665 Illumos wont build against openssl 1.0.0Reviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Keith Wesolowski <keith.wesolowski@joyent.com>Reviewed by: Joshua M. Clulow <josh@sysmgr.org>Approved by: Albert Lee <trisk@nexenta.com>
2111 begone, pkcs11_kms!Reviewed by: Alexander Eremin <alexander.eremin@nexenta.com>Reviewed by: Jason King <jason.brian.king@gmail.com>Reviewed by: Garrett D'Amore <garrett@damore.org>Approved b
2111 begone, pkcs11_kms!Reviewed by: Alexander Eremin <alexander.eremin@nexenta.com>Reviewed by: Jason King <jason.brian.king@gmail.com>Reviewed by: Garrett D'Amore <garrett@damore.org>Approved by: Richard Lowe <richlowe@richlowe.net>
2077 lots of unreachable breaks in illumos gateReviewed by: Dan McDonald <danmcd@nexenta.com>Reviewed by: Garrett D'Amore <garrett@damore.org>Approved by: Richard Lowe <richlowe@richlowe.net>
1760 constant condition in elfsign annoys GCCReviewed by: Dan McDonald <danmcd@nexenta.com>Reviewed by: Gordon Ross <gwr@nexenta.com>Approved by: Eric Schrock <eric.schrock@delphix.com>
1445 Stop trusting the diginotar certReviewed by: Gordon Ross <gwr@nexenta.com>Reviewed by: Dan McDonald <danmcd@nexenta.com>Approved by: Garrett D'Amore <garrett@nexenta.com>
6 Need open kcfdReviewed by: gwr@nexenta.com, richlowe@richlowe.net, matt@greenviolet.netApproved by: richlowe@richlowe.net
6974684 libpkcs11 performance can be improved with less restrictive dlopen() flags6975112 libpkcs11 shouldn't try to dlclose its own metaslot
6959099 T2 Crypto Drivers (ncp, n2cp, n2rng) need to implement self tests for FIPS 140-2 compliance
PSARC 2010/269 KMF Certificate Validation Enhancements6963018 kmf_validate_cert should put more flags into the output attribute in case of an error6939226 allow one KMF session to choose from multi
PSARC 2010/269 KMF Certificate Validation Enhancements6963018 kmf_validate_cert should put more flags into the output attribute in case of an error6939226 allow one KMF session to choose from multiple trusted anchors to validate a certificate
6970482 cryptoadm cores when listing CKM_AES_CBC mechanism
PSARC 2010/195 PKCS11 KMS Provider6944296 Solaris needs a PKCS#11 provider to allow access to KMS keystore functionality
PSARC 2009/430 Default system CA (X.509) Certificates6661895 /etc/sfw/openssl/certs has no well known CA certificates
PSARC/2010/177 KMF Certificate Name mapping extensionsPSARC/2010/178 KMF Common Name Mapper6942888 KMF should provide certificate to name mapping capabilities6949176 KMF cert-to-name mapping frame
PSARC/2010/177 KMF Certificate Name mapping extensionsPSARC/2010/178 KMF Common Name Mapper6942888 KMF should provide certificate to name mapping capabilities6949176 KMF cert-to-name mapping framework needs a CN mapper
6954451 pktool list does not pass user creds to KMF correctly
PSARC/2010/146 EOF unnecessary elfsign and kCF options6855881 clean up unnecessary technology from elfsign and kcf
6944179 kmf_sign_cert needs more info about signing algorithm6944121 KMF should add Basic-Constraint when keyCertSign EKU is set6943253 pktool should ask to overwrite a CSR file if it already exist
6944179 kmf_sign_cert needs more info about signing algorithm6944121 KMF should add Basic-Constraint when keyCertSign EKU is set6943253 pktool should ask to overwrite a CSR file if it already exists6943234 pktool online help wrongly suggests we can delete a key based on its subject-DN6940180 certClass should be called privClass (or just class) in KMFPK11_FindPrikeyByCert()6940146 kmf_sign_data() returns KMF_ERR_INTERNAL but the PKCS#11 plugin returns KMF_ERR_MISSING_ERRCODE6938522 kmf_openssl.so.1 clobbers OpenSSL locking callbacks
PSARC 2010/032 EC and SHA2 for KMF6902640 pktool/KMF needs to support ECDSA keys and certificates6787016 pktool can offer the ability to generate RSA keypairs
6927569 cryptoadm unload doesn't perform as expected on freshly-installed systems
12345