6715 Remove MD2 from libkmfReviewed by: Peter Tribble <peter.tribble@gmail.com>Reviewed by: Igor Kozhukhov <ikozhukhov@gmail.com>Reviewed by: Saso Kiselkov <skiselkov.ml@gmail.com>Approved by: Ga
6715 Remove MD2 from libkmfReviewed by: Peter Tribble <peter.tribble@gmail.com>Reviewed by: Igor Kozhukhov <ikozhukhov@gmail.com>Reviewed by: Saso Kiselkov <skiselkov.ml@gmail.com>Approved by: Garrett D'Amore <garrett@damore.org>
show more ...
5878 Additional lint fixes for sunstudio12.1 and more modern OpenSSLReviewed by: Dan McDonald <danmcd@omniti.com>Reviewed by: Hans Rosenfeld <rosenfeld@grumpf.hope-2000.org>Approved by: Gordon Ros
5878 Additional lint fixes for sunstudio12.1 and more modern OpenSSLReviewed by: Dan McDonald <danmcd@omniti.com>Reviewed by: Hans Rosenfeld <rosenfeld@grumpf.hope-2000.org>Approved by: Gordon Ross <gordon.w.ross@gmail.com>
5591 initialisation inversion of component order in cmd-crypto/elfsign.c5620 cstyle updates for cmd/cmd-crypto and lib/libkmfReviewed by: Dan McDonald <danmcd@omniti.com>Reviewed by: David Höppner
5591 initialisation inversion of component order in cmd-crypto/elfsign.c5620 cstyle updates for cmd/cmd-crypto and lib/libkmfReviewed by: Dan McDonald <danmcd@omniti.com>Reviewed by: David Höppner <0xffea@gmail.com>Reviewed by: Josef "Jeff" Sipek <jeffpc@josefsipek.net>Approved by: Dan McDonald <danmcd@omniti.com>
backout 4853: breaks lint
4853 illumos-gate is not lint-clean when built with openssl 1.0Reviewed by: Keith Wesolowski <keith.wesolowski@joyent.com>Reviewed by: Alexander Eremin <alexander.eremin@nexenta.com>Approved by: R
4853 illumos-gate is not lint-clean when built with openssl 1.0Reviewed by: Keith Wesolowski <keith.wesolowski@joyent.com>Reviewed by: Alexander Eremin <alexander.eremin@nexenta.com>Approved by: Robert Mustacchi <rm@joyent.com>
3915 Add adjuncts support to the buildReviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Richard Lowe <richlowe@richlowe.net>Approved by: Dan McDonald <danmcd@nexenta.com>
2933 compiler warning gags need better granularityReviewed by: Eric Schrock <eric.schrock@delphix.com>Approved by: Garrett D'Amore <garrett@damore.org>
1665 Illumos wont build against openssl 1.0.0Reviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Keith Wesolowski <keith.wesolowski@joyent.com>Reviewed by: Joshua M. Clulow <josh@sysmgr.org>
1665 Illumos wont build against openssl 1.0.0Reviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Keith Wesolowski <keith.wesolowski@joyent.com>Reviewed by: Joshua M. Clulow <josh@sysmgr.org>Approved by: Albert Lee <trisk@nexenta.com>
PSARC 2010/269 KMF Certificate Validation Enhancements6963018 kmf_validate_cert should put more flags into the output attribute in case of an error6939226 allow one KMF session to choose from multi
PSARC 2010/269 KMF Certificate Validation Enhancements6963018 kmf_validate_cert should put more flags into the output attribute in case of an error6939226 allow one KMF session to choose from multiple trusted anchors to validate a certificate
6964517 OSnet mapfiles should use version 2 link-editor syntax (2nd pass)6948720 SHT_INIT_ARRAY etc. section names don't follow ELF gABI6962343 sgsmsg should use mkstemp() for temporary file creati
6964517 OSnet mapfiles should use version 2 link-editor syntax (2nd pass)6948720 SHT_INIT_ARRAY etc. section names don't follow ELF gABI6962343 sgsmsg should use mkstemp() for temporary file creation
6916796 OSnet mapfiles should use version 2 link-editor syntax--HG--rename : usr/src/cmd/sgs/libelf/common/mapfile-common => usr/src/cmd/sgs/libelf/common/mapfile-versrename : usr/src/cmd/sgs/lin
6916796 OSnet mapfiles should use version 2 link-editor syntax--HG--rename : usr/src/cmd/sgs/libelf/common/mapfile-common => usr/src/cmd/sgs/libelf/common/mapfile-versrename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-bindings => usr/src/cmd/sgs/link_audit/common/mapfile-vers-bindingsrename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-perfcnt => usr/src/cmd/sgs/link_audit/common/mapfile-vers-perfcntrename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-symbindrep => usr/src/cmd/sgs/link_audit/common/mapfile-vers-symbindreprename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-truss => usr/src/cmd/sgs/link_audit/common/mapfile-vers-trussrename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-who => usr/src/cmd/sgs/link_audit/common/mapfile-vers-whorename : usr/src/common/mapfiles/i386/map.noexdata => usr/src/common/mapfiles/common/map.noexdatarename : usr/src/lib/libaio/sparc/mapfile-vers => usr/src/lib/libaio/common/mapfile-versrename : usr/src/lib/libelfsign/common/mapfile.map => usr/src/lib/libelfsign/common/mapfile-versrename : usr/src/lib/libpthread/sparc/mapfile-vers => usr/src/lib/libpthread/common/mapfile-versrename : usr/src/lib/librt/amd64/mapfile-vers => usr/src/lib/librt/common/mapfile-versrename : usr/src/lib/libsys/sparc/mapfile-vers => usr/src/lib/libsys/common/mapfile-versrename : usr/src/lib/libthread/sparc/mapfile-vers => usr/src/lib/libthread/common/mapfile-vers
6961704 KMF generates certificates with bad signatures
PSARC/2010/177 KMF Certificate Name mapping extensionsPSARC/2010/178 KMF Common Name Mapper6942888 KMF should provide certificate to name mapping capabilities6949176 KMF cert-to-name mapping frame
PSARC/2010/177 KMF Certificate Name mapping extensionsPSARC/2010/178 KMF Common Name Mapper6942888 KMF should provide certificate to name mapping capabilities6949176 KMF cert-to-name mapping framework needs a CN mapper
6944179 kmf_sign_cert needs more info about signing algorithm6944121 KMF should add Basic-Constraint when keyCertSign EKU is set6943253 pktool should ask to overwrite a CSR file if it already exist
6944179 kmf_sign_cert needs more info about signing algorithm6944121 KMF should add Basic-Constraint when keyCertSign EKU is set6943253 pktool should ask to overwrite a CSR file if it already exists6943234 pktool online help wrongly suggests we can delete a key based on its subject-DN6940180 certClass should be called privClass (or just class) in KMFPK11_FindPrikeyByCert()6940146 kmf_sign_data() returns KMF_ERR_INTERNAL but the PKCS#11 plugin returns KMF_ERR_MISSING_ERRCODE6938522 kmf_openssl.so.1 clobbers OpenSSL locking callbacks
PSARC 2010/032 EC and SHA2 for KMF6902640 pktool/KMF needs to support ECDSA keys and certificates6787016 pktool can offer the ability to generate RSA keypairs
6864896 libkmf leaks memory
6914632 libkmf has unused functions that should be removed6914613 libelfsign still uses deprecated libkmf API
6894056 libc is not clean6894060 libnsl is not lint clean6894068 libpool is not lint clean6894073 some zone libs are not lint clean6913623 some user land components of ON are not ss12u1 lint clean
6904179 kcfd dies under the tender mercies of libumem
6889197 libkmf uses realloc incorrectly6889730 pktool fails to add EKUs to CSR and Cert requests6889224 pktool incorrectly generates SAN
6887337 pktool gencert should use SHA1 instead of MD5
6796585 Array overrun in libkmf6874082 KMF fails to create generic AES keys for NSS6869630 pktool export is broken after CR 6860037 was integrated
6852240 libelfsign should use pkcs11_softtoken instead of OpenSSL for FIPS-140 integrity checking6851814 tools elfsign is unnecessarily linked against pkcs11_softtoken
6855407 kernel crypto module reports firmware version incorrectly6854979 kmf_pkcs11.so.1 has bad SONAME and versioning
6806387 Move OpenSSL from ON to SFW
123