#
6b35cb3c |
| 04-Feb-2015 |
Richard PALO <richard@NetBSD.org> |
5591 initialisation inversion of component order in cmd-crypto/elfsign.c 5620 cstyle updates for cmd/cmd-crypto and lib/libkmf Reviewed by: Dan McDonald <danmcd@omniti.com> Reviewed by: David Höppner
5591 initialisation inversion of component order in cmd-crypto/elfsign.c 5620 cstyle updates for cmd/cmd-crypto and lib/libkmf Reviewed by: Dan McDonald <danmcd@omniti.com> Reviewed by: David Höppner <0xffea@gmail.com> Reviewed by: Josef "Jeff" Sipek <jeffpc@josefsipek.net> Approved by: Dan McDonald <danmcd@omniti.com>
show more ...
|
#
fc2613b0 |
| 27-Jul-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
PSARC 2010/269 KMF Certificate Validation Enhancements 6963018 kmf_validate_cert should put more flags into the output attribute in case of an error 6939226 allow one KMF session to choose from multi
PSARC 2010/269 KMF Certificate Validation Enhancements 6963018 kmf_validate_cert should put more flags into the output attribute in case of an error 6939226 allow one KMF session to choose from multiple trusted anchors to validate a certificate
show more ...
|
#
f5880f73 |
| 21-Jun-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6961704 KMF generates certificates with bad signatures
|
#
2c9a247f |
| 23-Apr-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6944179 kmf_sign_cert needs more info about signing algorithm 6944121 KMF should add Basic-Constraint when keyCertSign EKU is set 6943253 pktool should ask to overwrite a CSR file if it already exist
6944179 kmf_sign_cert needs more info about signing algorithm 6944121 KMF should add Basic-Constraint when keyCertSign EKU is set 6943253 pktool should ask to overwrite a CSR file if it already exists 6943234 pktool online help wrongly suggests we can delete a key based on its subject-DN 6940180 certClass should be called privClass (or just class) in KMFPK11_FindPrikeyByCert() 6940146 kmf_sign_data() returns KMF_ERR_INTERNAL but the PKCS#11 plugin returns KMF_ERR_MISSING_ERRCODE 6938522 kmf_openssl.so.1 clobbers OpenSSL locking callbacks
show more ...
|
#
e65e5c2d |
| 22-Mar-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
PSARC 2010/032 EC and SHA2 for KMF 6902640 pktool/KMF needs to support ECDSA keys and certificates 6787016 pktool can offer the ability to generate RSA keypairs
|
#
9f0bc604 |
| 09-Jan-2010 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6914632 libkmf has unused functions that should be removed 6914613 libelfsign still uses deprecated libkmf API
|
#
4165f465 |
| 08-Oct-2009 |
Wyllys Ingersoll <wyllys.ingersoll@sun.com> |
6887337 pktool gencert should use SHA1 instead of MD5
|
#
2225707c |
| 18-Jul-2009 |
Valerie Bubb Fenwick <Valerie.Fenwick@Sun.COM> |
6852240 libelfsign should use pkcs11_softtoken instead of OpenSSL for FIPS-140 integrity checking 6851814 tools elfsign is unnecessarily linked against pkcs11_softtoken
|
#
448b8615 |
| 20-May-2008 |
wyllys <none@none> |
PSARC 2008/306 pktool CLI update (dir option correction) 6670712 cert of dsa type with key pair can not signcsr of rsa type, viceversa. 6670714 pktool gencert keystore=nss and keytype=dsa FAIL, param
PSARC 2008/306 pktool CLI update (dir option correction) 6670712 cert of dsa type with key pair can not signcsr of rsa type, viceversa. 6670714 pktool gencert keystore=nss and keytype=dsa FAIL, parameter error 6670715 pktool gencsr keystore=nss and token="install" (something not "internal") core dumped 6670725 pktool signcsr command fails to update the keyusage values. 6699535 pktool operations should not have "dir" option for file-based keystore 6700175 fix for 6654080 is not complete
show more ...
|
#
d00756cc |
| 21-Feb-2008 |
wyllys <none@none> |
PSARC 2008/037 new EKU support for pktool and kmfcfg 6648052 pktool(1) could allow certificate signing and verification 6652751 kmf_get_kmf_error_str() doesn't know about KMF_ERR_ATTR_NOT_FOUND 66540
PSARC 2008/037 new EKU support for pktool and kmfcfg 6648052 pktool(1) could allow certificate signing and verification 6652751 kmf_get_kmf_error_str() doesn't know about KMF_ERR_ATTR_NOT_FOUND 6654080 kmf_verify_data() should use algorithm from the cert if KMF_ALGORITHM_INDEX_ATTR is missing 6654205 kmf_find_prikey_by_cert() should be public 6654910 kmf_validate_cert() won't get over non-existent x509v3 extensions in TA 6660235 Command summary on pktool help should be localizable. 6660622 KMF needs API to determine format of raw data
show more ...
|
#
85b5e720 |
| 12-Jan-2008 |
wyllys <none@none> |
6643119 kmf_validate_cert() should download CRL only when the previous one has expired (fix lint)
|
#
646cf3c6 |
| 11-Jan-2008 |
wyllys <none@none> |
6630137 Un-initialized variable caused a wrong branch in KMFPK11_StoreKey 6643119 kmf_validate_cert() should download CRL only when the previous one has expired
|
#
431deaa0 |
| 07-Dec-2007 |
hylee <none@none> |
PSARC 2007/604 KMF Pluggability Enhancements 6621224 KMF Dynamic Plugin Support 6621231 pktool list keystore=file dir=/tmp/test prints out incorrect output
|
#
5b3e1433 |
| 28-Nov-2007 |
wyllys <none@none> |
6620497 KMF does not build proper PKCS12 PDUs 6624214 kmf_get_cert_extn can leak memory 6629477 libkmf is crashed in OpenSSL_StoreKey if keytype is not KMF_RSA or KMF_DSA
|
#
30a5e8fa |
| 14-Sep-2007 |
wyllys <none@none> |
PSARC 2007/426 KMFAPI Interface Taxonomy Change PSARC 2007/465 pktool symmetric key enhancements 6546405 KMF Interfaces need to be extensible 6547894 pktool should be more detailed 6590232 pktool sho
PSARC 2007/426 KMFAPI Interface Taxonomy Change PSARC 2007/465 pktool symmetric key enhancements 6546405 KMF Interfaces need to be extensible 6547894 pktool should be more detailed 6590232 pktool should import and export generic keys
show more ...
|
#
6adaf03e |
| 19-Apr-2007 |
wyllys <none@none> |
6547594 KMF incorrectly processes pkcs12 files 6547853 KMF is too strict about KeyUsage
|
#
9b37d296 |
| 15-Mar-2007 |
wyllys <none@none> |
6531818 libkmf has too many dependencies on libpkcs11 6534811 KMF openssl verify routine should test for NULL hash method. 6534827 KMF_ReadInputFile should not require a handle
|
#
02744e81 |
| 03-Mar-2007 |
wyllys <none@none> |
6523959 KMF needs keystore specific Verify operations
--HG-- rename : usr/src/lib/libkmf/include/oidsalg.h => deleted_files/usr/src/lib/libkmf/include/oidsalg.h
|
#
5363b112 |
| 22-Feb-2007 |
hylee <none@none> |
6525220 KMF_ValidateCert() and KMF_FindCertInCRL() should take a subject certificate as input
|
#
9a767088 |
| 17-Jan-2007 |
haimay <none@none> |
6509342 Code licenses for KMF need to be cleaned up.
|
#
71593db2 |
| 12-Jan-2007 |
wyllys <none@none> |
6501154 kssladm could use KMF
--HG-- rename : usr/src/cmd/cmd-inet/usr.sbin/kssl/kssladm/openssl_util.c => usr/src/cmd/cmd-inet/usr.sbin/kssl/kssladm/ksslutil.c
|
#
31558a35 |
| 27-Nov-2006 |
wyllys <none@none> |
6495595 KMF incorrectly checks the CA constraint 6495596 KMF_OpenSSL plugin incorrectly clears memory from returned cert list.
|
#
99ebb4ca |
| 11-Nov-2006 |
wyllys <none@none> |
PSARC 2005/074 Solaris Key Management Framework 6224192 Solaris needs unified key management interfaces
--HG-- rename : usr/src/cmd/cmd-crypto/pktool/biginteger.h => deleted_files/usr/src/cmd/cmd-cr
PSARC 2005/074 Solaris Key Management Framework 6224192 Solaris needs unified key management interfaces
--HG-- rename : usr/src/cmd/cmd-crypto/pktool/biginteger.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/biginteger.h rename : usr/src/cmd/cmd-crypto/pktool/derparse.c => deleted_files/usr/src/cmd/cmd-crypto/pktool/derparse.c rename : usr/src/cmd/cmd-crypto/pktool/derparse.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/derparse.h rename : usr/src/cmd/cmd-crypto/pktool/osslcommon.c => deleted_files/usr/src/cmd/cmd-crypto/pktool/osslcommon.c rename : usr/src/cmd/cmd-crypto/pktool/osslcommon.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/osslcommon.h rename : usr/src/cmd/cmd-crypto/pktool/p12common.c => deleted_files/usr/src/cmd/cmd-crypto/pktool/p12common.c rename : usr/src/cmd/cmd-crypto/pktool/p12common.h => deleted_files/usr/src/cmd/cmd-crypto/pktool/p12common.h
show more ...
|