Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

opencryptoki-3.26.0-1.fc44 RPM for x86_64

From Fedora Rawhide for x86_64 / o

Name: opencryptoki Distribution: Fedora Project
Version: 3.26.0 Vendor: Fedora Project
Release: 1.fc44 Build date: Fri Nov 28 17:55:29 2025
Group: Unspecified Build host: buildhw-x86-09.rdu3.fedoraproject.org
Size: 928172 Source RPM: opencryptoki-3.26.0-1.fc44.src.rpm
Packager: Fedora Project
Url: https://github.com/opencryptoki/opencryptoki
Summary: Implementation of the PKCS#11 (Cryptoki) specification v3.0 and partially v3.1
Opencryptoki implements the PKCS#11 specification  v3.0 and partially v3.1
for a set of cryptographic hardware, such as IBM 4767, 4768, 4769 and 4770
crypto cards, and the Trusted Platform Module (TPM) chip. Opencryptoki also
brings a software token implementation that can be used without any cryptographic
hardware.
This package contains the Slot Daemon (pkcsslotd) and general utilities.

Provides

Requires

License

CPL-1.0

Changelog

* Fri Nov 28 2025 Than Ngo <than@redhat.com> - 3.26.0-1
  - Update to 3.26.0
* Tue Jul 29 2025 Than Ngo <than@redhat.com> - 3.25.0-4
  - Require openssl >= 3.5.1
  - Fix incorrect effective group id of pkcsslotd daemon
  - Fix covscan findings
  - Fix detection of EC curve not supported by OpenSSL-3.5.x
  - Fix the image mode issue again as bootc expects to use /run/lock
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 3.25.0-3
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue Jun 10 2025 Than Ngo <than@redhat.com> - 3.25.0-2
  - Enable testsuite
* Tue Jun 10 2025 Than Ngo <than@redhat.com> - 3.25.0-1
  - Update to 3.25.0
  - Drop patches which are included in upstream
  - Adapt p11sak patch
  - Fix RPM build warnings
  - Add jq and openssl in Build Requirement, required for testcases
* Tue Apr 29 2025 Than Ngo <than@redhat.com> - 3.24.0-9
  - Fix, opencryptoki doesn't work in image mode
* Wed Mar 12 2025 Than Ngo <than@redhat.com> - 3.24.0-8
  - Fix rpminspect issue
* Thu Feb 27 2025 Than Ngo <than@redhat.com> - 3.24.0-7
  - Fix, opencryptoki tokens are deleted on reboot
* Tue Feb 11 2025 Than Ngo <than@redhat.com> - 3.24.0-6
  - Remove call to
* Tue Feb 04 2025 Than Ngo <than@redhat.com> - 3.24.0-5
  - Use tmpfiles to change file ownership for image mode
* Tue Feb 04 2025 Than Ngo <than@redhat.com> - 3.24.0-4
  - Fix opencryptoki for image mode
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 3.24.0-3
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Sep 13 2024 Than Ngo <than@redhat.com> - 3.24.0-2
  - build with --enable-pkcscca_migrate
  - fix build error due to incompatible pointer types
* Fri Sep 13 2024 Than Ngo <than@redhat.com> - 3.24.0-1
  - Update to 3.24.0
    * Add support for building Opencryptoki on the IBM AIX platform
    * Add support for the CCA token on non-IBM Z platforms (x86_64, ppc64)
    * Add support for protecting tokens with a token specific user group
    * EP11: Add support for combined CKA_EXTRACTABLE and CKA_IBM_PROTKEY_EXTRACTABLE
    * CCA: Add support for Koblitz curve secp256k1. Requires CCA v7.2 or later
    * CCA: Add support for IBM Dilithium (CKM_IBM_DILITHIUM).
      On Linux on IBM Z: Requires CCA v7.1 or later for Round2-65, and CCA v8.0 for the Round 3 variants.
      On other platforms: Requires CCA v7.2.43 or later for Round2-65, the Round 3 variants are currently not supported
    * CCA: Add support for RSA-OAEP with SHA224, SHA384, and SHA512 on en-/decrypt. Requires CCA v8.1 or later on Linux on IBM Z, not supported on other platforms
    * CCA: Add support for PKCS#11 v3.0 SHA3 mechanisms. Requires CCA v8.1 on Linux on IBM Z, not supported on other platforms
    * ICA: Support new libica AES-GCM api using the KMA instruction on z14 and later
    * ICA/Soft/ICSF: Add support for PKCS#11 v3.0 SHA3 mechanisms
    * ICA/Soft: Add support for SHA based key derivation mechanisms
    * ICA/Soft: Add support for CKD_*_SP800 KDFs for ECDH
    * EP11/CCA/ICA/Soft: Add support for CKA_ALWAYS_AUTHENTICATE
    * EP11/CCA: Support live guest relocation for protected key (PKEY) operations
    * Soft: Experimental support for IBM Dilithium via OpenSSL OQS provider
    * ICSF: Add support for SHA-2 mechanisms
    * ICSF: Performance improvements for attribute retrieval
    * p11sak: Add support for exporting a key or certificate as URI-PEM file
    * p11sak: Import/export of IBM Dilithium keys in 'oqsprovider' format PEM files
    * p11sak: Add option to show the master key verification patterns of secure keys
    * Bug fixes
  - Remove i686 support as upsrtream will get rid of 32-bit support, https://github.com/opencryptoki/opencryptoki/issues/174
  - Remove lockdir.patch
* Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.23.0-2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Wed Feb 07 2024 Than Ngo <than@redhat.com> - 3.23.0-1
  - 3.23.0
     * EP11: Add support for FIPS-session mode
     * Updates to harden against RSA timing attacks
     * Bug fixes
* Tue Jan 30 2024 Dan HorĂ¡k <dan[at]danny.cz> - 3.22.0-4
  - fix all errors and warnings (rhbz#2261419)
* Thu Jan 25 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.22.0-3
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.22.0-2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

Files

/etc/opencryptoki
/etc/opencryptoki/opencryptoki.conf
/etc/opencryptoki/p11kmip.conf
/etc/opencryptoki/p11sak_defined_attrs.conf
/etc/opencryptoki/strength.conf
/run/lock/opencryptoki
/run/lock/opencryptoki/ccatok
/run/lock/opencryptoki/icsf
/run/lock/opencryptoki/swtok
/run/opencryptoki
/usr/bin/p11kmip
/usr/bin/p11sak
/usr/bin/pkcsconf
/usr/bin/pkcshsm_mk_change
/usr/bin/pkcsslotd
/usr/bin/pkcsstats
/usr/bin/pkcstok_admin
/usr/bin/pkcstok_migrate
/usr/lib/.build-id
/usr/lib/.build-id/01
/usr/lib/.build-id/01/251f9da031f6135ec9d05ec02292fe471e7e08
/usr/lib/.build-id/22
/usr/lib/.build-id/22/c9221b46760c1188d6321601995459d1198a52
/usr/lib/.build-id/51
/usr/lib/.build-id/51/93283774f2b203cf1eabafa8c58beef83ce18c
/usr/lib/.build-id/6d
/usr/lib/.build-id/6d/c5c5f6fa0562405ef2d1094b2ba3b6a0252f3c
/usr/lib/.build-id/78
/usr/lib/.build-id/78/fa2daf4aa47f33cd98baa66dce7eee0dd53614
/usr/lib/.build-id/8e
/usr/lib/.build-id/8e/5ab49eb4a9ea37b33fd3dc91f37f7f1e2e5a17
/usr/lib/.build-id/99
/usr/lib/.build-id/99/0b907b3302898e45128e5896f4cf0805626ec0
/usr/lib/.build-id/e9
/usr/lib/.build-id/e9/88679d595e4c432cf47be99b8c049e22e091b6
/usr/lib/systemd/system/pkcsslotd.service
/usr/lib/tmpfiles.d/opencryptoki.conf
/usr/lib64/opencryptoki/methods
/usr/lib64/pkcs11/methods
/usr/share/doc/opencryptoki
/usr/share/doc/opencryptoki/ChangeLog
/usr/share/doc/opencryptoki/FAQ
/usr/share/doc/opencryptoki/README.md
/usr/share/doc/opencryptoki/README.token_data
/usr/share/doc/opencryptoki/opencryptoki-howto.md
/usr/share/doc/opencryptoki/policy-example.conf
/usr/share/doc/opencryptoki/strength-example.conf
/usr/share/man/man1/p11kmip.1.gz
/usr/share/man/man1/p11sak.1.gz
/usr/share/man/man1/pkcsconf.1.gz
/usr/share/man/man1/pkcshsm_mk_change.1.gz
/usr/share/man/man1/pkcsstats.1.gz
/usr/share/man/man1/pkcstok_admin.1.gz
/usr/share/man/man1/pkcstok_migrate.1.gz
/usr/share/man/man5/opencryptoki.conf.5.gz
/usr/share/man/man5/p11kmip.conf.5.gz
/usr/share/man/man5/p11sak_defined_attrs.conf.5.gz
/usr/share/man/man5/policy.conf.5.gz
/usr/share/man/man5/strength.conf.5.gz
/usr/share/man/man7/opencryptoki.7.gz
/usr/share/man/man8/pkcsslotd.8.gz
/var/lib/opencryptoki
/var/lib/opencryptoki/HSM_MK_CHANGE


Generated by rpm2html 1.8.1

Fabrice Bellet, Sun Nov 30 22:25:08 2025