barbican + SoftHSM2 + openssl-1.0.2g missing EVP_aes_128_wrap_pad()

Bug #1611393 reported by Alex Kavanagh on 2016-08-09
34
This bug affects 6 people
Affects Status Importance Assigned to Milestone
Barbican
Triaged
Wishlist
Unassigned
OpenStack Barbican Charm
Medium
Unassigned
OpenStack Barbican SoftHSM Charm
Medium
Unassigned

Bug Description

Barbican is written to expect the PKCS#11 library to support AES_WRAP_PAD with 128 bits but unfortunately, SoftHSM2 + openssl-1.0.2g is missing the functions.

The EVP_aes_128_wrap_pad() function does appear in the openssl-1.0.2h candidate and so this bug is to pick up testing when the openssl-1.0.2h library appears in Xenial.

James Page (james-page) on 2016-12-12
Changed in charm-barbican-softhsm:
status: New → Triaged
Changed in charm-barbican:
status: New → Triaged
importance: Undecided → Medium
Changed in charm-barbican-softhsm:
importance: Undecided → Medium

The Barbican team would like the PKCS#11 plugin to work with SoftHSM if there are users interested in deploying with that configuration. We would be open to reviewing patches if someone wants to develop a bugfix for this.

Changed in barbican:
status: New → Triaged
importance: Undecided → Medium
importance: Medium → Wishlist
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers