[21.04 FEAT] zkey integration with EKMF stage1

Bug #1887806 reported by bugproxy
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu on IBM z Systems
Fix Released
High
Skipper Bug Screeners
s390-tools (Ubuntu)
Fix Released
Undecided
Skipper Bug Screeners

Bug Description

zkey integration with EKMF stage1
Will be integrated into s390-tools.
Move imformation will be provided, once available.

bugproxy (bugproxy)
tags: added: architecture-s39064 bugnameltc-183148 severity-high targetmilestone-inin2010
Changed in ubuntu:
assignee: nobody → Skipper Bug Screeners (skipper-screen-team)
affects: ubuntu → linux (Ubuntu)
Revision history for this message
Frank Heimes (fheimes) wrote :

Changing to Incomplete for now, until s390-tools version got released.

affects: linux (Ubuntu) → s390-tools (Ubuntu)
Changed in ubuntu-z-systems:
assignee: nobody → Skipper Bug Screeners (skipper-screen-team)
importance: Undecided → High
status: New → Incomplete
Changed in s390-tools (Ubuntu):
status: New → Incomplete
summary: - [20.10 FEAT] zkey integration with EKMF stage1
+ [21.04 FEAT] zkey integration with EKMF stage1
Revision history for this message
bugproxy (bugproxy) wrote : Comment bridged from LTC Bugzilla

------- Comment From <email address hidden> 2020-08-28 03:25 EDT-------
Feature will not make it in time for 20.10, moved to 21.04

tags: added: targetmilestone-inin2104
removed: targetmilestone-inin2010
information type: Private → Public
Changed in s390-tools (Ubuntu):
status: Incomplete → In Progress
Frank Heimes (fheimes)
Changed in ubuntu-z-systems:
status: Incomplete → In Progress
Revision history for this message
Dimitri John Ledkov (xnox) wrote :

Hi, this is part of 2.15.1 and will be packaged as follows:

New binary packages:

+ libekmfweb-dev:
/usr/include/ekmfweb/ekmfweb.h
/usr/lib/s390x-linux-gnu/libekmfweb.so

+ libekmfweb1:
/usr/lib/s390x-linux-gnu/libekmfweb.so.1
/usr/lib/s390x-linux-gnu/libekmfweb.so.1.0

Additions in s390-tools-zkey:
/etc/zkey/kms-plugins.conf
/usr/libexec/zkey/zkey-ekmfweb.so
/usr/libexec/zkey/zkey-ekmfweb.so

Which depends on libekmfweb1.

All symbols exported by libekmfweb1 and will be monitored for any ABI breaks. Adding new symbols is always ok. When changing existing exported symbols ensure that ABI remains stable. When breaking changes are necessory either bump the soname, or continue to export old implementation of tagged version symbol in the shared library. This way, newly compiled software will use latest interfaces, without breaking any binaries at runtime that were built and linked against prior version of library.

The package will fail to build if ABI is broken in incompatible manner.

Changed in s390-tools (Ubuntu):
status: In Progress → Fix Committed
Frank Heimes (fheimes)
Changed in ubuntu-z-systems:
status: In Progress → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package s390-tools - 2.15.1-0ubuntu2

---------------
s390-tools (2.15.1-0ubuntu2) hirsute; urgency=medium

  * Package libekmfweb library.
  * Do not use /usr/lib64 prefix.

s390-tools (2.15.1-0ubuntu1) hirsute; urgency=medium

  * New upstream release. LP: #1902865, LP: #1902047, LP: #1892824, LP: #1887920, LP: #1887806
  * Drop .triggers, and initramfs override. Triggers to update initramfs
    are desired in both packages that ship hooks.

s390-tools (2.14.0-2ubuntu1) hirsute; urgency=medium

  * Merge from Debian unstable (LP: #1903688). Remaining changes:
    - lower priority to optional
    - add libsnmp-dev, libglib2.0-dev build-deps
    - add support for signed zipl
    - use z Systems branding in descriptions
    - package cpuplugd, osasnmpd, statd, zkey
    - drop ziomon package, shipped in the main package
    - ship zdev in udeb
    - update copyright file
    - fix kernel installer script integration, to skip calling zipl without initrd
    - load monwriter kernel module for mon_statd/mon_fsstatd
    - do not run dumpconf in lxc
    - ziomon change exit code to 0 for version and help
    - add zkey initramfs hook
    - change zkey default back to argon2i
    - drop patch that disables building osasnmpd
    - drop udevadm-path.patch to init script, systemd units are used instead
    - enable hardening
    - enable initramfs & dracut integration
    - setup users/groups for mon_*, iucvterm, zkey
    - install more utilities and zdev initramfs integration
    - setup crashkernel integration
  * Update debian/not-installed file for additional files in debian/tmp
  * debian/rules:
    - drop unneeded "--parallel --with systemd" dh args
    - clean zipl/boot/.stage*.d files
    - avoid dh_installinitramfs to install additional triggers
  * s390-tools.docs: ship CHANGELOG.md (as Debian does)

 -- Dimitri John Ledkov <email address hidden> Wed, 18 Nov 2020 14:23:24 +0000

Changed in s390-tools (Ubuntu):
status: Fix Committed → Fix Released
Frank Heimes (fheimes)
Changed in ubuntu-z-systems:
status: Fix Committed → Fix Released
Revision history for this message
bugproxy (bugproxy) wrote :

------- Comment From <email address hidden> 2020-11-19 08:27 EDT-------
IBM Bugzilla status->closed, Fix Released with H

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.