Comment 40 for bug 1973296

Revision history for this message
Frank Heimes (fheimes) wrote :

Great! Many thx for testing these add. two cases - much appreciated!

A "strength.conf" file is neither incl. in the opencryptoki packages (other than as strength-example.conf) nor copied over or renamed.
I just double-checked it with the non-proposed packages in focal, impish and jammy, as well with the -proposed packages for these releases - so that's just like it is and no regression.

Since it's just a sample (that may not fit for all use cases), one needs to copy it manually, like mentioned in the header of strength-example.conf:
"
# Move/copy to /etc/opencryptoki/strength.cfg to use it with opencryptoki.
# Then chown it to root:pkcs11 and chmod it to 0640.
"

(
It's btw. a similar approach that we follow like with '/usr/share/doc/openssl-ibmca/examples/openssl.cnf.sample' in package 'openssl-ibmca' that one needs to copy, too.

I remember that we once discussed to change this, but the discussion went nowhere.)

With that, let me thank you again, and I consider this as successfully verified for focal, impish and jammy.

(A potential change on how to handle 'strength.conf' in a different way could be discussed as part of a separate ticket ...)