[24.10 FEAT] [SEC2356] openCryptoki ep11 token: support protected keys for extractable keys
Bug #2050018 reported by
bugproxy
This bug affects 1 person
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| Ubuntu on IBM z Systems |
Fix Released
|
High
|
Skipper Bug Screeners | ||
| opencryptoki (Ubuntu) |
Fix Released
|
Undecided
|
Frank Heimes | ||
Bug Description
With version 4.1 of the ep11 support program key may based on a new control point have both the CKA_EXTRACTABLE and the CKA_PROT_
With this support also the value ENABLED for the PKEY_MODE attribute in the EP11 config file. If the linked ep11 library has a version smaller than 4.1 then the semantics of the ENABLED attribute value should be set to the semantics of the ENABLE4NONEXTR.
| tags: | added: architecture-s39064 bugnameltc-204745 severity-high targetmilestone-inin2404 |
| Changed in ubuntu: | |
| assignee: | nobody → Skipper Bug Screeners (skipper-screen-team) |
| affects: | ubuntu → linux (Ubuntu) |
| affects: | linux (Ubuntu) → opencryptoki (Ubuntu) |
| Changed in ubuntu-z-systems: | |
| assignee: | nobody → Skipper Bug Screeners (skipper-screen-team) |
| Changed in opencryptoki (Ubuntu): | |
| assignee: | Skipper Bug Screeners (skipper-screen-team) → nobody |
| Changed in ubuntu-z-systems: | |
| importance: | Undecided → High |
| tags: |
added: targetmilestone-inin2410 removed: targetmilestone-inin2404 |
| Changed in ubuntu-z-systems: | |
| status: | Incomplete → Triaged |
| Changed in opencryptoki (Ubuntu): | |
| status: | Expired → Triaged |
| Changed in ubuntu-z-systems: | |
| status: | Triaged → Fix Committed |
| Changed in opencryptoki (Ubuntu): | |
| status: | Triaged → Fix Committed |
| information type: | Private → Public |
| Changed in opencryptoki (Ubuntu): | |
| assignee: | nobody → Frank Heimes (fheimes) |
| Changed in ubuntu-z-systems: | |
| status: | Fix Committed → Fix Released |
| tags: | added: petest-440 |
To post a comment you must log in.

Thanks for raising this.
Is the opencryptoki version already known where this should land in?