Changelog for
opencryptoki-debuginfo-3.24.0-2.fc41.x86_64.rpm :
* Fri Sep 13 2024 Than Ngo
- 3.24.0-2- build with --enable-pkcscca_migrate- fix build error due to incompatible pointer types
* Fri Sep 13 2024 Than Ngo - 3.24.0-1- Update to 3.24.0
* Add support for building Opencryptoki on the IBM AIX platform
* Add support for the CCA token on non-IBM Z platforms (x86_64, ppc64)
* Add support for protecting tokens with a token specific user group
* EP11: Add support for combined CKA_EXTRACTABLE and CKA_IBM_PROTKEY_EXTRACTABLE
* CCA: Add support for Koblitz curve secp256k1. Requires CCA v7.2 or later
* CCA: Add support for IBM Dilithium (CKM_IBM_DILITHIUM). On Linux on IBM Z: Requires CCA v7.1 or later for Round2-65, and CCA v8.0 for the Round 3 variants. On other platforms: Requires CCA v7.2.43 or later for Round2-65, the Round 3 variants are currently not supported
* CCA: Add support for RSA-OAEP with SHA224, SHA384, and SHA512 on en-/decrypt. Requires CCA v8.1 or later on Linux on IBM Z, not supported on other platforms
* CCA: Add support for PKCS#11 v3.0 SHA3 mechanisms. Requires CCA v8.1 on Linux on IBM Z, not supported on other platforms
* ICA: Support new libica AES-GCM api using the KMA instruction on z14 and later
* ICA/Soft/ICSF: Add support for PKCS#11 v3.0 SHA3 mechanisms
* ICA/Soft: Add support for SHA based key derivation mechanisms
* ICA/Soft: Add support for CKD_
*_SP800 KDFs for ECDH
* EP11/CCA/ICA/Soft: Add support for CKA_ALWAYS_AUTHENTICATE
* EP11/CCA: Support live guest relocation for protected key (PKEY) operations
* Soft: Experimental support for IBM Dilithium via OpenSSL OQS provider
* ICSF: Add support for SHA-2 mechanisms
* ICSF: Performance improvements for attribute retrieval
* p11sak: Add support for exporting a key or certificate as URI-PEM file
* p11sak: Import/export of IBM Dilithium keys in \'oqsprovider\' format PEM files
* p11sak: Add option to show the master key verification patterns of secure keys
* Bug fixes- Remove i686 support as upsrtream will get rid of 32-bit support, https://github.com/opencryptoki/opencryptoki/issues/174- Remove lockdir.patch
* Thu Jul 18 2024 Fedora Release Engineering - 3.23.0-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Wed Feb 07 2024 Than Ngo - 3.23.0-1- 3.23.0
* EP11: Add support for FIPS-session mode
* Updates to harden against RSA timing attacks
* Bug fixes
* Tue Jan 30 2024 Dan HorĂ¡k - 3.22.0-4- fix all errors and warnings (rhbz#2261419)
* Thu Jan 25 2024 Fedora Release Engineering - 3.22.0-3- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering - 3.22.0-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Thu Sep 21 2023 Than Ngo - 3.22.0-1- update to 3.22.0
* Thu Jul 20 2023 Fedora Release Engineering - 3.21.0-6- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Mon Jul 17 2023 Than Ngo - 3.21.0-5- p11sak tool: slot option does not accept argument 0 for slot index 0- p11sak fails as soon as there reside non-key objects
* Thu May 25 2023 Than Ngo - 3.21.0-4- add verify attributes for opencryptoki.conf to ignore the verification
* Mon May 22 2023 Than Ngo - 3.21.0-3- drop p11_kit_support- fix handling of user name- fix user confirmation prompt behavior when stdin is closed
* Tue May 16 2023 Than Ngo - 3.21.0-2- add missing /var/lib/opencryptoki/HSM_MK_CHANGE
* Mon May 15 2023 Than Ngo - 3.21.0-1- update to 3.21.0
* Tue Feb 14 2023 Than Ngo - 3.20.0-2- migrated to SPDX license
* Mon Feb 13 2023 Than Ngo - 3.20.0-1- update to 3.20.0- drop unnecessary opencryptoki-3.11.0-group.patch
* Wed Feb 08 2023 Than Ngo - 3.19.0-3- Add support of ep11 token for new IBM Z Hardware (IBM z16)
* Thu Jan 19 2023 Fedora Release Engineering - 3.19.0-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Tue Oct 11 2022 Than Ngo - 3.19.0-1- update to 3.19.0
* Wed Sep 14 2022 Florian Weimer - 3.18.0-5- Add missing build dependency on systemd-rpm-macros