summaryrefslogtreecommitdiff
path: root/usr/src/cmd/cmd-crypto
AgeCommit message (Collapse)AuthorFilesLines
2022-03-1014443 resection manual pages per IPD4Richard Lowe5-8/+7
Reviewed by: Toomas Soome <tsoome@me.com> Reviewed by: Robert Mustacchi <rm@fingolfin.org> Reviewed by: Peter Tribble <peter.tribble@gmail.com> Reviewed by: Andy Fiddaman <andy@omnios.org> Approved by: Dan McDonald <danmcd@joyent.com>
2021-05-0413762 stop passing MFLAGS to make(1)Richard Lowe1-1/+1
Reviewed by: Toomas Soome <tsoome@me.com> Reviewed by: Andy Fiddaman <andy@omnios.org> Reviewed by: Jason King <jason.brian.king@gmail.com> Approved by: Dan McDonald <danmcd@joyent.com>
2020-02-0512217 add ld assert-deflib and guidance to gate buildToomas Soome3-7/+3
Reviewed by: Robert Mustacchi <rm@fingolfin.org> Reviewed by: Gergő Mihály Doma <domag02@gmail.com> Approved by: Dan McDonald <danmcd@joyent.com>
2019-08-1611528 Makefile.noget can get goneJohn Levon4-4/+4
11529 Use -Wno-maybe-initialized Reviewed by: Peter Tribble <peter.tribble@gmail.com> Reviewed by: Toomas Soome <tsoome@me.com> Approved by: Robert Mustacchi <rm@joyent.com>
2019-07-0911304 cmd-crypto: NULL pointer errorsToomas Soome7-16/+16
Reviewed by: Garrett D'Amore <garrett@damore.org> Approved by: Dan McDonald <danmcd@joyent.com>
2019-02-2010124 smatch fixes for cryptoadmJohn Levon3-2/+7
Reviewed by: Andy Stormont <astormont@racktopsystems.com> Reviewed by: Gergő Doma <domag02@gmail.com> Approved by: Robert Mustacchi <rm@joyent.com>
2019-01-3010126 smatch fix for kmfcfgJohn Levon1-7/+12
Reviewed by: Peter Tribble <peter.tribble@gmail.com> Reviewed by: Andy Stormont <astormont@racktopsystems.com> Reviewed by: Gergő Doma <domag02@gmail.com> Approved by: Dan McDonald <danmcd@joyent.com>
2019-01-1410080 smatch Makefile changes for usr/src/cmdJohn Levon1-1/+5
Reviewed by: Andy Fiddaman <andy@omniosce.org> Approved by: Robert Mustacchi <rm@joyent.com>
2018-12-0510020 cmd-crypto: macro expands to multiple statementsToomas Soome1-7/+8
Reviewed by: Robert Mustacchi <rm@joyent.com> Reviewed by: C Fraire <cfraire@me.com> Approved by: Richard Lowe <richlowe@richlowe.net>
2018-02-279200 tpmadm says "restart Solaris"Andy Fiddaman1-4/+5
Reviewed by: Igor Kozhukhov <igor@dilos.org> Reviewed by: C Fraire <cfraire@me.com> Reviewed by: Michal Nowak <mnowak@startmail.com> Reviewed by: Hans Rosenfeld <rosenfeld@grumpf.hope-2000.org> Reviewed by: Garrett D'Amore <garrett@damore.org> Approved by: Dan McDonald <danmcd@joyent.com>
2017-05-278194 kmfcfg: case value not in enumerated typeToomas Soome1-1/+6
Reviewed by: Marcel Telka <marcel@telka.sk> Reviewed by: Robert Mustacchi <rm@joyent.com> Approved by: Gordon Ross <gordon.w.ross@gmail.com>
2017-05-118193 pktool: misleading-indentationToomas Soome1-53/+53
Reviewed by: Andrew Stormont <andyjstormont@gmail.com> Reviewed by: Marcel Telka <marcel@telka.sk> Approved by: Richard Lowe <richlowe@richlowe.net>
2015-02-165591 initialisation inversion of component order in cmd-crypto/elfsign.cRichard PALO15-54/+50
5620 cstyle updates for cmd/cmd-crypto and lib/libkmf Reviewed by: Dan McDonald <danmcd@omniti.com> Reviewed by: David Höppner <0xffea@gmail.com> Reviewed by: Josef "Jeff" Sipek <jeffpc@josefsipek.net> Approved by: Dan McDonald <danmcd@omniti.com>
2013-10-234027 remove CLOSED_BUILDJosef 'Jeff' Sipek1-6/+0
4028 remove CLOSED_IS_PRESENT 4029 remove tonic build bits Reviewed by: Andy Stormont <andyjstormont@gmail.com> Reviewed by: Richard Lowe <richlowe@richlowe.net> Approved by: Richard Lowe <richlowe@richlowe.net>
2013-08-304072 make clobber leaves trashGordon Ross1-0/+2
Reviewed by: Albert Lee <trisk@nexenta.com> Reviewed by: Dan McDonald <danmcd@nexenta.com> Reviewed by: Marcel Telka <marcel.telka@nexenta.com> Reviewed by: Richard Lowe <richlowe@richlowe.net> Approved by: Garrett D'Amore <garrett@damore.org>
2013-08-163915 Add adjuncts support to the buildKeith M Wesolowski3-3/+4
Reviewed by: Robert Mustacchi <rm@joyent.com> Reviewed by: Richard Lowe <richlowe@richlowe.net> Approved by: Dan McDonald <danmcd@nexenta.com>
2013-07-163887 Enlarge data buffer in digest/mac to boost performanceDavid Höppner1-1/+5
Reviewed by: Saso Kiselkov <skiselkov.ml@gmail.com> Reviewed by: Garrett D'Amore <garrett@damore.org> Approved by: Dan McDonald <danmcd@nexenta.com>
2012-11-063310 root CA certs should be removed from illumos-gatePaul B. Henson146-3950/+2
Reviewed by: Garrett D'Amore <garrett@damore.org> Approved by: Dan McDonald <danmcd@nexenta.com>
2012-09-222933 compiler warning gags need better granularityRichard Lowe4-4/+9
Reviewed by: Eric Schrock <eric.schrock@delphix.com> Approved by: Garrett D'Amore <garrett@damore.org>
2012-04-241665 Illumos wont build against openssl 1.0.0Theo Schlossnagle1-1/+4
Reviewed by: Robert Mustacchi <rm@joyent.com> Reviewed by: Keith Wesolowski <keith.wesolowski@joyent.com> Reviewed by: Joshua M. Clulow <josh@sysmgr.org> Approved by: Albert Lee <trisk@nexenta.com>
2012-02-022111 begone, pkcs11_kms!Joshua M. Clulow3-223/+0
Reviewed by: Alexander Eremin <alexander.eremin@nexenta.com> Reviewed by: Jason King <jason.brian.king@gmail.com> Reviewed by: Garrett D'Amore <garrett@damore.org> Approved by: Richard Lowe <richlowe@richlowe.net>
2012-02-182077 lots of unreachable breaks in illumos gateMilan Jurik7-13/+7
Reviewed by: Dan McDonald <danmcd@nexenta.com> Reviewed by: Garrett D'Amore <garrett@damore.org> Approved by: Richard Lowe <richlowe@richlowe.net>
2011-05-181760 constant condition in elfsign annoys GCCRichard Lowe1-3/+1
Reviewed by: Dan McDonald <danmcd@nexenta.com> Reviewed by: Gordon Ross <gwr@nexenta.com> Approved by: Eric Schrock <eric.schrock@delphix.com>
2011-09-031445 Stop trusting the diginotar certRichard Lowe2-33/+0
Reviewed by: Gordon Ross <gwr@nexenta.com> Reviewed by: Dan McDonald <danmcd@nexenta.com> Approved by: Garrett D'Amore <garrett@nexenta.com>
2010-09-126 Need open kcfdGarrett D'Amore9-751/+22
Reviewed by: gwr@nexenta.com, richlowe@richlowe.net, matt@greenviolet.net Approved by: richlowe@richlowe.net
2010-08-096974684 libpkcs11 performance can be improved with less restrictive dlopen() ↵Valerie Bubb Fenwick1-1/+6
flags 6975112 libpkcs11 shouldn't try to dlclose its own metaslot
2010-07-286959099 T2 Crypto Drivers (ncp, n2cp, n2rng) need to implement self tests ↵Misaki Miyashita5-29/+451
for FIPS 140-2 compliance
2010-07-27PSARC 2010/269 KMF Certificate Validation EnhancementsWyllys Ingersoll5-8/+11
6963018 kmf_validate_cert should put more flags into the output attribute in case of an error 6939226 allow one KMF session to choose from multiple trusted anchors to validate a certificate
2010-07-226970482 cryptoadm cores when listing CKM_AES_CBC mechanismDarren J Moffat1-18/+19
2010-06-28PSARC 2010/195 PKCS11 KMS ProviderWyllys Ingersoll3-3/+225
6944296 Solaris needs a PKCS#11 provider to allow access to KMS keystore functionality
2010-06-25PSARC 2009/430 Default system CA (X.509) CertificatesHai-May Chao142-6/+3725
6661895 /etc/sfw/openssl/certs has no well known CA certificates
2010-06-11PSARC/2010/177 KMF Certificate Name mapping extensionsJan Pechanec5-25/+177
PSARC/2010/178 KMF Common Name Mapper 6942888 KMF should provide certificate to name mapping capabilities 6949176 KMF cert-to-name mapping framework needs a CN mapper
2010-06-086954451 pktool list does not pass user creds to KMF correctlyWyllys Ingersoll1-4/+3
2010-05-04PSARC/2010/146 EOF unnecessary elfsign and kCF optionsValerie Bubb Fenwick1-417/+9
6855881 clean up unnecessary technology from elfsign and kcf
2010-04-236944179 kmf_sign_cert needs more info about signing algorithmWyllys Ingersoll7-68/+64
6944121 KMF should add Basic-Constraint when keyCertSign EKU is set 6943253 pktool should ask to overwrite a CSR file if it already exists 6943234 pktool online help wrongly suggests we can delete a key based on its subject-DN 6940180 certClass should be called privClass (or just class) in KMFPK11_FindPrikeyByCert() 6940146 kmf_sign_data() returns KMF_ERR_INTERNAL but the PKCS#11 plugin returns KMF_ERR_MISSING_ERRCODE 6938522 kmf_openssl.so.1 clobbers OpenSSL locking callbacks
2010-03-22PSARC 2010/032 EC and SHA2 for KMFWyllys Ingersoll9-373/+937
6902640 pktool/KMF needs to support ECDSA keys and certificates 6787016 pktool can offer the ability to generate RSA keypairs
2010-02-266927569 cryptoadm unload doesn't perform as expected on freshly-installed ↵Dan OpenSolaris Anderson1-15/+28
systems
2010-01-196910806 Remove warning after enabling fips by cryptoadmHai-May Chao1-5/+1
2010-01-086862532 "cryptoadm: failed to parse configuration" errorDan OpenSolaris Anderson2-37/+59
6353443 domestic (crypt) source build leaves stuff it shouldn't 6818180 mac(1) printed "invalid key" error message when user input an invalid passphrase
2009-12-036857427 remove the unused key and certificate files from the gateValerie Bubb Fenwick2-51/+1
2009-11-166895727 tpmadm command needs to set prompts correctly for auth commandScott Rotondo3-29/+55
2009-11-056897371 cryptoadm needs changes in order to support fips-140 mode in local zonesHai-May Chao7-222/+148
6897374 Memory leaking in kernel algorithm modules and softtoken dsa with fips enabled
2009-10-236894413 tpmadm needs more explanation in its error messagesScott Rotondo1-0/+15
2009-10-206889197 libkmf uses realloc incorrectlyWyllys Ingersoll1-0/+5
6889730 pktool fails to add EKUs to CSR and Cert requests 6889224 pktool incorrectly generates SAN
2009-10-086887337 pktool gencert should use SHA1 instead of MD5Wyllys Ingersoll3-7/+7
2009-10-07PSARC/2009/447 Kernel Cryptographic Framework support for FIPS 140-2Anthony Scarpino1-6/+4
6703950 Solaris cryptographic framework needs to implement changes for FIPS-140-2 compliance
2009-09-286606040 elfsign should use new KMF APIsJohn.Zolnowsky@Sun.COM1-53/+95
2009-09-11PSARC 2009/347 cryptoadm(1M) enhancement for FIPS-140 modeHai-May Chao7-243/+612
6787364 Administration and policy configuration changes to support FIPS 140-2 6867384 Solaris Crypto Framework needs to implement self tests for FIPS 140-2 compliance
2009-09-026796585 Array overrun in libkmfWyllys Ingersoll1-2/+8
6874082 KMF fails to create generic AES keys for NSS 6869630 pktool export is broken after CR 6860037 was integrated
2009-08-196855414 Deliver SPARC support for TPMWyllys Ingersoll2-13/+6
6865428 pkcs11_tpm should be installed by default, or it won't be used