Age | Commit message (Collapse) | Author | Files | Lines |
|
PSARC/2010/178 KMF Common Name Mapper
6942888 KMF should provide certificate to name mapping capabilities
6949176 KMF cert-to-name mapping framework needs a CN mapper
|
|
6944121 KMF should add Basic-Constraint when keyCertSign EKU is set
6943253 pktool should ask to overwrite a CSR file if it already exists
6943234 pktool online help wrongly suggests we can delete a key based on its subject-DN
6940180 certClass should be called privClass (or just class) in KMFPK11_FindPrikeyByCert()
6940146 kmf_sign_data() returns KMF_ERR_INTERNAL but the PKCS#11 plugin returns KMF_ERR_MISSING_ERRCODE
6938522 kmf_openssl.so.1 clobbers OpenSSL locking callbacks
|
|
6902640 pktool/KMF needs to support ECDSA keys and certificates
6787016 pktool can offer the ability to generate RSA keypairs
|
|
|
|
6914613 libelfsign still uses deprecated libkmf API
|
|
6894060 libnsl is not lint clean
6894068 libpool is not lint clean
6894073 some zone libs are not lint clean
6913623 some user land components of ON are not ss12u1 lint clean
|
|
|
|
6889730 pktool fails to add EKUs to CSR and Cert requests
6889224 pktool incorrectly generates SAN
|
|
|
|
6874082 KMF fails to create generic AES keys for NSS
6869630 pktool export is broken after CR 6860037 was integrated
|
|
FIPS-140 integrity checking
6851814 tools elfsign is unnecessarily linked against pkcs11_softtoken
|
|
6854979 kmf_pkcs11.so.1 has bad SONAME and versioning
|
|
|
|
6771298 Solaris needs a PKCS11 provider for the TPM
6771289 Solaris needs TCG support
|
|
Contributed by Richard Lowe
6785284 Mapfile versioning rules need to be more visible to gatelings
6800164 Standard file exclusion mechanism needed for Cadmium tools
|
|
6457487 clean up Makefile for cmd/openssl
6686002 move /usr/lib/libkmf and plugins to /lib - PSARC 2007/674
6686004 move libcryptoutil and libelfsign from /usr/lib to /lib - PSARC 2007/674
6700122 cryptosvc should be able to start before filesystem/usr
|
|
6763087 pktool signcsr dumps core in some conditions due to uninitialized variables.
6744183 pktool doesn't accept "KPClientAuth", "KPKdc" or "scLogon" as valid ekus
|
|
|
|
|
|
6686002 move /usr/lib/libkmf and plugins to /lib - PSARC 2007/674
6686004 move libcryptoutil and libelfsign from /usr/lib to /lib - PSARC 2007/674
6700122 cryptosvc should be able to start before filesystem/usr
|
|
6670712 cert of dsa type with key pair can not signcsr of rsa type, viceversa.
6670714 pktool gencert keystore=nss and keytype=dsa FAIL, parameter error
6670715 pktool gencsr keystore=nss and token="install" (something not "internal") core dumped
6670725 pktool signcsr command fails to update the keyusage values.
6699535 pktool operations should not have "dir" option for file-based keystore
6700175 fix for 6654080 is not complete
|
|
--HG--
rename : usr/src/uts/sun4u/rsa/Makefile => deleted_files/usr/src/uts/sun4u/rsa/Makefile
rename : usr/src/uts/sun4u/rsa/mont_mulf.s => usr/src/common/bignum/sun4u/mont_mulf_kernel_v9.s
rename : usr/src/uts/intel/rsa/Makefile.32 => usr/src/uts/intel/bignum/Makefile.32
rename : usr/src/uts/intel/rsa/Makefile.64 => usr/src/uts/intel/bignum/Makefile.64
|
|
|
|
6669357 KMF pkcs11 incorrectly sets some attributes when creating certificates and keys
6679525 [CLI] Subcommands in pktool's help are overtranslated
6680520 pktool needs to prompt for PIN more often
|
|
6648052 pktool(1) could allow certificate signing and verification
6652751 kmf_get_kmf_error_str() doesn't know about KMF_ERR_ATTR_NOT_FOUND
6654080 kmf_verify_data() should use algorithm from the cert if KMF_ALGORITHM_INDEX_ATTR is missing
6654205 kmf_find_prikey_by_cert() should be public
6654910 kmf_validate_cert() won't get over non-existent x509v3 extensions in TA
6660235 Command summary on pktool help should be localizable.
6660622 KMF needs API to determine format of raw data
|
|
has expired (fix lint)
|
|
6643119 kmf_validate_cert() should download CRL only when the previous one has expired
|
|
|
|
6621224 KMF Dynamic Plugin Support
6621231 pktool list keystore=file dir=/tmp/test prints out incorrect output
|
|
6624214 kmf_get_cert_extn can leak memory
6629477 libkmf is crashed in OpenSSL_StoreKey if keytype is not KMF_RSA or KMF_DSA
|
|
|
|
6612173 pktool interactive mode should ask more questions
6612636 pktool delete is inconsistent
6613494 pktool fails creation outkey = in dir= if there is a file/dir in current dir of same name
|
|
|
|
|
|
PSARC 2007/465 pktool symmetric key enhancements
6546405 KMF Interfaces need to be extensible
6547894 pktool should be more detailed
6590232 pktool should import and export generic keys
|
|
6585913 pktool import keystore=nss does not work for PEM encoded certs
|
|
|
|
6467531 nightly(1) needs option to generate OpenSolaris delivery
--HG--
rename : usr/src/pkgdefs/SUNWftpu/copyright => usr/src/cmd/cmd-inet/usr.sbin/in.ftpd/LICENSE
|
|
|
|
|
|
6547853 KMF is too strict about KeyUsage
|
|
|
|
|
|
|
|
|
|
|
|
6537358 KMF should allow CSRs to be created with empty Subject names
|
|
6534811 KMF openssl verify routine should test for NULL hash method.
6534827 KMF_ReadInputFile should not require a handle
|
|
4868006 encrypt(1) and mac(1) needs to support token objects
6517162 pktool genkey needs to support generic secret key
|
|
--HG--
rename : usr/src/lib/libkmf/include/oidsalg.h => deleted_files/usr/src/lib/libkmf/include/oidsalg.h
|