| ID | 164602 |
| Package Name | opencryptoki |
| Links |
Fedora Package Sources |
Fedora Official Koji Buildsystem |
Rocks RISC-V Koji Buildsystem |
Fedora RISC-V GitHub |
Old Koji Buildsystem
|
| Version | 3.25.0 |
| Release | 4.fc43 |
| Epoch | |
Draft | False |
| Source | git+https://src.fedoraproject.org/rpms/opencryptoki.git#2ac2a1652a65c91a8a22bc67914c31012c75cf76 |
| Summary |
| Description |
| Built by | kojiadmin |
| State |
complete
|
| Volume |
DEFAULT |
| Started | Sun, 09 Nov 2025 12:36:20 CST |
| Completed | Sun, 09 Nov 2025 13:58:36 CST |
| Task | build (f43, /rpms/opencryptoki.git:2ac2a1652a65c91a8a22bc67914c31012c75cf76) |
| Extra | {'source': {'original_url': 'git+https://src.fedoraproject.org/rpms/opencryptoki.git#2ac2a1652a65c91a8a22bc67914c31012c75cf76'}} |
| Tags |
|
| RPMs |
| src | |
|
opencryptoki-3.25.0-4.fc43.src.rpm (info) (download) |
| riscv64 |
|
opencryptoki-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
opencryptoki-devel-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
opencryptoki-icsftok-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
opencryptoki-libs-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
opencryptoki-swtok-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
opencryptoki-debuginfo-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
opencryptoki-debugsource-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
opencryptoki-icsftok-debuginfo-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
opencryptoki-libs-debuginfo-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
opencryptoki-swtok-debuginfo-3.25.0-4.fc43.riscv64.rpm (info) (download)
|
|
| Logs |
|
| Changelog |
* Tue Jul 29 2025 Than Ngo <than@redhat.com> - 3.25.0-4
- Require openssl >= 3.5.1
- Fix incorrect effective group id of pkcsslotd daemon
- Fix covscan findings
- Fix detection of EC curve not supported by OpenSSL-3.5.x
- Fix the image mode issue again as bootc expects to use /run/lock
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 3.25.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue Jun 10 2025 Than Ngo <than@redhat.com> - 3.25.0-2
- Enable testsuite
* Tue Jun 10 2025 Than Ngo <than@redhat.com> - 3.25.0-1
- Update to 3.25.0
- Drop patches which are included in upstream
- Adapt p11sak patch
- Fix RPM build warnings
- Add jq and openssl in Build Requirement, required for testcases
* Tue Apr 29 2025 Than Ngo <than@redhat.com> - 3.24.0-9
- Fix, opencryptoki doesn't work in image mode
* Wed Mar 12 2025 Than Ngo <than@redhat.com> - 3.24.0-8
- Fix rpminspect issue
* Thu Feb 27 2025 Than Ngo <than@redhat.com> - 3.24.0-7
- Fix, opencryptoki tokens are deleted on reboot
* Tue Feb 11 2025 Than Ngo <than@redhat.com> - 3.24.0-6
- Remove call to %sysusers_create_compat
* Tue Feb 04 2025 Than Ngo <than@redhat.com> - 3.24.0-5
- Use tmpfiles to change file ownership for image mode
* Tue Feb 04 2025 Than Ngo <than@redhat.com> - 3.24.0-4
- Fix opencryptoki for image mode
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 3.24.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Sep 13 2024 Than Ngo <than@redhat.com> - 3.24.0-2
- build with --enable-pkcscca_migrate
- fix build error due to incompatible pointer types
* Fri Sep 13 2024 Than Ngo <than@redhat.com> - 3.24.0-1
- Update to 3.24.0
* Add support for building Opencryptoki on the IBM AIX platform
* Add support for the CCA token on non-IBM Z platforms (x86_64, ppc64)
* Add support for protecting tokens with a token specific user group
* EP11: Add support for combined CKA_EXTRACTABLE and CKA_IBM_PROTKEY_EXTRACTABLE
* CCA: Add support for Koblitz curve secp256k1. Requires CCA v7.2 or later
* CCA: Add support for IBM Dilithium (CKM_IBM_DILITHIUM).
On Linux on IBM Z: Requires CCA v7.1 or later for Round2-65, and CCA v8.0 for the Round 3 variants.
On other platforms: Requires CCA v7.2.43 or later for Round2-65, the Round 3 variants are currently not supported
* CCA: Add support for RSA-OAEP with SHA224, SHA384, and SHA512 on en-/decrypt. Requires CCA v8.1 or later on Linux on IBM Z, not supported on other platforms
* CCA: Add support for PKCS#11 v3.0 SHA3 mechanisms. Requires CCA v8.1 on Linux on IBM Z, not supported on other platforms
* ICA: Support new libica AES-GCM api using the KMA instruction on z14 and later
* ICA/Soft/ICSF: Add support for PKCS#11 v3.0 SHA3 mechanisms
* ICA/Soft: Add support for SHA based key derivation mechanisms
* ICA/Soft: Add support for CKD_*_SP800 KDFs for ECDH
* EP11/CCA/ICA/Soft: Add support for CKA_ALWAYS_AUTHENTICATE
* EP11/CCA: Support live guest relocation for protected key (PKEY) operations
* Soft: Experimental support for IBM Dilithium via OpenSSL OQS provider
* ICSF: Add support for SHA-2 mechanisms
* ICSF: Performance improvements for attribute retrieval
* p11sak: Add support for exporting a key or certificate as URI-PEM file
* p11sak: Import/export of IBM Dilithium keys in 'oqsprovider' format PEM files
* p11sak: Add option to show the master key verification patterns of secure keys
* Bug fixes
- Remove i686 support as upsrtream will get rid of 32-bit support, https://github.com/opencryptoki/opencryptoki/issues/174
- Remove lockdir.patch
* Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.23.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Wed Feb 07 2024 Than Ngo <than@redhat.com> - 3.23.0-1
- 3.23.0
* EP11: Add support for FIPS-session mode
* Updates to harden against RSA timing attacks
* Bug fixes
* Tue Jan 30 2024 Dan Horák <dan[at]danny.cz> - 3.22.0-4
- fix all errors and warnings (rhbz#2261419)
* Thu Jan 25 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.22.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 3.22.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Thu Sep 21 2023 Than Ngo <than@redhat.com> - 3.22.0-1
- update to 3.22.0
|