Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-10590

Fix Luna HSM PKCS#11 wrapping mechanism

XMLWordPrintable

    • DFG Security: UC Sprint 102, DFG Security: UC Sprint 103, DFG Security: UC Sprint 104, DFG Security: UC Sprint 105

      The default backend configuration for Thales Luna Network HSM uses a key-wrapping mechanism that is no longer supported in newer versions of the HSM firmware.  This was reported upstream in a Launchpad bug: https://bugs.launchpad.net/barbican/+bug/2036506

      Barbican PKCS#11 code needs to be modified so that we can configure a different key wrapping mechanism - the current one is hard-coded.  Preferably we should use a NIST approved mechanism.  I.e. CKM_WRAPKEY_AES_KWP - https://thalesdocs.com/gphsm/ptk/5.9.1/docs/Content/PTK-C_Program/PTK-C_Mechs/CKM_WRAPKEY_AES_KWP.htm

       

              dmendiza Douglas Mendizabal
              dwilde@redhat.com Dave Wilde
              rhos-dfg-security
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: