Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-29672

Add custom configuration of pkcs11-provider for RHEL

    • pkcs11-provider-0.5-4.el10
    • 1
    • rhel-sst-security-crypto
    • ssg_security
    • 28
    • 2
    • Yes
    • Crypto24Q3
    • Feature
    • Hide
      .Added custom configuration for `pkcs11-provider`

      The `pkcs11-provider` allows direct access to hardware tokens by using `pkcs11` URIs from OpenSSL programs. Upon installation, the `pkcs11-provider` is automatically enabled and loads tokens detected by the `pcscd` daemon by using the `p11-kit` driver by default. As a result, you can use tokens available to the system if you provide a key URI by using the `pkcs11` URI specification to an application that supports that format by installing the package without the need to further change OpenSSL configuration. Uninstalling the package also removes the OpenSSL configuration snippet, which prevents errors when OpenSSL parses the configuration files.
      Show
      .Added custom configuration for `pkcs11-provider` The `pkcs11-provider` allows direct access to hardware tokens by using `pkcs11` URIs from OpenSSL programs. Upon installation, the `pkcs11-provider` is automatically enabled and loads tokens detected by the `pcscd` daemon by using the `p11-kit` driver by default. As a result, you can use tokens available to the system if you provide a key URI by using the `pkcs11` URI specification to an application that supports that format by installing the package without the need to further change OpenSSL configuration. Uninstalling the package also removes the OpenSSL configuration snippet, which prevents errors when OpenSSL parses the configuration files.
    • Done
    • None

      Goal

      • when pkcs11-provider is installed provide an easy way to enable it in openssl, ideally by deploying a snippet file in the openssl config

        Acceptance Criteria

      • Verify pkcs1-provider can be easily enabled

      NOTE: this requires a little bit of testing to find out what is the best solution.

              rhn-engineering-ssorce Simo Sorce
              rhn-engineering-ssorce Simo Sorce
              Sahana Prasad Hebbur Narasimha Prasad
              Simo Sorce Simo Sorce
              Ondrej Moris Ondrej Moris
              Jan Fiala Jan Fiala
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated: