[pki-devel][PATCH] 0090-First-cut-of-scp03-support.-Supports-the-g-d-smartca.patch
by John Magne
First cut of scp03 support. Supports the g&d smartcafe out of the box.
Developer keyset token operations and key change over supported.
Caveats.
-The diversification step going from master key to card key uses DES3 as required for the token.
-After that point, everything is scp03 to the spec with minor excpetions so far.
Supports 128 bit AES for now. Will resolve this.
Minor config tweaks:
TPS
Symmetric Key Changeover
Use this applet for scp03:
RSA/KeyRecovery/GP211/SCP02/SCP03 applet : 1.5.558cdcff.ijc
TKS:
Symmetric Key Changeover
tks.mk_mappings.#02#03=internal:new_master
tks.defKeySet.mk_mappings.#02#03=internal:new_master
Use the uncommented one because scp03 returns a different key set data string.
ToDo:
-Support the rest of the AES sizes other than 128.
-Support optional RMAC apdu.
-Test and adjust the config capability for other tokens.
-Support AES master key. Right now the standard key ends up creating AES card and session keys.
7 years
[PATCH] pki-tpsd@.service: Use BindsTo= instead of BindTo=
by Timo Aaltonen
From: Timo Aaltonen <tjaalton(a)debian.org>
BindTo is deprecated since a few years:
https://github.com/systemd/systemd/commit/7f2cddae09fd2579ae24434df577bb5...
---
base/tps-client/lib/systemd/system/pki-tpsd@.service | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/base/tps-client/lib/systemd/system/pki-tpsd@.service b/base/tps-client/lib/systemd/system/pki-tpsd@.service
index 6a0d6a3..e93d44c 100644
--- a/base/tps-client/lib/systemd/system/pki-tpsd@.service
+++ b/base/tps-client/lib/systemd/system/pki-tpsd@.service
@@ -1,7 +1,7 @@
[Unit]
Description=PKI Token Processing Server %i
After=pki-tpsd.target
-BindTo=pki-tpsd.target
+BindsTo=pki-tpsd.target
[Service]
Type=forking
--
2.7.4
7 years
[PATCH] 966 Refactored PKIInstance.load().
by Endi Sukma Dewata
The code that loads the password.conf in PKIInstance.load() has
been converted into a general purpose load_properties() method.
A corresponding store_properties() method has been added as well.
Pushed to master under trivial rule.
--
Endi S. Dewata
7 years