Enhancement Advisory openCryptoki enhancement and bug fix update

Advisory: RHEA-2008:0084-3
Type: Product Enhancement Advisory
Severity: N/A
Issued on: 2008-05-21
Last updated on: 2008-05-21
Affected Products: RHEL Desktop Workstation (v. 5 client)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
OVAL: N/A

Details

Enhanced openCryptoki packages that add CCA STDLL and TPM support for IBM
System z and fix several bugs are now available.

The openCryptoki package contains the PKCS#11 Version 2.11 API implemented
for the IBM Crypto cards. This package includes support for the IBM 4758
Cryptographic CoProcessor (with the PKCS#11 firmware loaded) and the IBM
eServer Cryptographic Accelerator (FC 4960 on IBM eServer System p).

These updated openCryptoki packages add the following enhancements:

* IBM System z PKCS#11 support for the secure key functionality of the
xCrypto card through the CCA interface.

* support for the hardware Trusted Platform Module (TPM) has also been added.

In addition, these updated openCryptoki packages provides fixes for the
following bugs:

* openCryptoki would fail to properly close file descriptors which would
lead to open file handle exhaustion in certain situations. These file
handles are now properly closed.

* openCryptoki used the /usr/sbin/pkcs11_startup script to probe for
hardware in the /proc file system and add support for it when it was
available. Because software fallback support is integrated into the libica
package on System z, there was no longer a need for openCryptoki to use
this script to probe for hardware. This obsolete check has thus been removed.

Users of openCryptoki are advised to upgrade to these updated packages,
which add these enhancements and resolve these issues.


Solution

Before applying this update, make sure that all previously-released errata
relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use the Red
Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

RHEL Desktop Workstation (v. 5 client)

IA-32:
openCryptoki-devel-2.2.4-21.el5.i386.rpm     d3c62eb0adb05ca223e5efddd956076e
 
x86_64:
openCryptoki-devel-2.2.4-21.el5.i386.rpm     d3c62eb0adb05ca223e5efddd956076e
openCryptoki-devel-2.2.4-21.el5.x86_64.rpm     05839abe951c6089fe1d4a231cf43996
 
Red Hat Enterprise Linux (v. 5 server)

SRPMS:
openCryptoki-2.2.4-21.el5.src.rpm     911d3f4aeb7eb282e0b74f00f5bf4323
 
IA-32:
openCryptoki-2.2.4-21.el5.i386.rpm     53ab954a8e620a5e72adef83a79bcfc9
openCryptoki-devel-2.2.4-21.el5.i386.rpm     d3c62eb0adb05ca223e5efddd956076e
 
PPC:
openCryptoki-2.2.4-21.el5.ppc64.rpm     3e8a00f39c64c8877eb4a63381d96473
openCryptoki-devel-2.2.4-21.el5.ppc64.rpm     5e830f1362f17e4610ed87ce6c34c441
 
s390x:
openCryptoki-2.2.4-21.el5.s390.rpm     a01a08108ef5a1affcfc5cb48023680a
openCryptoki-2.2.4-21.el5.s390x.rpm     cba9d0d907c4e33c19f45411a286b914
openCryptoki-devel-2.2.4-21.el5.s390x.rpm     7f1642d9dfb38c952cf9563bbe6bb5c5
 
x86_64:
openCryptoki-2.2.4-21.el5.i386.rpm     53ab954a8e620a5e72adef83a79bcfc9
openCryptoki-2.2.4-21.el5.x86_64.rpm     aec20be965f7f50ddbff13ba357aff1f
openCryptoki-devel-2.2.4-21.el5.i386.rpm     d3c62eb0adb05ca223e5efddd956076e
openCryptoki-devel-2.2.4-21.el5.x86_64.rpm     05839abe951c6089fe1d4a231cf43996
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
openCryptoki-2.2.4-21.el5.src.rpm     911d3f4aeb7eb282e0b74f00f5bf4323
 
IA-32:
openCryptoki-2.2.4-21.el5.i386.rpm     53ab954a8e620a5e72adef83a79bcfc9
 
x86_64:
openCryptoki-2.2.4-21.el5.i386.rpm     53ab954a8e620a5e72adef83a79bcfc9
openCryptoki-2.2.4-21.el5.x86_64.rpm     aec20be965f7f50ddbff13ba357aff1f
 
(The unlinked packages above are only available from the Red Hat Network)

Keywords

CCA, fd, leak, lock, spin, STDLL


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/