Merge "Fix minor formats of release note"

This commit is contained in:
Zuul 2025-03-28 14:42:18 +00:00 committed by Gerrit Code Review
commit 0acec3c0c0

View File

@ -1,8 +1,8 @@
---
deprecations:
- |
The `[p11_crypto_plugin]hmac_keywrap_mechanism` option has been replaced
by `[p11_crypto_plugin]hmac_mechanism`. This option was renamed to avoid
The ``[p11_crypto_plugin]hmac_keywrap_mechanism`` option has been replaced
by ``[p11_crypto_plugin]hmac_mechanism``. This option was renamed to avoid
confusion since this mechanism is only used to sign encrypted data and
never used for key wrap encryption.
security:
@ -14,9 +14,10 @@ security:
Version 3.0.
fixes:
- |
Fixed Bug #2036506 - This patch replaces the hard-coded CKM_AES_CBC_PAD
mechanism used to wrap pKEKs with an option to configure this mechanism.
Two new options have been added to the [p11_crypto_plugin] section of the
configuration file: `key_wrap_mechanism` and `key_wrap_generate_iv`. These
options default to `CKM_AES_CBC_PAD` and `True` respectively to preserve
backwards compatibility.
Bug `#2036506 <https://bugs.launchpad.net/barbican/+bug/2036506>`_:
Replaced the hard-coded CKM_AES_CBC_PAD mechanism used to wrap pKEKs with
an option to configure this mechanism.
Two new options have been added to the ``[p11_crypto_plugin]`` section of
the configuration file: ``key_wrap_mechanism`` and
``key_wrap_generate_iv``. These options default to ``CKM_AES_CBC_PAD``
and ``True`` respectively to preserve backwards compatibility.