Merge "Fix minor formats of release note"
This commit is contained in:
commit
0acec3c0c0
@ -1,8 +1,8 @@
|
||||
---
|
||||
deprecations:
|
||||
- |
|
||||
The `[p11_crypto_plugin]hmac_keywrap_mechanism` option has been replaced
|
||||
by `[p11_crypto_plugin]hmac_mechanism`. This option was renamed to avoid
|
||||
The ``[p11_crypto_plugin]hmac_keywrap_mechanism`` option has been replaced
|
||||
by ``[p11_crypto_plugin]hmac_mechanism``. This option was renamed to avoid
|
||||
confusion since this mechanism is only used to sign encrypted data and
|
||||
never used for key wrap encryption.
|
||||
security:
|
||||
@ -14,9 +14,10 @@ security:
|
||||
Version 3.0.
|
||||
fixes:
|
||||
- |
|
||||
Fixed Bug #2036506 - This patch replaces the hard-coded CKM_AES_CBC_PAD
|
||||
mechanism used to wrap pKEKs with an option to configure this mechanism.
|
||||
Two new options have been added to the [p11_crypto_plugin] section of the
|
||||
configuration file: `key_wrap_mechanism` and `key_wrap_generate_iv`. These
|
||||
options default to `CKM_AES_CBC_PAD` and `True` respectively to preserve
|
||||
backwards compatibility.
|
||||
Bug `#2036506 <https://bugs.launchpad.net/barbican/+bug/2036506>`_:
|
||||
Replaced the hard-coded CKM_AES_CBC_PAD mechanism used to wrap pKEKs with
|
||||
an option to configure this mechanism.
|
||||
Two new options have been added to the ``[p11_crypto_plugin]`` section of
|
||||
the configuration file: ``key_wrap_mechanism`` and
|
||||
``key_wrap_generate_iv``. These options default to ``CKM_AES_CBC_PAD``
|
||||
and ``True`` respectively to preserve backwards compatibility.
|
||||
|
Loading…
x
Reference in New Issue
Block a user