diff --git a/releasenotes/notes/fix-bug-2036506-bf171b5949495457.yaml b/releasenotes/notes/fix-bug-2036506-bf171b5949495457.yaml index f1853b555..b8a354aac 100644 --- a/releasenotes/notes/fix-bug-2036506-bf171b5949495457.yaml +++ b/releasenotes/notes/fix-bug-2036506-bf171b5949495457.yaml @@ -1,8 +1,8 @@ --- deprecations: - | - The `[p11_crypto_plugin]hmac_keywrap_mechanism` option has been replaced - by `[p11_crypto_plugin]hmac_mechanism`. This option was renamed to avoid + The ``[p11_crypto_plugin]hmac_keywrap_mechanism`` option has been replaced + by ``[p11_crypto_plugin]hmac_mechanism``. This option was renamed to avoid confusion since this mechanism is only used to sign encrypted data and never used for key wrap encryption. security: @@ -14,9 +14,10 @@ security: Version 3.0. fixes: - | - Fixed Bug #2036506 - This patch replaces the hard-coded CKM_AES_CBC_PAD - mechanism used to wrap pKEKs with an option to configure this mechanism. - Two new options have been added to the [p11_crypto_plugin] section of the - configuration file: `key_wrap_mechanism` and `key_wrap_generate_iv`. These - options default to `CKM_AES_CBC_PAD` and `True` respectively to preserve - backwards compatibility. + Bug `#2036506 `_: + Replaced the hard-coded CKM_AES_CBC_PAD mechanism used to wrap pKEKs with + an option to configure this mechanism. + Two new options have been added to the ``[p11_crypto_plugin]`` section of + the configuration file: ``key_wrap_mechanism`` and + ``key_wrap_generate_iv``. These options default to ``CKM_AES_CBC_PAD`` + and ``True`` respectively to preserve backwards compatibility.