Fix minor formats of release note

This is follow-up of 0d4101fa5da52f242ab0a52955f67769b23485a1 and
fix a few format problems of the release note added by that change.

 - Italic is not quite visible and Bold would be preferred

 - The release note is not associated with individual change we should
   not mention "this change".

 - Add link to bug url so that people can find bug details more
   easily.

Change-Id: Idd83933d14ecbf632b954db0bf898e322616bcde
This commit is contained in:
Takashi Kajinami 2025-03-13 10:40:23 +09:00
parent 4500d9f485
commit 17d9f2add6

View File

@ -1,8 +1,8 @@
--- ---
deprecations: deprecations:
- | - |
The `[p11_crypto_plugin]hmac_keywrap_mechanism` option has been replaced The ``[p11_crypto_plugin]hmac_keywrap_mechanism`` option has been replaced
by `[p11_crypto_plugin]hmac_mechanism`. This option was renamed to avoid by ``[p11_crypto_plugin]hmac_mechanism``. This option was renamed to avoid
confusion since this mechanism is only used to sign encrypted data and confusion since this mechanism is only used to sign encrypted data and
never used for key wrap encryption. never used for key wrap encryption.
security: security:
@ -14,9 +14,10 @@ security:
Version 3.0. Version 3.0.
fixes: fixes:
- | - |
Fixed Bug #2036506 - This patch replaces the hard-coded CKM_AES_CBC_PAD Bug `#2036506 <https://bugs.launchpad.net/barbican/+bug/2036506>`_:
mechanism used to wrap pKEKs with an option to configure this mechanism. Replaced the hard-coded CKM_AES_CBC_PAD mechanism used to wrap pKEKs with
Two new options have been added to the [p11_crypto_plugin] section of the an option to configure this mechanism.
configuration file: `key_wrap_mechanism` and `key_wrap_generate_iv`. These Two new options have been added to the ``[p11_crypto_plugin]`` section of
options default to `CKM_AES_CBC_PAD` and `True` respectively to preserve the configuration file: ``key_wrap_mechanism`` and
backwards compatibility. ``key_wrap_generate_iv``. These options default to ``CKM_AES_CBC_PAD``
and ``True`` respectively to preserve backwards compatibility.