planned bind-pkcs11 changes in F20+

Tomas Hozza thozza at redhat.com
Thu Sep 25 13:30:08 UTC 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello all.

I would like to inform everyone about changes I plan to do
in Fedora 20+ due to Bug 1097752 (Support for native PKCS#11
interface - needed by FreeIPA).

Currently there is a bind-pkcs11 package which includes
couple of utilities needed for working with PKCS#11.

- From the user feedback I got during the past year or so, utilities
from PKCS#11 didn't work much. I backported the native
PKCS#11 functionality from Bind 9.10 and plan to add/change
the following sub-packages:

bind-pkcs11
 - will contain special version of named (named-pkcs11) which
   is compiled with the native PKCS#11 and doesn't use OpenSSL,
   for crypto, but some HSM.

bind-pkcs11-libs
 - libdns and libisc compiled with native PKCS#11 functionality.
   These will be distributed as libdns-pkcs11 and libisc-pkcs11.

bind-pkcs11-devel
 - development files for the native PKCS#11 versions of libisc
   and libdns.

bind-pkcs11-utils
 - will provide utilities previously provided by the bind-pkcs11
   package. The update path will be solved as described in Packaging
   guidelines. These utilities are compiled with native PKCS#11, too.


If this changes could break someone's setup, please let me know
so we can work on some solution. Otherwise I'll do the changes
some day next week.

Thank you.

Regards,
- -- 
Tomas Hozza
Software Engineer - EMEA ENG Developer Experience

PGP: 1D9F3C2D
Red Hat Inc.                               http://cz.redhat.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBAgAGBQJUJBjZAAoJEMWIetUdnzwti44H/11yHgr1tpvPOYuyqrnP3+wl
UV5yiB5f8ygZdal9IclU7b9F/MrsB/lpsXVmyHHB3tPEF2ed9yTMyhNM3MrAV/pe
Fu8VygUqkiL3ZC1R5jVL/qLK590RO374oLD7UTaHfC1zfu1MnVf3G+2NwtSlXUP1
SAHTU5jCgBf3/9sqykPjuxZ4nwiImpAziMaMrzDzqTVGHmwgO7+W02HVo0wAD9dl
VJbdOL+HXIKQFIHyLDLJq+Zfn+qR06vG2L+aIPkAjkIsOM2ied9TtIuT+NQZQEs0
k0ccAL59Nr1aUtBDaNVWhf+AZ6cZBcWvKxYqooiRh2BaWs4JbWrm81PnIa/a4PU=
=2KjZ
-----END PGP SIGNATURE-----


More information about the devel mailing list