|
|
590d18 |
From 7bcdc22d4e08739837039027f7c939a7469b8110 Mon Sep 17 00:00:00 2001
|
|
|
590d18 |
From: Petr Spacek <pspacek@redhat.com>
|
|
|
590d18 |
Date: Tue, 1 Sep 2015 18:16:06 +0200
|
|
|
590d18 |
Subject: [PATCH] DNSSEC: Wrap master key using RSA OAEP instead of old PKCS
|
|
|
590d18 |
v1.5.
|
|
|
590d18 |
|
|
|
590d18 |
https://fedorahosted.org/freeipa/ticket/5273
|
|
|
590d18 |
|
|
|
590d18 |
Reviewed-By: Martin Basti <mbasti@redhat.com>
|
|
|
590d18 |
---
|
|
|
590d18 |
daemons/dnssec/ipa-ods-exporter | 6 +++---
|
|
|
590d18 |
1 file changed, 3 insertions(+), 3 deletions(-)
|
|
|
590d18 |
|
|
|
590d18 |
diff --git a/daemons/dnssec/ipa-ods-exporter b/daemons/dnssec/ipa-ods-exporter
|
|
|
590d18 |
index e0c88936d5983297483c504d422c8d1ee483b6cf..f30a2253a713d857aa4e7566e52a0a45f7bd50c2 100755
|
|
|
590d18 |
--- a/daemons/dnssec/ipa-ods-exporter
|
|
|
590d18 |
+++ b/daemons/dnssec/ipa-ods-exporter
|
|
|
590d18 |
@@ -53,8 +53,7 @@ KEYTAB_FB = paths.IPA_ODS_EXPORTER_KEYTAB
|
|
|
590d18 |
ODS_SE_MAXLINE = 1024 # from ODS common/config.h
|
|
|
590d18 |
ODS_DB_LOCK_PATH = "%s%s" % (paths.OPENDNSSEC_KASP_DB, '.our_lock')
|
|
|
590d18 |
|
|
|
590d18 |
-# TODO: MECH_RSA_OAEP
|
|
|
590d18 |
-SECRETKEY_WRAPPING_MECH = 'rsaPkcs'
|
|
|
590d18 |
+SECRETKEY_WRAPPING_MECH = 'rsaPkcsOaep'
|
|
|
590d18 |
PRIVKEY_WRAPPING_MECH = 'aesKeyWrapPad'
|
|
|
590d18 |
|
|
|
590d18 |
# DNSKEY flag constants
|
|
|
590d18 |
@@ -294,7 +293,8 @@ def master2ldap_master_keys_sync(log, ldapkeydb, localhsm):
|
|
|
590d18 |
hexlify(mkey_id), hexlify(replica_key_id)))
|
|
|
590d18 |
replica_key = localhsm.replica_pubkeys_wrap[replica_key_id]
|
|
|
590d18 |
keydata = localhsm.p11.export_wrapped_key(mkey_local.handle,
|
|
|
590d18 |
- replica_key.handle, _ipap11helper.MECH_RSA_PKCS)
|
|
|
590d18 |
+ replica_key.handle,
|
|
|
590d18 |
+ wrappingmech_name2id[SECRETKEY_WRAPPING_MECH])
|
|
|
590d18 |
mkey_ldap.add_wrapped_data(keydata, SECRETKEY_WRAPPING_MECH,
|
|
|
590d18 |
replica_key_id)
|
|
|
590d18 |
|
|
|
590d18 |
--
|
|
|
590d18 |
2.5.1
|
|
|
590d18 |
|