[tpm2] [RELEASE] tpm2-pkcs11 version 1.7.0
Roberts, William C <william.c.roberts at intel.com>
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | <SN6PR11MB34371331F2542B55EC1ADFA4B8A79@SN6PR11MB3437.namprd11.prod.outlook.com> |
Hello, I would like to announce tpm2-pkcs11 version 1.7.0 with the following changelog: 1.7.0 - 2021-09-27 * DB Schema Change from 5 to 7. - **Backup your DB before upgrading** * Fixed compilation issues with GCC11. * Fixed errors on releases due to newer compilers from failing by only adding `-Werror` for non-release builds. * Fixed error message when the DB is too new in tpm2\_ptool. * Added support for tpm2\_ptool import with ssh-keygen format keys. Note: Requires cryptography >= 3.0. * Changed default long level from error to warning. * Added better error message for FAPI backend errors along with [docs/FAPI.md](docs/FAPI.md) document. * Changed `tpm2_ptool` make `--algorithm` optional. * Fixed error message of wrong attribute name on expected attribute check to be false. * Added support for ECDSA 256, 384 and 512. * Fixed a bug in the Python code DB upgrade path from 4 to 5 where it didn't add AES mode CTR to CKA\_ALLOWED\_MECHANISMS. * Added tpm2\_ptool support for ECC key size 192. * Added support passwordless login for tokens, ie not setting CKF\_LOGIN\_REQUIRED. * Fixed Running integration tests when Java version has the `-ea`, like on Debian 11 and OpenJDK 17. * Added support for HMAC keys using tpm2\_ptool and the C\_Sign and C\_Verify interfaces. The following interfaces in ptool have support: - addkey: previous working versions of tpm2-tools will support this. - link: previous working versions of tpm2-tools will support this. - import: requires tpm2-tools 5.2+ for support. * Fixed leaking of temp file descriptors in tpm2\_ptool. * Fixed wrong free in tpm code, should use Esys\_Free. * Fixed a space formatting issue in tpm2\_ptool verify. * Fixed leaked file descriptor in tpm2\_ptool. * Fixed a few suspicious sizeof usages in str\_padded\_copy * Fixed a memory leak of the token list on a failure condition in initialization. The release can be found here: - https://github.com/tpm2-software/tpm2-pkcs11/releases/tag/1.7.0 Thanks, Bill