Thales Luna HSM Firmware above v7.4.0 doesnt support CKM_AES_CBC_PAD
Bug #2036506 reported by
Rajiv Mucheli
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Barbican |
New
|
Undecided
|
Unassigned |
Bug Description
Hi,
After discussing with Thales Engineering, Thales Luna HSM Firmware above v7.4.0 doesnt support CKM_AES_CBC_PAD wrapping mechanism. Unless we fix this in Barbican, we cannot upgrade to the latest Thales HSM firmware version.
Can i setup a call with Thales Engineering to discuss this further ?
I also found SoftHSM also doesnt support CKM_AES_CBC_PAD wrapping mechanism, more details are provided here :
https:/
https:/
Please let me know if we need to test on my Thales Luna A790 network device or if further information is required.
Regards,
Rajiv
To post a comment you must log in.
FYI : https:/ /opendev. org/openstack/ barbican/ src/branch/ master/ barbican/ plugin/ crypto/ pkcs11. py#L142
My production is running on Openstack Barbican Zed Release, i am planning to upgrade to Bobcat once the release is available