[Rpm-maint] [rpm-software-management/rpm] rpmsign: enable signing files with PKCS11 tokens (PR #4125)

Jeremy Cline notifications at github.com
Wed Mar 11 21:37:33 UTC 2026


@jeremycline commented on this pull request.



> +[[slots]]
+slot = 1
+dbtype = "sqlite"
+dbargs = "${token_dir}/token.sql"
+KRYOPTIC_EOF
+pkcs11-tool --module "${pkcs11_mod}" --init-token \
+  --label "${token_label}" --so-pin "${token_pin}"
+pkcs11-tool --module "${pkcs11_mod}" --init-pin \
+  --login --so-pin "${token_pin}" --pin "${token_pin}"
+pkcs11-tool --module "${pkcs11_mod}" --login \
+  --pin "${token_pin}" --keypairgen --key-type EC:prime256v1 \
+  --id 01 --label "ima-signing"
+
+RPMTEST_CHECK([[
+cp /data/RPMS/hello-2.0-1.x86_64.rpm /tmp/
+rpmsign --addsign --key-id 4344591E1964C5FC --signfiles \

Looks like it's coming from [pkcs11-provider](https://github.com/openssl-projects/pkcs11-provider/blob/1868d02c7ab0c574be5f8b1bb2524fe932b51af1/src/interface.c#L337). There seem to be facilities to [avoid it](https://github.com/openssl-projects/pkcs11-provider/blob/1868d02c7ab0c574be5f8b1bb2524fe932b51af1/src/interface.h#L12) if we wanted to rebuild it for the CI here (unless there's an easier way I'm missing, @simo5).

I'm not really familiar with the knobs for ASAN but I couldn't find a way to turn it off. I don't really want to get in the business of rebuilding pkcs11-provider so maybe the conditional is the least bad option?

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/pull/4125#discussion_r2921126725
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/pull/4125/review/3932679200 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260311/ecb9d462/attachment-0001.htm>


More information about the Rpm-maint mailing list