Compare commits

..

19 Commits

Author SHA1 Message Date
Python Maint 655676c16c Rebuilt for Python 3.14.0rc3 bytecode 2025-09-19 12:35:09 +02:00
Python Maint c6d83b0c57 Rebuilt for Python 3.14.0rc2 bytecode 2025-08-15 13:04:34 +02:00
Fedora Release Engineering 3b4a6e4ac5 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-24 23:42:46 +00:00
Jitka Plesnikova f8a5615d0a Perl 5.42 rebuild 2025-07-07 16:23:01 +02:00
Vitezslav Crhonek ea732b9976 Remove STI DSP test 2025-06-25 12:45:12 +02:00
Vitezslav Crhonek 94e2a92bdc Add post-quantum support test 2025-06-25 12:45:04 +02:00
Vitezslav Crhonek f7085bf7cf Update to better support post-quantum cryptography 2025-06-17 14:40:11 +02:00
Python Maint a15c71912a Rebuilt for Python 3.14 2025-06-09 11:44:53 +02:00
Vitezslav Crhonek e7504d677c Remove deprecated path from systemd service file 2025-06-09 09:49:40 +02:00
Python Maint d5b12f392f Rebuilt for Python 3.14 2025-06-03 12:20:17 +02:00
Vitezslav Crhonek 47117d833d Build winrs only when ruby binding is enabled 2025-04-10 14:31:06 +02:00
Vitezslav Crhonek 98cf5bcd84 Update to openwsman-2.8.1 2025-04-07 13:38:27 +02:00
Vitezslav Crhonek 8a58111e8d Update minimum required cmake version 2025-02-28 14:27:25 +01:00
Vitezslav Crhonek d6df136fc0 Fix mixed use of tabs and spaces in specfile 2025-02-28 13:34:54 +01:00
Björn Esser 6862d70ca0 Add explicit BR: libxcrypt-devel
Signed-off-by: Björn Esser <besser82@fedoraproject.org>
2025-02-01 19:56:20 +01:00
Vitezslav Crhonek 531f9577de Fix FTBFS with GCC 15, bin and sbin unification 2025-01-23 12:52:51 +01:00
Fedora Release Engineering c98dedc944 Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-17 21:55:13 +00:00
Mamoru TASAKA d5765d2977 Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.4 2025-01-08 11:07:07 +09:00
Vitezslav Crhonek 053236801c Add rpminspect.yaml 2024-08-30 13:50:15 +02:00
15 changed files with 315 additions and 72 deletions
+1
View File
@@ -0,0 +1 @@
1
+1 -1
View File
@@ -1,2 +1,2 @@
/openwsmand.8.gz
/v2.7.2.tar.gz
/v2.8.1.tar.gz
+1 -1
View File
@@ -6,7 +6,7 @@ diff -up openwsman-2.7.2/bindings/ruby/extconf.rb.orig openwsman-2.7.2/bindings/
major, minor, path = RUBY_VERSION.split(".")
-raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i")
+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.2-build/openwsman-2.7.2/include/ -o openwsman_wrap.c openwsman.i")
+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.8.1-build/openwsman-2.8.1/include -o openwsman_wrap.c openwsman.i")
$CPPFLAGS = "-I/usr/include/openwsman -I.."
+14 -14
View File
@@ -1,6 +1,6 @@
diff -up openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig openwsman-2.7.0/src/server/shttpd/compat_unix.h
--- openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig 2020-05-25 15:16:28.000000000 +0200
+++ openwsman-2.7.0/src/server/shttpd/compat_unix.h 2021-03-09 09:15:26.750942006 +0100
diff -up openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig openwsman-2.8.1/src/server/shttpd/compat_unix.h
--- openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig 2025-01-23 10:23:52.000000000 +0100
+++ openwsman-2.8.1/src/server/shttpd/compat_unix.h 2025-02-03 09:11:35.072818890 +0100
@@ -27,10 +27,6 @@
pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0)
#endif /* !NO_THREADS */
@@ -12,9 +12,9 @@ diff -up openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig openwsman-2.7.0/sr
#define DIRSEP '/'
#define IS_DIRSEP_CHAR(c) ((c) == '/')
#define O_BINARY 0
diff -up openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig openwsman-2.7.0/src/server/shttpd/io_ssl.c
--- openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig 2020-05-25 15:16:28.000000000 +0200
+++ openwsman-2.7.0/src/server/shttpd/io_ssl.c 2021-03-09 09:15:26.750942006 +0100
diff -up openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig openwsman-2.8.1/src/server/shttpd/io_ssl.c
--- openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig 2025-01-23 10:23:52.000000000 +0100
+++ openwsman-2.8.1/src/server/shttpd/io_ssl.c 2025-02-03 09:12:22.387355905 +0100
@@ -11,28 +11,6 @@
#include "defs.h"
@@ -44,10 +44,10 @@ diff -up openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig openwsman-2.7.0/src/ser
void
_shttpd_ssl_handshake(struct stream *stream)
{
diff -up openwsman-2.7.0/src/server/shttpd/shttpd.c.orig openwsman-2.7.0/src/server/shttpd/shttpd.c
--- openwsman-2.7.0/src/server/shttpd/shttpd.c.orig 2020-05-25 15:16:28.000000000 +0200
+++ openwsman-2.7.0/src/server/shttpd/shttpd.c 2021-03-09 09:16:58.843241510 +0100
@@ -1489,25 +1489,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch
diff -up openwsman-2.8.1/src/server/shttpd/shttpd.c.orig openwsman-2.8.1/src/server/shttpd/shttpd.c
--- openwsman-2.8.1/src/server/shttpd/shttpd.c.orig 2025-01-23 10:23:52.000000000 +0100
+++ openwsman-2.8.1/src/server/shttpd/shttpd.c 2025-02-03 09:13:43.415562784 +0100
@@ -1510,25 +1510,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch
int retval = FALSE;
EC_KEY* key;
@@ -73,10 +73,10 @@ diff -up openwsman-2.7.0/src/server/shttpd/shttpd.c.orig openwsman-2.7.0/src/ser
+ OPENSSL_init_ssl(0, NULL);
if ((CTX = SSL_CTX_new(TLS_server_method())) == NULL)
#endif
_shttpd_elog(E_LOG, NULL, "SSL_CTX_new error");
diff -up openwsman-2.7.0/src/server/shttpd/ssl.h.orig openwsman-2.7.0/src/server/shttpd/ssl.h
--- openwsman-2.7.0/src/server/shttpd/ssl.h.orig 2020-05-25 15:16:28.000000000 +0200
+++ openwsman-2.7.0/src/server/shttpd/ssl.h 2021-03-09 09:15:26.750942006 +0100
_shttpd_report_ssl_error("SSL_CTX_new failed", NULL);
diff -up openwsman-2.8.1/src/server/shttpd/ssl.h.orig openwsman-2.8.1/src/server/shttpd/ssl.h
--- openwsman-2.8.1/src/server/shttpd/ssl.h.orig 2025-01-23 10:23:52.000000000 +0100
+++ openwsman-2.8.1/src/server/shttpd/ssl.h 2025-02-03 09:14:43.142975166 +0100
@@ -12,55 +12,4 @@
#include <openssl/ssl.h>
-12
View File
@@ -1,12 +0,0 @@
diff -up openwsman-2.7.2/bindings/openwsman.i.orig openwsman-2.7.2/bindings/openwsman.i
--- openwsman-2.7.2/bindings/openwsman.i.orig 2024-01-22 09:36:42.764721705 +0100
+++ openwsman-2.7.2/bindings/openwsman.i 2024-01-22 09:37:29.970817151 +0100
@@ -109,7 +109,7 @@ SWIGINTERNINLINE SV *SWIG_From_double S
%typemap(in) FILE* {
#if RUBY_VERSION > 18
- struct rb_io_t *fptr;
+ struct rb_io *fptr;
#else
struct OpenFile *fptr;
#endif
+24
View File
@@ -0,0 +1,24 @@
diff -up openwsman-2.8.1/src/plugins/swig/src/target_ruby.c.orig openwsman-2.8.1/src/plugins/swig/src/target_ruby.c
--- openwsman-2.8.1/src/plugins/swig/src/target_ruby.c.orig 2025-01-23 10:23:52.000000000 +0100
+++ openwsman-2.8.1/src/plugins/swig/src/target_ruby.c 2025-02-03 09:30:36.905616375 +0100
@@ -49,7 +49,7 @@
*/
static VALUE
-load_module()
+load_module(VALUE)
{
ruby_script(PLUGIN_FILE);
return rb_require(PLUGIN_FILE);
diff -up openwsman-2.8.1/src/server/CMakeLists.txt.orig openwsman-2.8.1/src/server/CMakeLists.txt
--- openwsman-2.8.1/src/server/CMakeLists.txt.orig 2025-01-23 10:23:52.000000000 +0100
+++ openwsman-2.8.1/src/server/CMakeLists.txt 2025-02-03 09:31:15.258241237 +0100
@@ -48,7 +48,7 @@ IF( HAVE_LIBDL )
TARGET_LINK_LIBRARIES(openwsmand ${DL_LIBRARIES})
ENDIF( HAVE_LIBDL )
-INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/sbin)
+INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/bin)
#
#
+101
View File
@@ -0,0 +1,101 @@
diff -up openwsman-2.7.2/etc/openwsman.conf.orig openwsman-2.7.2/etc/openwsman.conf
--- openwsman-2.7.2/etc/openwsman.conf.orig 2022-12-28 16:43:03.000000000 +0100
+++ openwsman-2.7.2/etc/openwsman.conf 2025-05-27 08:03:57.890057721 +0200
@@ -32,8 +32,12 @@ ipv6 = yes
# the openwsman server certificate file, in .pem format
ssl_cert_file = /etc/openwsman/servercert.pem
+# the openwsman server certificate fallback file, in .pem format
+#ssl_cert_fallback_file = /etc/openwsman/servercert-fallback.pem
# the openwsman server private key, in .pem format
ssl_key_file = /etc/openwsman/serverkey.pem
+# the openwsman server private key fallback, in .pem format
+#ssl_key_fallback_file = /etc/openwsman/serverkey-fallback.pem
# space-separated list of SSL protocols to *dis*able
# possible values: SSLv2 SSLv3 TLSv1 TLSv1_1 TLSv1_2
diff -up openwsman-2.7.2/src/server/shttpd/shttpd.c.orig openwsman-2.7.2/src/server/shttpd/shttpd.c
--- openwsman-2.7.2/src/server/shttpd/shttpd.c.orig 2025-05-21 10:07:40.404532496 +0200
+++ openwsman-2.7.2/src/server/shttpd/shttpd.c 2025-06-12 12:27:44.785904555 +0200
@@ -1491,7 +1491,6 @@ set_ssl(struct shttpd_ctx *ctx, const ch
char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols();
char *ssl_cipher_list = wsmand_options_get_ssl_cipher_list();
int retval = FALSE;
- EC_KEY* key;
/* Initialize SSL crap */
@@ -1510,11 +1509,15 @@ set_ssl(struct shttpd_ctx *ctx, const ch
else
retval = TRUE;
- /* This enables ECDH Perfect Forward secrecy. Currently with just the most generic p256 prime curve */
- key = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
- if (key != NULL) {
- SSL_CTX_set_tmp_ecdh(CTX, key);
- EC_KEY_free(key);
+ /* Add fall back certificate/key pair */
+ if (wsmand_options_get_ssl_cert_fallback_file() &&
+ wsmand_options_get_ssl_key_fallback_file()) {
+ if (SSL_CTX_use_certificate_file(CTX, wsmand_options_get_ssl_cert_fallback_file(), SSL_FILETYPE_PEM) != 1)
+ _shttpd_elog(E_LOG, NULL, "cannot open certificate fallback file %s", pem);
+ else if (SSL_CTX_use_PrivateKey_file(CTX, wsmand_options_get_ssl_key_fallback_file(), SSL_FILETYPE_PEM) != 1)
+ _shttpd_elog(E_LOG, NULL, "cannot open fallback PrivateKey %s", pem);
+ else
+ retval = TRUE;
}
while (ssl_disabled_protocols) {
diff -up openwsman-2.7.2/src/server/wsmand-daemon.c.orig openwsman-2.7.2/src/server/wsmand-daemon.c
--- openwsman-2.7.2/src/server/wsmand-daemon.c.orig 2025-05-27 07:18:16.878974761 +0200
+++ openwsman-2.7.2/src/server/wsmand-daemon.c 2025-05-27 07:22:06.832235764 +0200
@@ -76,8 +76,10 @@ static int use_ipv6 = 0;
#endif
static int use_digest = 0;
static char *ssl_key_file = NULL;
+static char *ssl_key_fallback_file = NULL;
static char *service_path = DEFAULT_SERVICE_PATH;
static char *ssl_cert_file = NULL;
+static char *ssl_cert_fallback_file = NULL;
static char *ssl_disabled_protocols = NULL;
static char *ssl_cipher_list = NULL;
static char *pid_file = DEFAULT_PID_PATH;
@@ -186,7 +188,9 @@ int wsmand_read_config(dictionary * ini)
service_path =
iniparser_getstring(ini, "server:service_path", "/wsman");
ssl_key_file = iniparser_getstr(ini, "server:ssl_key_file");
+ ssl_key_fallback_file = iniparser_getstr(ini, "server:ssl_key_fallback_file");
ssl_cert_file = iniparser_getstr(ini, "server:ssl_cert_file");
+ ssl_cert_fallback_file = iniparser_getstr(ini, "server:ssl_cert_fallback_file");
ssl_disabled_protocols = iniparser_getstr(ini, "server:ssl_disabled_protocols");
ssl_cipher_list = iniparser_getstr(ini, "server:ssl_cipher_list");
use_ipv4 = iniparser_getboolean(ini, "server:ipv4", 1);
@@ -364,6 +368,16 @@ char *wsmand_options_get_ssl_cert_file(v
return ssl_cert_file;
}
+char *wsmand_options_get_ssl_key_fallback_file(void)
+{
+ return ssl_key_fallback_file;
+}
+
+char *wsmand_options_get_ssl_cert_fallback_file(void)
+{
+ return ssl_cert_fallback_file;
+}
+
char *wsmand_options_get_ssl_disabled_protocols(void)
{
return ssl_disabled_protocols;
diff -up openwsman-2.7.2/src/server/wsmand-daemon.h.orig openwsman-2.7.2/src/server/wsmand-daemon.h
--- openwsman-2.7.2/src/server/wsmand-daemon.h.orig 2025-05-27 07:15:56.869002037 +0200
+++ openwsman-2.7.2/src/server/wsmand-daemon.h 2025-05-27 07:18:06.429846617 +0200
@@ -76,6 +76,8 @@ int wsmand_options_get_server_port(void)
int wsmand_options_get_server_ssl_port(void);
char *wsmand_options_get_ssl_key_file(void);
char *wsmand_options_get_ssl_cert_file(void);
+char *wsmand_options_get_ssl_key_fallback_file(void);
+char *wsmand_options_get_ssl_cert_fallback_file(void);
char *wsmand_options_get_ssl_disabled_protocols(void);
char *wsmand_options_get_ssl_cipher_list(void);
int wsmand_options_get_digest(void);
+59 -5
View File
@@ -18,14 +18,14 @@
%global with_perl 0
%global with_python 0
%else
%global with_ruby 1
%global with_ruby 0
%global with_perl 1
%global with_python 1
%endif
Name: openwsman
Version: 2.7.2
Release: 11%{?dist}
Version: 2.8.1
Release: 10%{?dist}
Summary: Open source Implementation of WS-Management
License: BSD-3-Clause AND MIT
@@ -49,7 +49,8 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch
Patch3: openwsman-2.6.2-openssl-1.1-fix.patch
Patch4: openwsman-2.6.5-http-status-line.patch
Patch5: openwsman-2.6.8-update-ssleay-conf.patch
Patch6: openwsman-2.7.2-fix-ftbfs.patch
Patch6: openwsman-2.7.2-gcc15-fix.patch
Patch7: openwsman-2.8.1-post-quantum.patch
BuildRequires: make
BuildRequires: swig
BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel
@@ -66,6 +67,7 @@ BuildRequires: pkgconfig openssl-devel
BuildRequires: cmake
BuildRequires: systemd-units
BuildRequires: gcc gcc-c++
BuildRequires: libxcrypt-devel
%description
Openwsman is a project intended to provide an open-source
@@ -161,6 +163,7 @@ Requires: libwsman1 = %{version}-%{release}
This package provides Perl bindings to access the openwsman client API.
%endif
%if %{with_ruby}
%package winrs
Summary: Windows Remote Shell
Requires: rubygem-%{gem_name} = %{version}-%{release}
@@ -168,6 +171,7 @@ Requires: rubygem-%{gem_name} = %{version}-%{release}
%description winrs
This is a command line tool for the Windows Remote Shell protocol.
You can use it to send shell commands to a remote Windows hosts.
%endif
%if 0%{?with_selinux}
# SELinux subpackage
@@ -257,6 +261,7 @@ rm -f %{buildroot}/%{_libdir}/openwsman/plugins/*.la
rm -f %{buildroot}/%{_libdir}/openwsman/authenticators/*.la
%if %{with_ruby}
[ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsmanplugin.rb
[ -d %{buildroot}/%{ruby_sitelibdir} ] && rm -f %{buildroot}/%{ruby_sitelibdir}/openwsmanplugin.rb
[ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsman.rb
%endif
mkdir -p %{buildroot}%{_sysconfdir}/init.d
@@ -283,6 +288,8 @@ rm -rf %{buildroot}%{gem_instdir}/ext
mkdir -p %{buildroot}%{gem_extdir_mri}
cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/
%else
rm -f %{buildroot}%{_bindir}/winrs
%endif
%if 0%{?with_selinux}
@@ -388,7 +395,7 @@ fi
%dir %{_libdir}/openwsman/plugins
%{_libdir}/openwsman/plugins/*.so
%{_libdir}/openwsman/plugins/*.so.*
%{_sbindir}/openwsmand
%{_bindir}/openwsmand
%{_libdir}/libwsman_server.so.*
%{_mandir}/man8/*
@@ -397,8 +404,10 @@ fi
%{_libdir}/libwsman_clientpp.so.*
%config(noreplace) %{_sysconfdir}/openwsman/openwsman_client.conf
%if %{with_ruby}
%files winrs
%{_bindir}/winrs
%endif
%if 0%{?with_selinux}
%files selinux
@@ -408,6 +417,51 @@ fi
%endif
%changelog
* Fri Sep 19 2025 Python Maint <python-maint@redhat.com> - 2.8.1-10
- Rebuilt for Python 3.14.0rc3 bytecode
* Fri Aug 15 2025 Python Maint <python-maint@redhat.com> - 2.8.1-9
- Rebuilt for Python 3.14.0rc2 bytecode
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 2.8.1-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jul 07 2025 Jitka Plesnikova <jplesnik@redhat.com> - 2.8.1-7
- Perl 5.42 rebuild
* Tue Jun 17 2025 Vitezslav Crhonek <vcrhonek@redhat.com> - 2.8.1-6
- Update to better support post-quantum cryptography
* Mon Jun 09 2025 Python Maint <python-maint@redhat.com> - 2.8.1-5
- Rebuilt for Python 3.14
* Mon Jun 09 2025 Vitezslav Crhonek <vcrhonek@redhat.com> - 2.8.1-4
- Remove deprecated path from systemd service file
* Tue Jun 03 2025 Python Maint <python-maint@redhat.com> - 2.8.1-3
- Rebuilt for Python 3.14
* Thu Apr 10 2025 Vitezslav Crhonek <vcrhonek@redhat.com> - 2.8.1-2
- Build winrs only when ruby binding is enabled
* Mon Apr 07 2025 Vitezslav Crhonek <vcrhonek@redhat.com> - 2.8.1-1
- Update to openwsman-2.8.1
* Fri Feb 28 2025 Vitezslav Crhonek <vcrhonek@redhat.com> - 2.7.2-16
- Update minimum required cmake version
* Sat Feb 01 2025 Björn Esser <besser82@fedoraproject.org> - 2.7.2-15
- Add explicit BR: libxcrypt-devel
* Thu Jan 23 2025 Vitezslav Crhonek <vcrhonek@redhat.com> - 2.7.2-14
- Fix FTBFS with GCC 15, bin and sbin unification
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 2.7.2-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Wed Jan 08 2025 Mamoru TASAKA <mtasaka@fedoraproject.org> - 2.7.2-12
- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.4
* Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org> - 2.7.2-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
+1 -1
View File
@@ -6,7 +6,7 @@ After=syslog.target
Type=forking
ExecStart=/usr/sbin/openwsmand -S
ExecStartPre=/etc/openwsman/owsmantestcert.sh
PIDFile=/var/run/wsmand.pid
PIDFile=/run/wsmand.pid
[Install]
WantedBy=multi-user.target
+9
View File
@@ -0,0 +1,9 @@
summary: Basic test plan
prepare:
how: install
package:
- openwsman-server
discover:
how: fmf
execute:
how: tmt
+5
View File
@@ -0,0 +1,5 @@
---
badfuncs:
allowed:
/usr/sbin/openwsmand:
- inet_ntoa
+1 -1
View File
@@ -1,2 +1,2 @@
SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c
SHA512 (v2.7.2.tar.gz) = ffd6a0d00a00b00e321b2b55e0c77326f5943ca3224eee74c706e53a1c5c44ef0e8b1cfde5d631966769eefd4e567b0db8713085b7a8b386c2871ab4ada83046
SHA512 (v2.8.1.tar.gz) = 3c72b6778269186108e48203a9c37f1e4ea8ff532013a80be6af3c6e8d2bf89343233287bc4eb2e955b8db4b7cf6d20818f77423781f6fdb52a6317a7e8bc972
+6
View File
@@ -0,0 +1,6 @@
summary: Post-quantum cryptography support test
author: Vitezslav Crhonek <vcrhonek@redhat.com>
contact: Vitezslav Crhonek <vcrhonek@redhat.com>
require: patch
duration: 10m
test: ./runtest.sh
+92
View File
@@ -0,0 +1,92 @@
#!/bin/sh -eux
function check_key_and_cert()
{
echo -e "\n===== key info"
ssh-keygen -l -f /etc/openwsman/serverkey.pem || :
file /etc/openwsman/serverkey.pem
echo -e "\n\n\n"
echo -e "\n===== cert info"
openssl x509 -in /etc/openwsman/servercert.pem --text --noout
echo -e "\n\n\n"
}
function test_key_exchange()
{
echo -e "\n===== check that it uses TLS 1.3 and the X25519MLKEM768 key exchange by default if the peer supports it"
openssl s_client -connect localhost:5986 -CAfile /etc/openwsman/servercert.pem </dev/null | tee key-exchange.out
echo -e "\n\n\n"
grep "Negotiated TLS1.3 group: X25519MLKEM768" key-exchange.out
echo -e "\n\n\n"
}
function test_cert_support()
{
echo -e "\n===== check that TLS certificate using ML-DSA works"
openssl s_client -connect localhost:5986 -CAfile /etc/openwsman/servercert.pem </dev/null | tee cert-mldsa.out
echo -e "\n\n\n"
grep "Peer signature type: mldsa65" cert-mldsa.out
echo -e "\n\n\n"
# simulate lack of ML-DSA support
echo "\n===== check support for a classic certificate chain if peer doesn't support ML-DSA certificate"
openssl s_client -connect localhost:5986 -CAfile /etc/openwsman/servercert-fallback.pem </dev/null -sigalgs 'rsa_pss_pss_sha256:rsa_pss_rsae_sha256' </dev/null | \
tee cert-classic.out
echo -e "\n\n\n"
grep "Peer signature type: rsa_pss_rsae_sha256" cert-classic.out
echo -e "\n\n\n"
}
(echo CZ; echo "Czech Republic"; echo Brno; echo "Red Hat"; echo "Core Services"; echo localhost; echo joe@example.com; ) | /etc/openwsman/owsmangencert.sh
systemctl start openwsmand
check_key_and_cert
test_key_exchange
systemctl stop openwsmand
# keep RSA certificate and key
cp /etc/openwsman/servercert.pem /etc/openwsman/servercert-fallback.pem
cp /etc/openwsman/serverkey.pem /etc/openwsman/serverkey-fallback.pem
# remove previously generated certificates/keys
rm -rf /etc/openwsman/{servercert,serverkey}.pem
# update genOpenPegasusSSLCerts to generate a new key using ML-DSA-65
# and issue a self-signed certificate for localhost using this key
patch /etc/openwsman/owsmangencert.sh << 'EOF'
--- /etc/openwsman/owsmangencert.sh.orig 2025-06-25 04:03:22.295778704 -0400
+++ /etc/openwsman/owsmangencert.sh 2025-06-25 04:05:12.181435542 -0400
@@ -26,7 +26,7 @@
# certificate is created
openssl req -days 365 $@ -config $CNFFILE \
- -newkey rsa:2048 -x509 -nodes -out $CERTFILE \
+ -newkey mldsa65 -x509 -nodes -out $CERTFILE \
-keyout $KEYFILE
chmod 600 $KEYFILE
EOF
(echo CZ; echo "Czech Republic"; echo Brno; echo "Red Hat"; echo "Core Services"; echo localhost; echo joe@example.com; ) | /etc/openwsman/owsmangencert.sh
# update config file
patch /etc/openwsman/openwsman.conf << 'EOF'
--- openwsman.conf.orig 2025-06-05 07:50:30.285822838 -0400
+++ openwsman.conf 2025-06-05 07:50:38.609822838 -0400
@@ -33,11 +33,11 @@
# the openwsman server certificate file, in .pem format
ssl_cert_file = /etc/openwsman/servercert.pem
# the openwsman server certificate fallback file, in .pem format
-#ssl_cert_fallback_file = /etc/openwsman/servercert-fallback.pem
+ssl_cert_fallback_file = /etc/openwsman/servercert-fallback.pem
# the openwsman server private key, in .pem format
ssl_key_file = /etc/openwsman/serverkey.pem
# the openwsman server private key fallback, in .pem format
-#ssl_key_fallback_file = /etc/openwsman/serverkey-fallback.pem
+ssl_key_fallback_file = /etc/openwsman/serverkey-fallback.pem
# space-separated list of SSL protocols to *dis*able
# possible values: SSLv2 SSLv3 TLSv1 TLSv1_1 TLSv1_2
EOF
systemctl start openwsmand
check_key_and_cert
test_cert_support
-37
View File
@@ -1,37 +0,0 @@
- hosts: localhost
roles:
- role: standard-test-beakerlib
tags:
- classic
repositories:
- repo: https://pagure.io/DSP_test.git
dest: DSP_test
version: master
tests:
- DSP_test
environment:
# RPM package containing the policy module
TEST_RPM: openwsman-selinux
# policy module name
TEST_POLICY: openwsman
# policy sources will be extracted from corresponding .src.rpm
# policy tar filename regexp (e.g. "usbguard-selinux*.tar.gz")
# or empty string if policy sources are not inside a tar archive
POLICY_TAR: ''
# path to policy sources (in of the tar archive) -- <POLICY_TAR>/<POLICY_PATH>/<TEST_POLICY>.(te|if|fc)
# or path in the src.rpm if there is no tar archive -- <src.rpm>/<POLICY_PATH>/<TEST_POLICY>.(te|if|fc)
# can contain wildcards (e.g. for versions etc.)
POLICY_PATH: .
required_packages:
- policycoreutils
- selinux-policy
- selinux-policy-targeted
- setools-console
- libselinux-utils
- rpm
- tar
- git
- openwsman-server