2 Summary: Central Key Manager and utilities
7 Source0: %{name}-%{version}.tar.gz
8 Source1001: key-manager.manifest
9 Source1002: key-manager-listener.manifest
10 Source1003: libkey-manager-client.manifest
11 Source1004: libkey-manager-common.manifest
14 BuildRequires: pkgconfig(dlog)
15 BuildRequires: pkgconfig(openssl)
16 BuildRequires: libattr-devel
17 BuildRequires: pkgconfig(libsmack)
18 BuildRequires: pkgconfig(libsystemd-daemon)
19 BuildRequires: pkgconfig(vconf)
20 BuildRequires: pkgconfig(libsystemd-journal)
21 BuildRequires: pkgconfig(libxml-2.0)
22 BuildRequires: pkgconfig(capi-system-info)
23 BuildRequires: pkgconfig(security-manager)
24 BuildRequires: boost-devel
25 Requires: libkey-manager-common = %{version}-%{release}
29 Central Key Manager daemon could be used as secure storage
30 for certificate and private/public keys. It gives API for
31 application to sign and verify (DSA/RSA/ECDSA) signatures.
33 %package -n key-manager-listener
34 Summary: Package with listener daemon
35 Group: System/Security
36 BuildRequires: pkgconfig(vconf)
37 BuildRequires: pkgconfig(glib-2.0)
38 BuildRequires: pkgconfig(capi-appfw-package-manager)
39 Requires: libkey-manager-client = %{version}-%{release}
41 %description -n key-manager-listener
42 Listener for central key manager. This daemon is responsible for
43 receive notification from dbus about uninstall application
44 and pass them to key-manager daemon.
46 %package -n libkey-manager-common
47 Summary: Central Key Manager (common libraries)
48 Group: Development/Libraries
49 Requires(post): /sbin/ldconfig
50 Requires(postun): /sbin/ldconfig
52 %description -n libkey-manager-common
53 Central Key Manager package (common library)
55 %package -n libkey-manager-client
56 Summary: Central Key Manager (client)
57 Group: Development/Libraries
58 Requires: key-manager = %{version}-%{release}
59 Requires: libkey-manager-common = %{version}-%{release}
60 Requires(post): /sbin/ldconfig
61 Requires(postun): /sbin/ldconfig
63 %description -n libkey-manager-client
64 Central Key Manager package (client)
66 %package -n libkey-manager-client-devel
67 Summary: Central Key Manager (client-devel)
68 Group: Development/Libraries
69 BuildRequires: pkgconfig(capi-base-common)
70 Requires: pkgconfig(capi-base-common)
71 Requires: libkey-manager-client = %{version}-%{release}
73 %description -n libkey-manager-client-devel
74 Central Key Manager package (client-devel)
76 %package -n key-manager-tests
77 Summary: Internal test for key-manager
79 BuildRequires: pkgconfig(libxml-2.0)
81 Requires: key-manager = %{version}-%{release}
83 %description -n key-manager-tests
84 Internal test for key-manager implementation.
86 %package -n key-manager-pam-plugin
87 Summary: CKM login/password module to PAM.
88 Group: Development/Libraries
89 BuildRequires: pam-devel
90 Requires: key-manager = %{version}-%{release}
91 Requires(post): /sbin/ldconfig
92 Requires(postun): /sbin/ldconfig
94 %description -n key-manager-pam-plugin
95 CKM login/password module to PAM.
96 It's used to monitor user login/logout and password change events from PAM.
101 cp -a %{SOURCE1001} .
102 cp -a %{SOURCE1002} .
103 cp -a %{SOURCE1003} .
104 cp -a %{SOURCE1004} .
107 %if 0%{?sec_build_binary_debug_enable}
108 export CFLAGS="$CFLAGS -DTIZEN_DEBUG_ENABLE"
109 export CXXFLAGS="$CXXFLAGS -DTIZEN_DEBUG_ENABLE"
110 export FFLAGS="$FFLAGS -DTIZEN_DEBUG_ENABLE"
114 export LDFLAGS+="-Wl,--rpath=%{_libdir},-Bsymbolic-functions "
116 %cmake . -DVERSION=%{version} \
117 -DCMAKE_BUILD_TYPE=%{?build_type:%build_type}%{!?build_type:RELEASE} \
118 -DCMAKE_VERBOSE_MAKEFILE=ON \
119 %if "%{sec_product_feature_security_mdfpp_enable}" == "1"
120 -DSECURITY_MDFPP_STATE_ENABLE=1 \
122 -DSYSTEMD_UNIT_DIR=%{_unitdir} \
123 -DSYSTEMD_ENV_FILE="/etc/sysconfig/central-key-manager" \
124 -DMOCKUP_SM=%{?mockup_sm:%mockup_sm}%{!?mockup_sm:OFF}
126 make %{?jobs:-j%jobs}
130 mkdir -p %{buildroot}/usr/share/license
131 cp LICENSE %{buildroot}/usr/share/license/%{name}
132 cp LICENSE %{buildroot}/usr/share/license/libkey-manager-client
133 cp LICENSE %{buildroot}/usr/share/license/libkey-manager-control-client
134 mkdir -p %{buildroot}/opt/data/ckm/initial_values
135 mkdir -p %{buildroot}/etc/security/
136 mkdir -p %{buildroot}/usr/share/ckm/scripts
137 cp data/scripts/*.sql %{buildroot}/usr/share/ckm/scripts
138 cp doc/initial_values.xsd %{buildroot}/usr/share/ckm
139 mkdir -p %{buildroot}/usr/share/ckm-db-test
140 cp tests/testme_ver1.db %{buildroot}/usr/share/ckm-db-test/
141 cp tests/testme_ver2.db %{buildroot}/usr/share/ckm-db-test/
142 cp tests/testme_ver3.db %{buildroot}/usr/share/ckm-db-test/
143 cp tests/XML_1_okay.xml %{buildroot}/usr/share/ckm-db-test/
144 cp tests/XML_1_okay.xsd %{buildroot}/usr/share/ckm-db-test/
145 cp tests/XML_1_wrong.xml %{buildroot}/usr/share/ckm-db-test/
146 cp tests/XML_1_wrong.xsd %{buildroot}/usr/share/ckm-db-test/
147 cp tests/XML_2_structure.xml %{buildroot}/usr/share/ckm-db-test/
148 mkdir -p %{buildroot}/etc/gumd/userdel.d/
149 cp data/gumd/10_key-manager.post %{buildroot}/etc/gumd/userdel.d/
152 mkdir -p %{buildroot}%{_unitdir}/multi-user.target.wants
153 mkdir -p %{buildroot}%{_unitdir}/sockets.target.wants
154 ln -s ../central-key-manager.service %{buildroot}%{_unitdir}/multi-user.target.wants/central-key-manager.service
155 ln -s ../central-key-manager-listener.service %{buildroot}%{_unitdir}/multi-user.target.wants/central-key-manager-listener.service
156 ln -s ../central-key-manager-api-control.socket %{buildroot}%{_unitdir}/sockets.target.wants/central-key-manager-api-control.socket
157 ln -s ../central-key-manager-api-storage.socket %{buildroot}%{_unitdir}/sockets.target.wants/central-key-manager-api-storage.socket
158 ln -s ../central-key-manager-api-ocsp.socket %{buildroot}%{_unitdir}/sockets.target.wants/central-key-manager-api-ocsp.socket
159 ln -s ../central-key-manager-api-encryption.socket %{buildroot}%{_unitdir}/sockets.target.wants/central-key-manager-api-encryption.socket
165 systemctl daemon-reload
168 systemctl start central-key-manager.service
173 systemctl restart central-key-manager.service
180 systemctl stop central-key-manager.service
186 systemctl daemon-reload
189 %post -n libkey-manager-client -p /sbin/ldconfig
191 %postun -n libkey-manager-client -p /sbin/ldconfig
193 %post -n key-manager-listener
194 systemctl daemon-reload
197 systemctl start central-key-manager-listener.service
201 systemctl restart central-key-manager-listener.service
204 %preun -n key-manager-listener
207 systemctl stop central-key-manager-listener.service
210 %postun -n key-manager-listener
213 systemctl daemon-reload
217 %files -n key-manager
218 %manifest key-manager.manifest
219 %{_bindir}/key-manager
220 %{_unitdir}/multi-user.target.wants/central-key-manager.service
221 %{_unitdir}/central-key-manager.service
222 %{_unitdir}/central-key-manager.target
223 %{_unitdir}/sockets.target.wants/central-key-manager-api-control.socket
224 %{_unitdir}/central-key-manager-api-control.socket
225 %{_unitdir}/sockets.target.wants/central-key-manager-api-storage.socket
226 %{_unitdir}/central-key-manager-api-storage.socket
227 %{_unitdir}/sockets.target.wants/central-key-manager-api-ocsp.socket
228 %{_unitdir}/central-key-manager-api-ocsp.socket
229 %{_unitdir}/sockets.target.wants/central-key-manager-api-encryption.socket
230 %{_unitdir}/central-key-manager-api-encryption.socket
231 %{_datadir}/license/%{name}
232 %{_datadir}/ckm/scripts/*.sql
234 %{_datadir}/ckm/initial_values.xsd
235 /opt/data/ckm/initial_values/
236 %attr(444, root, root) %{_datadir}/ckm/scripts/*.sql
237 /etc/opt/upgrade/230.key-manager-migrate-dkek.patch.sh
238 /etc/gumd/userdel.d/10_key-manager.post
239 %attr(550, root, root) /etc/gumd/userdel.d/10_key-manager.post
242 %files -n key-manager-listener
243 %manifest key-manager-listener.manifest
244 %{_bindir}/key-manager-listener
245 %{_unitdir}/multi-user.target.wants/central-key-manager-listener.service
246 %{_unitdir}/central-key-manager-listener.service
248 %files -n libkey-manager-common
249 %manifest libkey-manager-common.manifest
250 %{_libdir}/libkey-manager-common.so.*
252 %files -n libkey-manager-client
253 %manifest libkey-manager-client.manifest
254 %{_libdir}/libkey-manager-client.so.*
255 %{_libdir}/libkey-manager-control-client.so.*
256 %{_datadir}/license/libkey-manager-client
257 %{_datadir}/license/libkey-manager-control-client
259 %files -n libkey-manager-client-devel
260 %defattr(-,root,root,-)
261 %{_libdir}/libkey-manager-client.so
262 %{_libdir}/libkey-manager-control-client.so
263 %{_libdir}/libkey-manager-common.so
264 %{_includedir}/ckm/ckm/ckm-manager.h
265 %{_includedir}/ckm/ckm/ckm-manager-async.h
266 %{_includedir}/ckm/ckm/ckm-certificate.h
267 %{_includedir}/ckm/ckm/ckm-control.h
268 %{_includedir}/ckm/ckm/ckm-error.h
269 %{_includedir}/ckm/ckm/ckm-key.h
270 %{_includedir}/ckm/ckm/ckm-password.h
271 %{_includedir}/ckm/ckm/ckm-pkcs12.h
272 %{_includedir}/ckm/ckm/ckm-raw-buffer.h
273 %{_includedir}/ckm/ckm/ckm-type.h
274 %{_includedir}/ckm/ckmc/ckmc-manager.h
275 %{_includedir}/ckm/ckmc/ckmc-control.h
276 %{_includedir}/ckm/ckmc/ckmc-error.h
277 %{_includedir}/ckm/ckmc/ckmc-type.h
278 %{_libdir}/pkgconfig/*.pc
280 %files -n key-manager-tests
281 %defattr(-,root,root,-)
282 %{_bindir}/ckm-tests-internal
283 %{_datadir}/ckm-db-test/testme_ver1.db
284 %{_datadir}/ckm-db-test/testme_ver2.db
285 %{_datadir}/ckm-db-test/testme_ver3.db
286 %{_datadir}/ckm-db-test/XML_1_okay.xml
287 %{_datadir}/ckm-db-test/XML_1_okay.xsd
288 %{_datadir}/ckm-db-test/XML_1_wrong.xml
289 %{_datadir}/ckm-db-test/XML_1_wrong.xsd
290 %{_datadir}/ckm-db-test/XML_2_structure.xml
291 %{_bindir}/ckm_so_loader
293 %files -n key-manager-pam-plugin
294 %defattr(-,root,root,-)
295 %{_libdir}/security/pam_key_manager_plugin.so*