66ec3de347c914c3e6eeee4af559629ab3d9fde2
[platform/core/security/key-manager.git] / packaging / key-manager.spec
1 Name:       key-manager
2 Summary:    Central Key Manager and utilities
3 Version:    0.1.16
4 Release:    1
5 Group:      System/Security
6 License:    Apache-2.0
7 Source0:    %{name}-%{version}.tar.gz
8 Source1001: key-manager.manifest
9 Source1002: key-manager-pam-plugin.manifest
10 Source1003: key-manager-listener.manifest
11 Source1004: libkey-manager-client.manifest
12 Source1005: libkey-manager-common.manifest
13 BuildRequires: cmake
14 BuildRequires: zip
15 BuildRequires: pkgconfig(dlog)
16 BuildRequires: pkgconfig(openssl)
17 BuildRequires: libattr-devel
18 BuildRequires: pkgconfig(libsmack)
19 BuildRequires: pkgconfig(libsystemd-daemon)
20 BuildRequires: pkgconfig(vconf)
21 BuildRequires: pkgconfig(libsystemd-journal)
22 BuildRequires: pkgconfig(libxml-2.0)
23 BuildRequires: pkgconfig(capi-system-info)
24 BuildRequires: pkgconfig(security-manager)
25 BuildRequires: pkgconfig(cynara-client-async)
26 BuildRequires: pkgconfig(cynara-creds-socket)
27 BuildRequires: boost-devel
28 Requires: libkey-manager-common = %{version}-%{release}
29 %{?systemd_requires}
30
31 %description
32 Central Key Manager daemon could be used as secure storage
33 for certificate and private/public keys. It gives API for
34 application to sign and verify (DSA/RSA/ECDSA) signatures.
35
36 %package -n key-manager-listener
37 Summary:    Package with listener daemon
38 Group:      System/Security
39 BuildRequires: pkgconfig(vconf)
40 BuildRequires: pkgconfig(glib-2.0)
41 BuildRequires: pkgconfig(capi-appfw-package-manager)
42 Requires:   libkey-manager-client = %{version}-%{release}
43
44 %description -n key-manager-listener
45 Listener for central key manager. This daemon is responsible for
46 receive notification from dbus about uninstall application
47 and pass them to key-manager daemon.
48
49 %package -n libkey-manager-common
50 Summary:    Central Key Manager (common libraries)
51 Group:      Development/Libraries
52 Requires(post): /sbin/ldconfig
53 Requires(postun): /sbin/ldconfig
54
55 %description -n libkey-manager-common
56 Central Key Manager package (common library)
57
58 %package -n libkey-manager-client
59 Summary:    Central Key Manager (client)
60 Group:      Development/Libraries
61 Requires:   key-manager = %{version}-%{release}
62 Requires:   libkey-manager-common = %{version}-%{release}
63 Requires(post): /sbin/ldconfig
64 Requires(postun): /sbin/ldconfig
65
66 %description -n libkey-manager-client
67 Central Key Manager package (client)
68
69 %package -n libkey-manager-client-devel
70 Summary:    Central Key Manager (client-devel)
71 Group:      Development/Libraries
72 BuildRequires: pkgconfig(capi-base-common)
73 Requires:   pkgconfig(capi-base-common)
74 Requires:   libkey-manager-client = %{version}-%{release}
75
76 %description -n libkey-manager-client-devel
77 Central Key Manager package (client-devel)
78
79 %package -n key-manager-tests
80 Summary:    Internal test for key-manager
81 Group:      Development
82 BuildRequires: pkgconfig(libxml-2.0)
83 Requires:   boost-test
84 Requires:   key-manager = %{version}-%{release}
85
86 %description -n key-manager-tests
87 Internal test for key-manager implementation.
88
89 %package -n key-manager-pam-plugin
90 Summary:    CKM login/password module to PAM
91 Group:      Development/Libraries
92 BuildRequires: pam-devel
93 Requires:   key-manager = %{version}-%{release}
94 Requires(post): /sbin/ldconfig
95 Requires(postun): /sbin/ldconfig
96
97 %description -n key-manager-pam-plugin
98 CKM login/password module to PAM. Used to monitor user login/logout
99 and password change events from PAM
100
101
102 %prep
103 %setup -q
104 cp -a %{SOURCE1001} .
105 cp -a %{SOURCE1002} .
106 cp -a %{SOURCE1003} .
107 cp -a %{SOURCE1004} .
108 cp -a %{SOURCE1005} .
109
110 %build
111 %if 0%{?sec_build_binary_debug_enable}
112     export CFLAGS="$CFLAGS -DTIZEN_DEBUG_ENABLE"
113     export CXXFLAGS="$CXXFLAGS -DTIZEN_DEBUG_ENABLE"
114     export FFLAGS="$FFLAGS -DTIZEN_DEBUG_ENABLE"
115 %endif
116
117
118 export LDFLAGS+="-Wl,--rpath=%{_libdir},-Bsymbolic-functions "
119
120 %cmake . -DVERSION=%{version} \
121         -DCMAKE_BUILD_TYPE=%{?build_type:%build_type}%{!?build_type:RELEASE} \
122         -DCMAKE_VERBOSE_MAKEFILE=ON \
123 %if "%{sec_product_feature_security_mdfpp_enable}" == "1"
124         -DSECURITY_MDFPP_STATE_ENABLE=1 \
125 %endif
126         -DSYSTEMD_UNIT_DIR=%{_unitdir} \
127         -DSYSTEMD_ENV_FILE="/etc/sysconfig/central-key-manager" \
128         -DMOCKUP_SM=%{?mockup_sm:%mockup_sm}%{!?mockup_sm:OFF}
129
130 make %{?jobs:-j%jobs}
131
132 %install
133 rm -rf %{buildroot}
134 mkdir -p %{buildroot}/usr/share/license
135 cp LICENSE %{buildroot}/usr/share/license/%{name}
136 cp LICENSE %{buildroot}/usr/share/license/libkey-manager-client
137 mkdir -p %{buildroot}/opt/data/ckm/initial_values
138 mkdir -p %{buildroot}/etc/security/
139 mkdir -p %{buildroot}/usr/share/ckm/scripts
140 mkdir -p %{buildroot}/etc/gumd/userdel.d/
141 cp data/scripts/*.sql %{buildroot}/usr/share/ckm/scripts
142 cp doc/initial_values.xsd %{buildroot}/usr/share/ckm
143 cp data/gumd/10_key-manager.post %{buildroot}/etc/gumd/userdel.d/
144
145 mkdir -p %{buildroot}/usr/share/ckm-db-test
146 cp tests/testme_ver1.db %{buildroot}/usr/share/ckm-db-test/
147 cp tests/testme_ver2.db %{buildroot}/usr/share/ckm-db-test/
148 cp tests/testme_ver3.db %{buildroot}/usr/share/ckm-db-test/
149 cp tests/XML_1_okay.xml %{buildroot}/usr/share/ckm-db-test/
150 cp tests/XML_1_okay.xsd %{buildroot}/usr/share/ckm-db-test/
151 cp tests/XML_1_wrong.xml %{buildroot}/usr/share/ckm-db-test/
152 cp tests/XML_1_wrong.xsd %{buildroot}/usr/share/ckm-db-test/
153 cp tests/XML_2_structure.xml %{buildroot}/usr/share/ckm-db-test/
154
155 %make_install
156 %install_service multi-user.target.wants central-key-manager.service
157 %install_service multi-user.target.wants central-key-manager-listener.service
158 %install_service sockets.target.wants central-key-manager-api-control.socket
159 %install_service sockets.target.wants central-key-manager-api-storage.socket
160 %install_service sockets.target.wants central-key-manager-api-ocsp.socket
161 %install_service sockets.target.wants central-key-manager-api-encryption.socket
162
163 %clean
164 rm -rf %{buildroot}
165
166 %post
167 systemctl daemon-reload
168 if [ $1 = 1 ]; then
169     # installation
170     systemctl start central-key-manager.service
171 fi
172
173 if [ $1 = 2 ]; then
174     # update
175     systemctl restart central-key-manager.service
176 fi
177
178
179 %preun
180 if [ $1 = 0 ]; then
181     # unistall
182     systemctl stop central-key-manager.service
183 fi
184
185 %postun
186 if [ $1 = 0 ]; then
187     # unistall
188     systemctl daemon-reload
189 fi
190
191 %post -n libkey-manager-common -p /sbin/ldconfig
192 %post -n libkey-manager-client -p /sbin/ldconfig
193 %postun -n libkey-manager-common -p /sbin/ldconfig
194 %postun -n libkey-manager-client -p /sbin/ldconfig
195
196 %post -n key-manager-listener
197 systemctl daemon-reload
198 if [ $1 = 1 ]; then
199     # installation
200     systemctl start central-key-manager-listener.service
201 fi
202 if [ $1 = 2 ]; then
203     # update
204     systemctl restart central-key-manager-listener.service
205 fi
206
207 %preun -n key-manager-listener
208 if [ $1 = 0 ]; then
209     # unistall
210     systemctl stop central-key-manager-listener.service
211 fi
212
213 %postun -n key-manager-listener
214 if [ $1 = 0 ]; then
215     # unistall
216     systemctl daemon-reload
217 fi
218
219
220 %files -n key-manager
221 %manifest key-manager.manifest
222 %{_bindir}/key-manager
223 %{_unitdir}/multi-user.target.wants/central-key-manager.service
224 %{_unitdir}/central-key-manager.service
225 %{_unitdir}/central-key-manager.target
226 %{_unitdir}/sockets.target.wants/central-key-manager-api-control.socket
227 %{_unitdir}/central-key-manager-api-control.socket
228 %{_unitdir}/sockets.target.wants/central-key-manager-api-storage.socket
229 %{_unitdir}/central-key-manager-api-storage.socket
230 %{_unitdir}/sockets.target.wants/central-key-manager-api-ocsp.socket
231 %{_unitdir}/central-key-manager-api-ocsp.socket
232 %{_unitdir}/sockets.target.wants/central-key-manager-api-encryption.socket
233 %{_unitdir}/central-key-manager-api-encryption.socket
234 %{_datadir}/license/%{name}
235 %{_datadir}/ckm/initial_values.xsd
236 /opt/data/ckm/initial_values/
237 %attr(444, root, root) %{_datadir}/ckm/scripts/*.sql
238 /etc/opt/upgrade/230.key-manager-migrate-dkek.patch.sh
239 %attr(550, root, root) /etc/gumd/userdel.d/10_key-manager.post
240 %{_bindir}/ckm_tool
241
242 %files -n key-manager-pam-plugin
243 %manifest key-manager-pam-plugin.manifest
244 %{_libdir}/security/pam_key_manager_plugin.so*
245
246 %files -n key-manager-listener
247 %manifest key-manager-listener.manifest
248 %{_bindir}/key-manager-listener
249 %{_unitdir}/multi-user.target.wants/central-key-manager-listener.service
250 %{_unitdir}/central-key-manager-listener.service
251
252 %files -n libkey-manager-common
253 %manifest libkey-manager-common.manifest
254 %{_libdir}/libkey-manager-common.so.*
255
256 %files -n libkey-manager-client
257 %manifest libkey-manager-client.manifest
258 %{_libdir}/libkey-manager-client.so.*
259 %{_libdir}/libkey-manager-control-client.so.*
260 %{_datadir}/license/libkey-manager-client
261
262 %files -n libkey-manager-client-devel
263 %{_libdir}/libkey-manager-client.so
264 %{_libdir}/libkey-manager-control-client.so
265 %{_libdir}/libkey-manager-common.so
266 %{_includedir}/ckm/ckm/ckm-manager.h
267 %{_includedir}/ckm/ckm/ckm-manager-async.h
268 %{_includedir}/ckm/ckm/ckm-certificate.h
269 %{_includedir}/ckm/ckm/ckm-control.h
270 %{_includedir}/ckm/ckm/ckm-error.h
271 %{_includedir}/ckm/ckm/ckm-key.h
272 %{_includedir}/ckm/ckm/ckm-password.h
273 %{_includedir}/ckm/ckm/ckm-pkcs12.h
274 %{_includedir}/ckm/ckm/ckm-raw-buffer.h
275 %{_includedir}/ckm/ckm/ckm-type.h
276 %{_includedir}/ckm/ckmc/ckmc-manager.h
277 %{_includedir}/ckm/ckmc/ckmc-control.h
278 %{_includedir}/ckm/ckmc/ckmc-error.h
279 %{_includedir}/ckm/ckmc/ckmc-type.h
280 %{_libdir}/pkgconfig/*.pc
281
282 %files -n key-manager-tests
283 %{_bindir}/ckm-tests-internal
284 %{_datadir}/ckm-db-test/testme_ver1.db
285 %{_datadir}/ckm-db-test/testme_ver2.db
286 %{_datadir}/ckm-db-test/testme_ver3.db
287 %{_datadir}/ckm-db-test/XML_1_okay.xml
288 %{_datadir}/ckm-db-test/XML_1_okay.xsd
289 %{_datadir}/ckm-db-test/XML_1_wrong.xml
290 %{_datadir}/ckm-db-test/XML_1_wrong.xsd
291 %{_datadir}/ckm-db-test/XML_2_structure.xml
292 %{_bindir}/ckm_so_loader
293 %{_bindir}/ckm_db_tool