2 Summary: Central Key Manager and utilities
7 Source0: %{name}-%{version}.tar.gz
8 Source1001: key-manager.manifest
9 Source1002: key-manager-listener.manifest
10 Source1003: libkey-manager-client.manifest
11 Source1004: libkey-manager-common.manifest
14 BuildRequires: pkgconfig(dlog)
15 BuildRequires: pkgconfig(openssl)
16 BuildRequires: libattr-devel
17 BuildRequires: pkgconfig(libsmack)
18 BuildRequires: pkgconfig(libsystemd-daemon)
19 BuildRequires: pkgconfig(vconf)
20 BuildRequires: pkgconfig(libsystemd-journal)
21 BuildRequires: pkgconfig(libxml-2.0)
22 BuildRequires: pkgconfig(capi-system-info)
23 BuildRequires: pkgconfig(security-manager)
24 BuildRequires: pkgconfig(cynara-client-async)
25 BuildRequires: pkgconfig(cynara-creds-socket)
26 BuildRequires: boost-devel
27 Requires: libkey-manager-common = %{version}-%{release}
31 Central Key Manager daemon could be used as secure storage
32 for certificate and private/public keys. It gives API for
33 application to sign and verify (DSA/RSA/ECDSA) signatures.
35 %package -n key-manager-listener
36 Summary: Package with listener daemon
37 Group: System/Security
38 BuildRequires: pkgconfig(vconf)
39 BuildRequires: pkgconfig(glib-2.0)
40 BuildRequires: pkgconfig(capi-appfw-package-manager)
41 Requires: libkey-manager-client = %{version}-%{release}
43 %description -n key-manager-listener
44 Listener for central key manager. This daemon is responsible for
45 receive notification from dbus about uninstall application
46 and pass them to key-manager daemon.
48 %package -n libkey-manager-common
49 Summary: Central Key Manager (common libraries)
50 Group: Development/Libraries
51 Requires(post): /sbin/ldconfig
52 Requires(postun): /sbin/ldconfig
54 %description -n libkey-manager-common
55 Central Key Manager package (common library)
57 %package -n libkey-manager-client
58 Summary: Central Key Manager (client)
59 Group: Development/Libraries
60 Requires: key-manager = %{version}-%{release}
61 Requires: libkey-manager-common = %{version}-%{release}
62 Requires(post): /sbin/ldconfig
63 Requires(postun): /sbin/ldconfig
65 %description -n libkey-manager-client
66 Central Key Manager package (client)
68 %package -n libkey-manager-client-devel
69 Summary: Central Key Manager (client-devel)
70 Group: Development/Libraries
71 BuildRequires: pkgconfig(capi-base-common)
72 Requires: pkgconfig(capi-base-common)
73 Requires: libkey-manager-client = %{version}-%{release}
75 %description -n libkey-manager-client-devel
76 Central Key Manager package (client-devel)
78 %package -n key-manager-tests
79 Summary: Internal test for key-manager
81 BuildRequires: pkgconfig(libxml-2.0)
83 Requires: key-manager = %{version}-%{release}
85 %description -n key-manager-tests
86 Internal test for key-manager implementation.
88 %package -n key-manager-pam-plugin
89 Summary: CKM login/password module to PAM.
90 Group: Development/Libraries
91 BuildRequires: pam-devel
92 Requires: key-manager = %{version}-%{release}
93 Requires(post): /sbin/ldconfig
94 Requires(postun): /sbin/ldconfig
96 %description -n key-manager-pam-plugin
97 CKM login/password module to PAM.
98 It's used to monitor user login/logout and password change events from PAM.
103 cp -a %{SOURCE1001} .
104 cp -a %{SOURCE1002} .
105 cp -a %{SOURCE1003} .
106 cp -a %{SOURCE1004} .
108 # optional password disabled temporary for milestone release
109 %define ckm_optional_password_enable 0
112 %if 0%{?sec_build_binary_debug_enable}
113 export CFLAGS="$CFLAGS -DTIZEN_DEBUG_ENABLE"
114 export CXXFLAGS="$CXXFLAGS -DTIZEN_DEBUG_ENABLE"
115 export FFLAGS="$FFLAGS -DTIZEN_DEBUG_ENABLE"
119 export LDFLAGS+="-Wl,--rpath=%{_libdir},-Bsymbolic-functions "
121 %cmake . -DVERSION=%{version} \
122 -DCMAKE_BUILD_TYPE=%{?build_type:%build_type}%{!?build_type:RELEASE} \
123 -DCMAKE_VERBOSE_MAKEFILE=ON \
124 %if "%{sec_product_feature_security_mdfpp_enable}" == "1"
125 -DSECURITY_MDFPP_STATE_ENABLE=1 \
127 %if 0%{?ckm_optional_password_enable}
128 -DOPTIONAL_PASSWORD_ENABLE=1 \
130 -DSYSTEMD_UNIT_DIR=%{_unitdir} \
131 -DSYSTEMD_ENV_FILE="/etc/sysconfig/central-key-manager" \
132 -DMOCKUP_SM=%{?mockup_sm:%mockup_sm}%{!?mockup_sm:OFF}
134 make %{?jobs:-j%jobs}
138 mkdir -p %{buildroot}/usr/share/license
139 cp LICENSE %{buildroot}/usr/share/license/%{name}
140 cp LICENSE %{buildroot}/usr/share/license/libkey-manager-client
141 cp LICENSE %{buildroot}/usr/share/license/libkey-manager-control-client
142 mkdir -p %{buildroot}/opt/data/ckm/initial_values
143 mkdir -p %{buildroot}/etc/security/
144 mkdir -p %{buildroot}/usr/share/ckm/scripts
145 cp data/scripts/*.sql %{buildroot}/usr/share/ckm/scripts
146 cp doc/initial_values.xsd %{buildroot}/usr/share/ckm
147 mkdir -p %{buildroot}/usr/share/ckm-db-test
148 cp tests/testme_ver1.db %{buildroot}/usr/share/ckm-db-test/
149 cp tests/testme_ver2.db %{buildroot}/usr/share/ckm-db-test/
150 cp tests/testme_ver3.db %{buildroot}/usr/share/ckm-db-test/
151 cp tests/XML_1_okay.xml %{buildroot}/usr/share/ckm-db-test/
152 cp tests/XML_1_okay.xsd %{buildroot}/usr/share/ckm-db-test/
153 cp tests/XML_1_wrong.xml %{buildroot}/usr/share/ckm-db-test/
154 cp tests/XML_1_wrong.xsd %{buildroot}/usr/share/ckm-db-test/
155 cp tests/XML_2_structure.xml %{buildroot}/usr/share/ckm-db-test/
156 mkdir -p %{buildroot}/etc/gumd/userdel.d/
157 cp data/gumd/10_key-manager.post %{buildroot}/etc/gumd/userdel.d/
160 mkdir -p %{buildroot}%{_unitdir}/multi-user.target.wants
161 mkdir -p %{buildroot}%{_unitdir}/sockets.target.wants
162 ln -s ../central-key-manager.service %{buildroot}%{_unitdir}/multi-user.target.wants/central-key-manager.service
163 ln -s ../central-key-manager-listener.service %{buildroot}%{_unitdir}/multi-user.target.wants/central-key-manager-listener.service
164 ln -s ../central-key-manager-api-control.socket %{buildroot}%{_unitdir}/sockets.target.wants/central-key-manager-api-control.socket
165 ln -s ../central-key-manager-api-storage.socket %{buildroot}%{_unitdir}/sockets.target.wants/central-key-manager-api-storage.socket
166 ln -s ../central-key-manager-api-ocsp.socket %{buildroot}%{_unitdir}/sockets.target.wants/central-key-manager-api-ocsp.socket
167 ln -s ../central-key-manager-api-encryption.socket %{buildroot}%{_unitdir}/sockets.target.wants/central-key-manager-api-encryption.socket
173 systemctl daemon-reload
176 systemctl start central-key-manager.service
181 systemctl restart central-key-manager.service
188 systemctl stop central-key-manager.service
194 systemctl daemon-reload
197 %post -n libkey-manager-client -p /sbin/ldconfig
199 %postun -n libkey-manager-client -p /sbin/ldconfig
201 %post -n key-manager-listener
202 systemctl daemon-reload
205 systemctl start central-key-manager-listener.service
209 systemctl restart central-key-manager-listener.service
212 %preun -n key-manager-listener
215 systemctl stop central-key-manager-listener.service
218 %postun -n key-manager-listener
221 systemctl daemon-reload
225 %files -n key-manager
226 %manifest key-manager.manifest
227 %{_bindir}/key-manager
228 %{_unitdir}/multi-user.target.wants/central-key-manager.service
229 %{_unitdir}/central-key-manager.service
230 %{_unitdir}/central-key-manager.target
231 %{_unitdir}/sockets.target.wants/central-key-manager-api-control.socket
232 %{_unitdir}/central-key-manager-api-control.socket
233 %{_unitdir}/sockets.target.wants/central-key-manager-api-storage.socket
234 %{_unitdir}/central-key-manager-api-storage.socket
235 %{_unitdir}/sockets.target.wants/central-key-manager-api-ocsp.socket
236 %{_unitdir}/central-key-manager-api-ocsp.socket
237 %{_unitdir}/sockets.target.wants/central-key-manager-api-encryption.socket
238 %{_unitdir}/central-key-manager-api-encryption.socket
239 %{_datadir}/license/%{name}
240 %{_datadir}/ckm/scripts/*.sql
242 %{_datadir}/ckm/initial_values.xsd
243 /opt/data/ckm/initial_values/
244 %attr(444, root, root) %{_datadir}/ckm/scripts/*.sql
245 /etc/opt/upgrade/230.key-manager-migrate-dkek.patch.sh
246 /etc/gumd/userdel.d/10_key-manager.post
247 %attr(550, root, root) /etc/gumd/userdel.d/10_key-manager.post
250 %files -n key-manager-listener
251 %manifest key-manager-listener.manifest
252 %{_bindir}/key-manager-listener
253 %{_unitdir}/multi-user.target.wants/central-key-manager-listener.service
254 %{_unitdir}/central-key-manager-listener.service
256 %files -n libkey-manager-common
257 %manifest libkey-manager-common.manifest
258 %{_libdir}/libkey-manager-common.so.*
260 %files -n libkey-manager-client
261 %manifest libkey-manager-client.manifest
262 %{_libdir}/libkey-manager-client.so.*
263 %{_libdir}/libkey-manager-control-client.so.*
264 %{_datadir}/license/libkey-manager-client
265 %{_datadir}/license/libkey-manager-control-client
267 %files -n libkey-manager-client-devel
268 %defattr(-,root,root,-)
269 %{_libdir}/libkey-manager-client.so
270 %{_libdir}/libkey-manager-control-client.so
271 %{_libdir}/libkey-manager-common.so
272 %{_includedir}/ckm/ckm/ckm-manager.h
273 %{_includedir}/ckm/ckm/ckm-manager-async.h
274 %{_includedir}/ckm/ckm/ckm-certificate.h
275 %{_includedir}/ckm/ckm/ckm-control.h
276 %{_includedir}/ckm/ckm/ckm-error.h
277 %{_includedir}/ckm/ckm/ckm-key.h
278 %{_includedir}/ckm/ckm/ckm-password.h
279 %{_includedir}/ckm/ckm/ckm-pkcs12.h
280 %{_includedir}/ckm/ckm/ckm-raw-buffer.h
281 %{_includedir}/ckm/ckm/ckm-type.h
282 %{_includedir}/ckm/ckmc/ckmc-manager.h
283 %{_includedir}/ckm/ckmc/ckmc-control.h
284 %{_includedir}/ckm/ckmc/ckmc-error.h
285 %{_includedir}/ckm/ckmc/ckmc-type.h
286 %{_libdir}/pkgconfig/*.pc
288 %files -n key-manager-tests
289 %defattr(-,root,root,-)
290 %{_bindir}/ckm-tests-internal
291 %{_datadir}/ckm-db-test/testme_ver1.db
292 %{_datadir}/ckm-db-test/testme_ver2.db
293 %{_datadir}/ckm-db-test/testme_ver3.db
294 %{_datadir}/ckm-db-test/XML_1_okay.xml
295 %{_datadir}/ckm-db-test/XML_1_okay.xsd
296 %{_datadir}/ckm-db-test/XML_1_wrong.xml
297 %{_datadir}/ckm-db-test/XML_1_wrong.xsd
298 %{_datadir}/ckm-db-test/XML_2_structure.xml
299 %{_bindir}/ckm_so_loader
300 %{_bindir}/ckm_db_tool
302 %files -n key-manager-pam-plugin
303 %defattr(-,root,root,-)
304 %{_libdir}/security/pam_key_manager_plugin.so*