#8814 Use Dogtag's CryptographyCryptoProvider instead of NSSCryptoProvider for KRAClient()
Closed: fixed 2 years ago by frenaud. Opened 3 years ago by cheimes.

Request for enhancement

KRAClient and kra backend in ipaserver.plugins.dogtag currently use NSSCryptoProvider to implement key and data wrapping. The NSS provider uses python-nss. We would like to drop the dependency.

Dogtag has support for PyCA cryptography-based crypto provider called CryptographyCryptoProvider for several years now.


Metadata Update from @cheimes:
- Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/5726
- Issue tagged with: rfe

3 years ago

master:

  • 1d80048 Use PyCA crypto provider for KRAClient

ipa-4-9:

  • 0244a06 Use PyCA crypto provider for KRAClient

Metadata Update from @frenaud:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

2 years ago

Login to comment on this ticket.

Metadata