6916796 OSnet mapfiles should use version 2 link-editor syntax
6944179 kmf_sign_cert needs more info about signing algorithm6944121 KMF should add Basic-Constraint when keyCertSign EKU is set6943253 pktool should ask to overwrite a CSR file if it already exists6943234 pktool online help wrongly suggests we can delete a key based on its subject-DN6940180 certClass should be called privClass (or just class) in KMFPK11_FindPrikeyByCert()6940146 kmf_sign_data() returns KMF_ERR_INTERNAL but the PKCS#11 plugin returns KMF_ERR_MISSING_ERRCODE6938522 kmf_openssl.so.1 clobbers OpenSSL locking callbacks
PSARC 2010/032 EC and SHA2 for KMF6902640 pktool/KMF needs to support ECDSA keys and certificates6787016 pktool can offer the ability to generate RSA keypairs
6864896 libkmf leaks memory
6855407 kernel crypto module reports firmware version incorrectly6854979 kmf_pkcs11.so.1 has bad SONAME and versioning
6806387 Move OpenSSL from ON to SFW
6798660 Cadmium .NOT file processing problem with CWD relative file pathsContributed by Richard Lowe6785284 Mapfile versioning rules need to be more visible to gatelings6800164 Standard file exclusion mechanism needed for Cadmium tools
6449514 move OpenSSL from /usr/sfw to /usr, /lib6457487 clean up Makefile for cmd/openssl6686002 move /usr/lib/libkmf and plugins to /lib - PSARC 2007/6746686004 move libcryptoutil and libelfsign from /usr/lib to /lib - PSARC 2007/6746700122 cryptosvc should be able to start before filesystem/usr
backout 6449514/6686002/6686004/6700122: needs more work
6449514 move OpenSSL from /usr/sfw to /usr, /lib6686002 move /usr/lib/libkmf and plugins to /lib - PSARC 2007/6746686004 move libcryptoutil and libelfsign from /usr/lib to /lib - PSARC 2007/6746700122 cryptosvc should be able to start before filesystem/usr
6683064 check_rtime could do with some spring cleaning
PSARC 2008/037 new EKU support for pktool and kmfcfg6648052 pktool(1) could allow certificate signing and verification6652751 kmf_get_kmf_error_str() doesn't know about KMF_ERR_ATTR_NOT_FOUND6654080 kmf_verify_data() should use algorithm from the cert if KMF_ALGORITHM_INDEX_ATTR is missing6654205 kmf_find_prikey_by_cert() should be public6654910 kmf_validate_cert() won't get over non-existent x509v3 extensions in TA6660235 Command summary on pktool help should be localizable.6660622 KMF needs API to determine format of raw data
6634339 kmf_find_key returns error when searching for raw (RSA) public key
6620497 KMF does not build proper PKCS12 PDUs6624214 kmf_get_cert_extn can leak memory6629477 libkmf is crashed in OpenSSL_StoreKey if keytype is not KMF_RSA or KMF_DSA
6614385 libkmf should be able to open plugins on demand
PSARC 2007/426 KMFAPI Interface Taxonomy ChangePSARC 2007/465 pktool symmetric key enhancements6546405 KMF Interfaces need to be extensible6547894 pktool should be more detailed6590232 pktool should import and export generic keys
6558467 memory leak in kcfd
6549186 OpenSSL_FindCert incorrectly tracks matched certificates
6547594 KMF incorrectly processes pkcs12 files6547853 KMF is too strict about KeyUsage
6542973 KMF_FindCert is racy
6512691 kssladm dumps core when given invalid input
6531818 libkmf has too many dependencies on libpkcs116534811 KMF openssl verify routine should test for NULL hash method.6534827 KMF_ReadInputFile should not require a handle
PSARC 2007/094 encrypt(1) / mac(1) token key support4868006 encrypt(1) and mac(1) needs to support token objects6517162 pktool genkey needs to support generic secret key
6523959 KMF needs keystore specific Verify operations
6509342 Code licenses for KMF need to be cleaned up.
6501154 kssladm could use KMF
6495595 KMF incorrectly checks the CA constraint6495596 KMF_OpenSSL plugin incorrectly clears memory from returned cert list.
6224192 Solaris needs unified key management interfaces (fix clobber, EXPORT_SRC build)
PSARC 2005/074 Solaris Key Management Framework6224192 Solaris needs unified key management interfaces