From sacadmin Tue Oct 31 04:04:24 2006
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.6+Sun/8.13.6) with ESMTP id k9VC4OpK029164;
	Tue, 31 Oct 2006 04:04:24 -0800 (PST)
Received: (from darrenm@localhost)
	by sac.sfbay.sun.com (8.13.6+Sun/8.13.6/Submit) id k9VC4OWl029160;
	Tue, 31 Oct 2006 04:04:24 -0800 (PST)
Date: Tue, 31 Oct 2006 04:04:24 -0800 (PST)
From: Darren J Moffat <darrenm@sac.sfbay.sun.com>
Message-Id: <200610311204.k9VC4OWl029160@sac.sfbay.sun.com>
To: PSARC@sac.sfbay.sun.com
Cc: ef-core@sun.com
Subject: Data Encryption Kit (SUNWcry) Removal [PSARC/2006/610 Timeout:  11/07/2006]
Status: RO
Content-Length: 5554

Subject: PSARC FastTrack [11/07/2006]: Data Encryption Kit (SUNWcry) Removal


Template Version: @(#)sac_nextcase %I% %G% SMI
1. Introduction
    1.1. Project/Component Working Name:
	 Data Encryption Kit (SUNWcry) Removal
    1.2. Name of Document Author/Supplier:
	 Author:  Darren Moffat
    1.3  Date of This Document:
	31 October, 2006
4. Technical Description

Solaris has had a SUNWcry/SUWNcryr package pair for several releases now.
Upto and including Solaris 9 this was required due to US export restrictions
on the export of encryption software.  For Solaris 10 these same packages were
reprovisioned to deal with import restrictions to some other countries,
the US export restriction for software no longer applied in a way that
impacted us shipping the algorithm implementations as part of the
crypto framework.

The base Solaris 10 software implementation of symmetric key algorithms in the 
crypto framework and in OpenSSL was limited to 128 bit.  Adding the
SUNWcry/SUNWcryr packages "removed" this restriction.  For the crypto
framework this was done by adding additional kernel and user providers
and "upgrading" the private kcf.conf and pkcs11.conf files.  For OpenSSL
it was done using "linker magic" (aka filter libs).

The problem countries at the time were:
	France, Israel, Russia, China, Hong Kong.

All of those countries no longer have this restriction and Sun's ITS
department has confirmed this and given approval to ship full strength
symetric crypto as part of core Solaris.

Given that, there is no longer a need to have this restriction in Solaris
that our competitors in the open source world (and some commercial vendors)
never implemented.

This case seeks immediate EOF of the Solaris Data Encryption Kit (sometimes
called Supplement) and removal of the SUNWcry/SUNWcryr packages
and their contents.  This is being done for a minor release binding only
at this time, we believe that it is possible and safe to do this
in a patch but need to work out some further details.  This case therefore
requests minor release binding if we patch it a future ammendment case
will cover patch binding.

There will be a release note issued for Solaris Express that informs
customers of the change.  

Since this isn't acutally an EOF of any functionality just a change in the
delivery mechanism a EOF notice in the Solaris 10 update releases
doesn't appear to be needed.

On upgrade a customer that had SUNWcry/SUNWcryr installed will see
no difference other than the names of the providers listed by
cryptoadm(1M) the functionality will be the same as the base.  For
systems that did not have SUNWcry/SUNWcryr installed they will now have
pkcs11_softtoken.so.1 and its kernel counterparts providing the full
supported keylengths for CKM_AES* (256), CKM_BLOWFISH_* (448), and
CKM_RC4 (4096).


                        Exported Interface Table
==============================================================================
Obsoleted and removed interfaces for all platforms and architectures:

SUNWcry		pkcs11_softtoken_extra.so.1	Userland PKCS#11 provider
SUNWcryr	aes256				Kernel Crypto Provider
SUNWcryr	arcfour2048			Kernel Crypto Provider
SUNWcryr	blowfish448			Kernel Crypto Provider
SUNWcry		libcrypto_extra.so		OpenSSL filter
SUNWcry		libssl_extra.so			OpenSSL filter
------------------------------------------------------------------------------
Moved interfaces

SUNWcry		/usr/bin/des			Moved to SUNWcsu.

------------------------------------------------------------------------------
Project Private files updated:

SUNWcsl/postintstall /etc/security/pkcs11.conf  Revert to pkcs11_softtoken
SUNWcsr/postintstall /etc/security/kcf.conf     Revert to aes/arcfour/blowfish
------------------------------------------------------------------------------
Public Interfaces (Crypto Providers) updated:

SUNWcsl		pkcs11_softtoken.so.1
SUNWckr		kernel/crypto modules: aes, blowfish, arcfour		
SUNWcakr	kernel/crypto modules: aes
------------------------------------------------------------------------------

SUNWcsr and SUNWcsl will contain the necessary changes to thier postinstall 
scripts to undo the kcf.conf, pkcs11.conf changes that SUNWcry/SUNWcryr 
did ensuring that the system is running with "full strength" 
crypto and it is available.

Similar changes will be done to bfu, which will also delete the old
providers.

A set of package history files will be filed with RE to ensure that
on upgrade to Solaris 11 (the assumed minor release that contains this)
the SUNWcry/SUNWcryr packages will be removed.

Live Upgrade never knew about SUNWcry/SUNWcryr so needs no changes beyond
the postinstall scripts in the base packages.

The project team will work with the ON C-Team and Solaris RE to
terminate the processes they have for building and shipping the
media that contains the SUNWcry/SUNWcryr packages.

This case also resolves the following bugs bug making the problem just
go way:

6321294 bfu should not auto enable the SUNWcry crypto providers
6354242 SUNWcryr install or remove may leave wrong software provider in kernel
6359145 SUNWcry incorrectly updates $BASEDIR/etc/crypto/pkcs11.conf

It also reduces the number of things in the closed-bins.tar for OpenSolaris
since even though these are open source they were signed by Sun.  I'll work
with the relevant engineers to ensure the correct things happen for the
opensolaris source/binary drops too.


6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack

From sacadmin Tue Oct 31 05:17:29 2006
Received: from phys-bohemia2-2 (phys-bohemia2-2.Czech.Sun.COM [129.157.72.190])
	by sac.sfbay.sun.com (8.13.6+Sun/8.13.6) with ESMTP id k9VDHSaE000141;
	Tue, 31 Oct 2006 05:17:29 -0800 (PST)
Received: from conversion-daemon.bohemia2-mail1.czech.sun.com by
 bohemia2-mail1.czech.sun.com
 (iPlanet Messaging Server 5.2 HotFix 1.24 (built Dec 19 2003))
 id <0J8000L014C8OE@bohemia2-mail1.czech.sun.com>
 (original mail from Jan.Pechanec@Sun.COM); Tue,
 31 Oct 2006 14:17:28 +0100 (CET)
Received: from andal (andal.Czech.Sun.COM [129.157.18.59])
 by bohemia2-mail1.czech.sun.com
 (iPlanet Messaging Server 5.2 HotFix 1.24 (built Dec 19 2003))
 with ESMTP id <0J8000CXD4X4PU@bohemia2-mail1.czech.sun.com>; Tue,
 31 Oct 2006 14:17:28 +0100 (CET)
Date: Tue, 31 Oct 2006 14:16:32 +0100 (CET)
From: Jan Pechanec <Jan.Pechanec@Sun.COM>
Subject: Re: Data Encryption Kit (SUNWcry) Removal [PSARC/2006/610 Timeout:
 11/07/2006]
In-reply-to: <200610311204.k9VC4OWl029160@sac.sfbay.sun.com>
X-X-Sender: jp161948@andal
To: Darren J Moffat <darrenm@sac.sfbay.sun.com>
Cc: PSARC@sac.sfbay.sun.com, ef-core@Sun.COM
Message-id: <Pine.GSO.4.61.0610311413150.103299@andal>
MIME-version: 1.0
Content-type: TEXT/PLAIN; charset=US-ASCII
References: <200610311204.k9VC4OWl029160@sac.sfbay.sun.com>
Status: RO
Content-Length: 812

On Tue, 31 Oct 2006, Darren J Moffat wrote:

>Subject: PSARC FastTrack [11/07/2006]: Data Encryption Kit (SUNWcry) Removal
>
>
>Template Version: @(#)sac_nextcase %I% %G% SMI
>1. Introduction
>    1.1. Project/Component Working Name:
>	 Data Encryption Kit (SUNWcry) Removal
>    1.2. Name of Document Author/Supplier:
>	 Author:  Darren Moffat
>    1.3  Date of This Document:
>	31 October, 2006
>4. Technical Description

	one more thing is that we should also ping Apache maintainers so 
that after this is done they can update SSLCipherSuite in httpd.conf which 
currently removes all that strong crypto from default configuration. It was 
also a call generator since whoever installed Apache from sources without 
SUNWcry* packages saw that Apache wasn't working with SSL properly.

	Jan.

-- 
Jan Pechanec

From sacadmin Tue Oct 31 05:20:28 2006
Received: from sfbaymail1sca.SFBay.Sun.COM (sfbaymail1sca.SFBay.Sun.COM [129.145.154.35])
	by sac.sfbay.sun.com (8.13.6+Sun/8.13.6) with ESMTP id k9VDKSN2000157;
	Tue, 31 Oct 2006 05:20:28 -0800 (PST)
Received: from gmp-ea-fw-1.sun.com (gmpes-gis-mail-2.UK.Sun.COM [129.156.42.6])
	by sfbaymail1sca.SFBay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2) with ESMTP id k9VDKRdR001934;
	Tue, 31 Oct 2006 05:20:27 -0800 (PST)
Received: from d1-emea-09.sun.com ([192.18.2.119])
	by gmp-ea-fw-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id k9VDKLHG014514;
	Tue, 31 Oct 2006 13:20:21 GMT
Received: from conversion-daemon.d1-emea-09.sun.com by d1-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0J8000N015152D00@d1-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM); Tue,
 31 Oct 2006 13:20:21 +0000 (GMT)
Received: from [129.150.120.2] by d1-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0J80000O351WS910@d1-emea-09.sun.com>; Tue,
 31 Oct 2006 13:20:21 +0000 (GMT)
Date: Tue, 31 Oct 2006 13:20:12 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: Data Encryption Kit (SUNWcry) Removal [PSARC/2006/610 Timeout:
 11/07/2006]
In-reply-to: <Pine.GSO.4.61.0610311413150.103299@andal>
Sender: Darren.Moffat@Sun.COM
To: Jan Pechanec <Jan.Pechanec@Sun.COM>
Cc: Darren J Moffat <darrenm@sac.sfbay.sun.com>, PSARC@sac.sfbay.sun.com,
        ef-core@Sun.COM
Message-id: <45474D8C.30404@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <200610311204.k9VC4OWl029160@sac.sfbay.sun.com>
 <Pine.GSO.4.61.0610311413150.103299@andal>
User-Agent: Thunderbird 1.5.0.5 (X11/20060925)
Status: RO
Content-Length: 1141

Jan Pechanec wrote:
> On Tue, 31 Oct 2006, Darren J Moffat wrote:
> 
>> Subject: PSARC FastTrack [11/07/2006]: Data Encryption Kit (SUNWcry) Removal
>>
>>
>> Template Version: @(#)sac_nextcase %I% %G% SMI
>> 1. Introduction
>>    1.1. Project/Component Working Name:
>> 	 Data Encryption Kit (SUNWcry) Removal
>>    1.2. Name of Document Author/Supplier:
>> 	 Author:  Darren Moffat
>>    1.3  Date of This Document:
>> 	31 October, 2006
>> 4. Technical Description
> 
> 	one more thing is that we should also ping Apache maintainers so 
> that after this is done they can update SSLCipherSuite in httpd.conf which 
> currently removes all that strong crypto from default configuration. It was 
> also a call generator since whoever installed Apache from sources without 
> SUNWcry* packages saw that Apache wasn't working with SSL properly.

Thanks for the reminder on that Jan.

Consider it part of this case that the Apache httpd.conf in the SFW
consolidation is updated post this putback.  Note it may not happen in
the same build but that is okay, it just has to happen after the ON
putback to remove the packages.

-- 
Darren J Moffat

From sacadmin Tue Oct 31 13:45:53 2006
Received: from eastmail4bur.east.Sun.COM (eastmail4bur.East.Sun.COM [129.148.13.1])
	by sac.sfbay.sun.com (8.13.6+Sun/8.13.6) with ESMTP id k9VLjqpq016434;
	Tue, 31 Oct 2006 13:45:53 -0800 (PST)
Received: from thunk.east.sun.com (thunk.East.Sun.COM [129.148.174.66])
	by eastmail4bur.east.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2) with ESMTP id k9VLjq3u013587;
	Tue, 31 Oct 2006 16:45:52 -0500 (EST)
Received: from localhost (localhost [IPv6:::1])
	by thunk.east.sun.com (8.13.8+Sun/8.13.8) with ESMTP id k9VLjqKa008946;
	Tue, 31 Oct 2006 16:45:52 -0500 (EST)
Subject: Re: Data Encryption Kit (SUNWcry) Removal [PSARC/2006/610 Timeout:
	11/07/2006]
From: Bill Sommerfeld <sommerfeld@sun.com>
To: Darren J Moffat <darrenm@sac.sfbay.sun.com>
Cc: PSARC@sac.sfbay.sun.com, ef-core@sun.com
In-Reply-To: <200610311204.k9VC4OWl029160@sac.sfbay.sun.com>
References: <200610311204.k9VC4OWl029160@sac.sfbay.sun.com>
Content-Type: text/plain
Date: Tue, 31 Oct 2006 16:45:51 -0500
Message-Id: <1162331151.7145.11.camel@thunk>
Mime-Version: 1.0
X-Mailer: Evolution 2.6.2 
Content-Transfer-Encoding: 7bit
Status: RO
Content-Length: 588

On Tue, 2006-10-31 at 04:04 -0800, Darren J Moffat wrote:
> This is being done for a minor release binding only
> at this time, we believe that it is possible and safe to do this
> in a patch but need to work out some further details. 

given the removal of packages and installed files, you should explicitly
mention in release notes, etc., the correct way for third party/layered
scripts, etc., to check for full crypto being installed (looks like on
s10+, scripts should inspect the output of cryptoadm list -m).  

This would be even more important for patch binding.

						- Bill



From sacadmin Wed Nov  1 03:18:08 2006
Received: from sfbaymail2sca.sfbay.sun.com (sfbaymail2sca.SFBay.Sun.COM [129.145.155.42])
	by sac.sfbay.sun.com (8.13.6+Sun/8.13.6) with ESMTP id kA1BI8Yq006720;
	Wed, 1 Nov 2006 03:18:08 -0800 (PST)
Received: from gmp-ea-fw-1.sun.com (gmpes-gis-mail-2.UK.Sun.COM [129.156.42.6])
	by sfbaymail2sca.sfbay.sun.com (8.13.6+Sun/8.12.10/ENSMAIL,v2.2) with ESMTP id kA1BI7I2009570;
	Wed, 1 Nov 2006 03:18:08 -0800 (PST)
Received: from d1-emea-09.sun.com ([192.18.2.119])
	by gmp-ea-fw-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id kA1BI1Wf001537;
	Wed, 1 Nov 2006 11:18:02 GMT
Received: from conversion-daemon.d1-emea-09.sun.com by d1-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0J8100G01U0K4T00@d1-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM); Wed,
 01 Nov 2006 11:18:01 +0000 (GMT)
Received: from [129.150.120.2] by d1-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0J8100D4CU21T310@d1-emea-09.sun.com>; Wed,
 01 Nov 2006 11:18:01 +0000 (GMT)
Date: Wed, 01 Nov 2006 11:17:52 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: Data Encryption Kit (SUNWcry) Removal [PSARC/2006/610 Timeout:
 11/07/2006]
In-reply-to: <1162331151.7145.11.camel@thunk>
Sender: Darren.Moffat@Sun.COM
To: Bill Sommerfeld <sommerfeld@Sun.COM>
Cc: Darren J Moffat <darrenm@sac.sfbay.sun.com>, PSARC@sac.sfbay.sun.com,
        ef-core@Sun.COM
Message-id: <45488260.6000701@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <200610311204.k9VC4OWl029160@sac.sfbay.sun.com>
 <1162331151.7145.11.camel@thunk>
User-Agent: Thunderbird 1.5.0.5 (X11/20060925)
Status: RO
Content-Length: 954

Bill Sommerfeld wrote:
> On Tue, 2006-10-31 at 04:04 -0800, Darren J Moffat wrote:
>> This is being done for a minor release binding only
>> at this time, we believe that it is possible and safe to do this
>> in a patch but need to work out some further details. 
> 
> given the removal of packages and installed files, you should explicitly
> mention in release notes, etc., the correct way for third party/layered
> scripts, etc., to check for full crypto being installed (looks like on
> s10+, scripts should inspect the output of cryptoadm list -m).  

We never documented a way to do this when SUNWcry/SUNWcryr was installed
so I'm not sure I understand why we should have to document that in
the release notes.

cryptoadm list -vm will tell you the keylength information for userland
providers but not for kernel - there is an outstanding CR for making the
kernel output the same as the userland one but that is not this case.

-- 
Darren J Moffat

From sacadmin Thu Nov  2 07:55:51 2006
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.6+Sun/8.13.6) with ESMTP id kA2FtoB6016089
	for <psarc@sac.eng.Sun.COM>; Thu, 2 Nov 2006 07:55:51 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.149.247.22])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id kA2FtQLe026389;
	Thu, 2 Nov 2006 23:55:27 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0J8400E0F1KDLK00@nwk-avmta-2.sfbay.sun.com>; Thu,
 02 Nov 2006 07:55:25 -0800 (PST)
Received: from gmp-ea-fw-1.sun.com ([129.156.42.6])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0J8400A4U1KB4RF0@nwk-avmta-2.sfbay.sun.com>; Thu,
 02 Nov 2006 07:55:24 -0800 (PST)
Received: from d1-emea-10.sun.com ([192.18.2.120])
	by gmp-ea-fw-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id kA2FtNWq002643; Thu,
 02 Nov 2006 15:55:23 +0000 (GMT)
Received: from conversion-daemon.d1-emea-10.sun.com by d1-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0J84000011J0RU00@d1-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM); Thu,
 02 Nov 2006 15:55:23 +0000 (GMT)
Received: from [129.156.173.199] by d1-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0J8400AC01KAL910@d1-emea-10.sun.com>; Thu,
 02 Nov 2006 15:55:22 +0000 (GMT)
Date: Thu, 02 Nov 2006 15:55:22 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: PSARC/2006/610 [closed-approved] Data Encryption Kit (SUNWcry) Removal
Sender: Darren.Moffat@Sun.COM
To: psarc@Sun.COM
Cc: ef-core@Sun.COM
Message-id: <454A14EA.7030605@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
User-Agent: Thunderbird 1.5.0.5 (X11/20060926)
Status: RO
Content-Length: 55

This case is now closed approved.

-- 
Darren J Moffat

