Comment 22 for bug 1973296

Revision history for this message
bugproxy (bugproxy) wrote : Comment bridged from LTC Bugzilla

------- Comment From <email address hidden> 2022-06-07 10:25 EDT-------
Successfully tested this on 20.04 using https://launchpad.net/ubuntu/+source/opencryptoki/3.13.0+dfsg-0ubuntu5.2 from -proposed.

With original package (3.13.0+dfsg-0ubuntu5.1) and EP11 host library of 3.0.1, it does show support for the CKM_IBM_DILITHIUM mechanism. It also shows a firmware version of '3.1' wit pkcsconf -t for the EP11 token. Although '3.1' is actually wrong, this is still what is expected with the original opencryptoki package version (which has a version query bug leading to this incorrectness).

Once upgraded to the new version of the EP11 host library, it now shows a firmware version of '3.0' and CKM_IBM_DILITHIUM is no longer available. This is the error that this BZ is supposed to fix.

Next I upgraded opencryptoki to 3.13.0+dfsg-0ubuntu5.2 from -proposed. With that the firmware version shown by pkcsconf is back to '3.1' and CKM_IBM_DILITHIUM is available again.

So this confirms that the opencryptoki/3.13.0+dfsg-0ubuntu5.2 fixes the problem.

Changed keyword verification-needed-focal to verification-done-focal.