Current Series Release Notes¶
23.0.0-13¶
New Features¶
The SimpleCrypto plugin now supports Elliptic Curve (EC) asymmetric key generation in addition to RSA and DSA. Supported EC curves are SECP256R1 (P-256), SECP384R1 (P-384), and SECP521R1 (P-521), selected by the
bit_lengthparameter in the API request (256, 384, or 521 respectively).
Upgrade Notes¶
Asymmetric key generation requests that do not specify an
algorithmparameter will now be rejected with an error. Previously, these requests defaulted to RSA. To avoid disruption, ensure all Order and key generation API calls include an explicitalgorithmvalue (RSA,DSA, orEC).
Security Issues¶
Bug #2165913: The container-consumer and secret-consumer
GETendpoints now verify that the requested consumer actually belongs to the container or secret named in the URL before returning it. Previously a consumer was looked up only by its own id while authorization was checked against the URL’s container/secret, allowing an authenticated user to read another tenant’s consumer metadata by pairing their own container/secret id with an arbitrary consumer id. A mismatch now returns 404.
Bug #2165908: The
barbican-manage dbcommand no longer prepends the current working directory tosys.path. Previously, a Python module placed in the invocation directory could shadow a module that barbican or one of its transitive dependencies imports, causing it to be imported and executed with the privileges of the operator running the command. Removing thesys.pathinsertion closes this module-shadowing path.
Bug Fixes¶
Fixed
barbican-managecallinglogging.setup()beforeCONFwas populated from the configuration files, causing logging to be configured with default settings instead of the ones frombarbican.conf.logging.setup()is now called after config parsing.