Current Series Release Notes

23.0.0-13

New Features

  • The SimpleCrypto plugin now supports Elliptic Curve (EC) asymmetric key generation in addition to RSA and DSA. Supported EC curves are SECP256R1 (P-256), SECP384R1 (P-384), and SECP521R1 (P-521), selected by the bit_length parameter in the API request (256, 384, or 521 respectively).

Upgrade Notes

  • Asymmetric key generation requests that do not specify an algorithm parameter will now be rejected with an error. Previously, these requests defaulted to RSA. To avoid disruption, ensure all Order and key generation API calls include an explicit algorithm value (RSA, DSA, or EC).

Security Issues

  • Bug #2165913: The container-consumer and secret-consumer GET endpoints now verify that the requested consumer actually belongs to the container or secret named in the URL before returning it. Previously a consumer was looked up only by its own id while authorization was checked against the URL’s container/secret, allowing an authenticated user to read another tenant’s consumer metadata by pairing their own container/secret id with an arbitrary consumer id. A mismatch now returns 404.

  • Bug #2165908: The barbican-manage db command no longer prepends the current working directory to sys.path. Previously, a Python module placed in the invocation directory could shadow a module that barbican or one of its transitive dependencies imports, causing it to be imported and executed with the privileges of the operator running the command. Removing the sys.path insertion closes this module-shadowing path.

Bug Fixes

  • Fixed barbican-manage calling logging.setup() before CONF was populated from the configuration files, causing logging to be configured with default settings instead of the ones from barbican.conf. logging.setup() is now called after config parsing.