openCryptoki-32bit - An Implementation of PKCS#11 (Cryptoki) v2.11 for IBM Cryptographic Hardware

Property Value
Distribution openSUSE Tumbleweed
Repository Security all
Package filename openCryptoki-32bit-3.11.0-140.4.i586.rpm
Package name openCryptoki-32bit
Package version 3.11.0
Package release 140.4
Package architecture i586
Package type rpm
Category Productivity/Security
License CPL-1.0
Maintainer -
Download size 413.63 KB
Installed size 2.72 MB
This is a re-packaged binary rpm. For the package source, please look
for the source of the package without the "32bit" ending
The PKCS#11 version 2.11 API implemented for the IBM cryptographic
cards. This package includes support for the IBM 4758 cryptographic
coprocessor (with the PKCS#11 firmware loaded) and the IBM eServer
Cryptographic Accelerator (FC 4960 on pSeries).


Package Version Architecture Repository
openCryptoki-32bit-3.11.0-4.1.i586.rpm 3.11.0 i586 openSUSE Oss
openCryptoki-32bit - - -


Name Value - - - - - - - - - - - - - - -
openCryptoki -


Name Value - - - - - - - - - -
openCryptoki-32bit = 3.11.0-140.4
openCryptoki-32bit(x86-32) = 3.11.0-140.4


Type URL
Binary Package openCryptoki-32bit-3.11.0-140.4.i586.rpm
Source Package openCryptoki-3.11.0-140.4.src.rpm

Install Howto

  1. Add the Security repository:
    # zypper addrepo security
  2. Install openCryptoki-32bit rpm package:
    # zypper install openCryptoki-32bit




2019-02-15 -
- Added ocki-3.11-Fix-target_list-passing-for-EP11-session.patch
2018-11-30 - Jan Engelhardt <>
- Do not ignore errors from groupadd. If groupadd fails,
installation ought not to proceed because files would have the
wrong ownership.
2018-11-29 -
- Don't hide error messages from the groupadd command. To eliminate
a potentially common one, check to see if the pkcs11 group is
already defined before trying to add it.
- Update the summary for the -devel package.
- Changed several PreReq entries to Requires(pre) as a result of
the output from spec-cleaner. Removed a couple of obsolete lines.
- Removed obsolete check for whether systemd is in use or not.
2018-11-16 -
- Upgraded to version 3.11.0 (Fate#325685)
* opencryptoki 3.11.0
EP11 enhancements
A lot of bug fixes
- Reworked the ocki-3.1-remove-make-install-chgrp.patch to apply
properly to 3.11, and renamed it to
- Removed obsolete patch ocki-3.5-icsf-coverity-memoryleakfix.patch
2018-11-15 -
- Upgraded to version 3.10.0 (Fate#325685)
* opencryptoki 3.10.0
Add support to ECC on ICA token and to common code.
Add SHA224 support to SOFT token.
Improve pkcsslotd logging.
Fix sha512_hmac_sign and rsa_x509_verify for ICA token.
Fix tracing of session id.
Fix and improve testcases.
Fix spec file permission for log directory.
Fix build warnings.
* opencryptoki 3.9.0
Fix token reinitialization
Fix conditional man pages
EP11 enhancements
EP11 EC Key import
Increase RSA max key length
Fix broken links on documentation
Define CK_FALSE and CK_TRUE macros
Improve build flags
- Dropped obsolete patch ocki-3.8.2-Fix-Hardware-Feature-Object-validation-and-tests.patch
- Made multiple changes to the spec file based on spec-cleaner output.
- Added an rpmlintrc file to squelch warnings about adding ghost
entries for files under /var/log/opencryptoki/
2018-04-17 -
- Added ocki-3.8.2-Fix-Hardware-Feature-Object-validation-and-tests.patch
2018-03-09 -
- Re-enabled ARM architectures now that gcc6 is in SLE15. (bsc#1084617)
2017-11-30 -
- Upgraded to version 3.8.2 (fate#323295, bsc#1066412)
* v3.8.2
Update man pages.
Improve ock_tests for parallel execution.
Fix FindObjectsInit for hidden HW-feature.
Fix to allow vendor defined hardware features.
Fix unresolved symbols.
Fix tracing.
Code/project cleanup.
* v3.8.1
Fix TPM data-structure reset function.
Fix error message when dlsym fails.
Update travis.
* v3.8.0
Multi token instance feature.
Added possibility to run opencryptoki with transactional memory or locks
(--enable-locks on configure step).
Updated documentation.
Fix segfault on ec_test.
Bunch of small fixes.
2017-05-31 -
- Removed ARM architectures from the build list until gcc6 becomes
available for SLES. (bsc#1039510).
2017-05-12 -
- Updated to version 3.7.0 (Fate#321451) (bsc#1036640)
- Update example spec file
- Performance improvement. Moving from mutexes to transactional memory.
- Add ECDSA SHA2 support for EP11 and CCA.
- Fix declaration of inline functions.
- Fix wrong testcase and ber en/decoding for integers.
- Check for 'flex' and 'YACC' on configure.
- EP11 config file rework.
- Add enable-debug on travis build.
- Add testcase for C_GetOperationState/C_SetOperationState.
- Upgrade License to CPL-1.0
- Ica token: fix openssh/ibmpkcs11 engine/libica crash.
- Fix segfault and logic in hardware feature test.
- Fix spelling of documentation and manuals.
- Fix the retrieval of p from a generated rsa key.
- Coverity scan fixes - incompatible pointer type and unused variables.

See Also

Package Description
openCryptoki-64bit-3.11.0-140.4.x86_64.rpm An Implementation of PKCS#11 (Cryptoki) v2.11 for IBM Cryptographic Hardware
openCryptoki-devel-3.11.0-140.4.i586.rpm Development files for openCryptoki, a PKCS#11 implementation for IBM hardware
openCryptoki-devel-3.11.0-140.4.x86_64.rpm Development files for openCryptoki, a PKCS#11 implementation for IBM hardware
openscap-1.3.0-220.1.i586.rpm A Set of Libraries for Integration with SCAP
openscap-1.3.0-220.1.x86_64.rpm A Set of Libraries for Integration with SCAP
openscap-content-1.3.0-220.1.i586.rpm SCAP content
openscap-content-1.3.0-220.1.x86_64.rpm SCAP content
openscap-devel-1.3.0-220.1.i586.rpm Development Files for OpenSCAP
openscap-devel-1.3.0-220.1.x86_64.rpm Development Files for OpenSCAP
openscap-docker-1.3.0-220.1.i586.rpm Docker plugin for OpenSCAP
openscap-docker-1.3.0-220.1.x86_64.rpm Docker plugin for OpenSCAP
openscap-utils-1.3.0-220.1.i586.rpm Openscap utilities
openscap-utils-1.3.0-220.1.x86_64.rpm Openscap utilities
ovaldi- The OVAL reference interpreter
ovaldi- The OVAL reference interpreter