)]}'
{"barbican/plugin/crypto/p11_crypto.py":[{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"42af947e91e2451330a39e3f610885ecbf2400fa","unresolved":true,"context_lines":[{"line_number":343,"context_line":"        passphrase \u003d generate_dto.passphrase"},{"line_number":344,"context_line":""},{"line_number":345,"context_line":"        if algorithm \u003d\u003d \u0027rsa\u0027:"},{"line_number":346,"context_line":"            private_key \u003d rsa.generate_private_key("},{"line_number":347,"context_line":"                public_exponent\u003d65537,"},{"line_number":348,"context_line":"                key_size\u003dbit_length,"},{"line_number":349,"context_line":"            )"}],"source_content_type":"text/x-python","patch_set":3,"id":"06d291e8_2ac21bcd","line":346,"range":{"start_line":346,"start_character":26,"end_line":346,"end_character":51},"updated":"2026-09-25 15:40:21.000000000","message":"This is probably not what we want to do here.  Essentially what you are doing here is using cryptography to generate keys in memory - and then passing those to the HSM to store them.\n\nThats different from passing a request to the HSM device to generate the key there.  That involves using the C_GenerateKeyPair call or similar in the pkcs11.py layer.\n\nIf you look at generate_symmetric() here, you will see that we are actually calling into the pkcs11 layer and making calls to C_GenerateKey to generate the symmetric key on the HSM.\n\nSo - implementing his means work on the pkcs11.py layer to add support for C_GenerateKeyPair and then calling the relevant function.","commit_id":"9b14ca67f70e799f90cc3f8daa809530344f9500"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"2d6f2558e029eaa5509506626706ff8d3ed755aa","unresolved":true,"context_lines":[{"line_number":343,"context_line":"        passphrase \u003d generate_dto.passphrase"},{"line_number":344,"context_line":""},{"line_number":345,"context_line":"        if algorithm \u003d\u003d \u0027rsa\u0027:"},{"line_number":346,"context_line":"            private_key \u003d rsa.generate_private_key("},{"line_number":347,"context_line":"                public_exponent\u003d65537,"},{"line_number":348,"context_line":"                key_size\u003dbit_length,"},{"line_number":349,"context_line":"            )"}],"source_content_type":"text/x-python","patch_set":3,"id":"153b0957_43c76e4b","line":346,"range":{"start_line":346,"start_character":26,"end_line":346,"end_character":51},"in_reply_to":"06d291e8_2ac21bcd","updated":"2026-09-25 15:44:19.000000000","message":"As you are doing this, you might want to rebase on top of https://review.opendev.org/c/openstack/barbican/+/1004026  and add to the tests there.  This will give you a softhsm pkcs11 gate to test against.","commit_id":"9b14ca67f70e799f90cc3f8daa809530344f9500"}]}
