[Pkg-freeipa-devel] [Git][freeipa-team/jss][master] 23 commits: control: Update standards version.

Timo Aaltonen (@tjaalton) gitlab at salsa.debian.org
Sun Sep 27 18:08:01 BST 2026



Timo Aaltonen pushed to branch master at FreeIPA packaging / jss


Commits:
5d338b70 by Jarl Gullberg at 2026-09-27T11:57:59+02:00
control: Update standards version.

- - - - -
1b80a5d2 by Jarl Gullberg at 2026-09-27T11:59:00+02:00
control: package libjss-tools.

- - - - -
98b07eba by Jarl Gullberg at 2026-09-27T11:59:24+02:00
control: reformat first line.

- - - - -
af8bef39 by Jarl Gullberg at 2026-09-27T12:04:38+02:00
rules: use pkg-info.mk in gentarball

Parsing the changelog is discouraged in modern packaging workflows.

- - - - -
30dd49b8 by Jarl Gullberg at 2026-09-27T12:05:12+02:00
rules: exclude debian/ from gentarball.

- - - - -
9d2800c9 by Jarl Gullberg at 2026-09-27T12:05:34+02:00
rules: respect nocheck build profile.

- - - - -
d5e54b17 by Jarl Gullberg at 2026-09-27T13:32:59+02:00
rules: remove dh_clean override

- - - - -
b951fc11 by Jarl Gullberg at 2026-09-27T13:33:24+02:00
rules: remove unused variables.

- - - - -
9e66534f by Jarl Gullberg at 2026-09-27T13:33:43+02:00
rules: update override_dh_auto_configure with new maven+cmake build steps.

- - - - -
6089068b by Jarl Gullberg at 2026-09-27T13:33:59+02:00
rules: add override_dh_auto_clean for new maven+cmake build steps.

- - - - -
f302ca70 by Jarl Gullberg at 2026-09-27T13:34:01+02:00
rules: use more fault-evident symlink invocations

- - - - -
6167e0f5 by Jarl Gullberg at 2026-09-27T13:34:02+02:00
rules: use standard flags for build and install

- - - - -
37fb8c9d by Jarl Gullberg at 2026-09-27T13:34:03+02:00
rules: move non-installed files to debian/not-installed

- - - - -
cac7a066 by Jarl Gullberg at 2026-09-27T13:34:04+02:00
rules: don't delete the tool programs

- - - - -
04dde2a6 by Jarl Gullberg at 2026-09-27T13:34:05+02:00
use javahelper to correctly install jss.jar.

- - - - -
d88251b3 by Jarl Gullberg at 2026-09-27T13:34:06+02:00
rules: enable all hardening flags.

- - - - -
04dcd9ff by Jarl Gullberg at 2026-09-27T13:34:07+02:00
rules: remove redundant removal of javadoc directory.

- - - - -
84361f9b by Jarl Gullberg at 2026-09-27T13:34:08+02:00
patches: remove upstreamed patch.

- - - - -
8db54a03 by Jarl Gullberg at 2026-09-27T13:34:09+02:00
patches: add forwarded patch for unguarded access to PQ algorithm code

- - - - -
f3d5de7e by Jarl Gullberg at 2026-09-27T13:34:10+02:00
patches: add forwarded patch for maven artifact versions

- - - - -
86b5e86b by Jarl Gullberg at 2026-09-27T13:34:11+02:00
control: add missing separator between dependency variables.

- - - - -
32ceebce by Jarl Gullberg at 2026-09-27T13:34:12+02:00
control: mark replacement of libtomcatjss-java

JSS Connector for Apache Tomcat version 8.5 was merged into JSS 5.5,
making libtomcatjss-java obsolete.

- - - - -
c4f44ff4 by Jarl Gullberg at 2026-09-27T13:34:13+02:00
copyright: update license and copyright data

- - - - -


11 changed files:

- debian/control
- debian/copyright
- debian/libjss-java.install
- + debian/libjss-java.jlibs
- + debian/lrc.config
- + debian/not-installed
- − debian/patches/0001-fix-use-size_t-in-call-to-JSS_FromByteArray.patch
- + debian/patches/fix-ml-kem-dsa.patch
- + debian/patches/fix-versions.diff
- debian/patches/series
- debian/rules


Changes:

=====================================
debian/control
=====================================
@@ -3,9 +3,11 @@ Section: java
 Maintainer: Debian FreeIPA Team <pkg-freeipa-devel at alioth-lists.debian.net>
 Uploaders: Timo Aaltonen <tjaalton at debian.org>,
 Priority: optional
-Build-Depends: debhelper-compat (= 13),
+Build-Depends:
+ debhelper-compat (= 13),
  cmake (>= 3.14),
  default-jdk,
+ javahelper,
  junit5,
  libcommons-codec-java,
  libcommons-lang3-java,
@@ -18,7 +20,7 @@ Build-Depends: debhelper-compat (= 13),
  quilt,
  unzip,
  zip,
-Standards-Version: 4.6.1
+Standards-Version: 4.7.2
 Vcs-Git: https://salsa.debian.org/freeipa-team/jss.git
 Vcs-Browser: https://salsa.debian.org/freeipa-team/jss
 Homepage: https://github.com/dogtagpki/jss
@@ -27,21 +29,28 @@ Package: libjss-java
 Architecture: any
 Depends:
  ${shlibs:Depends},
- ${maven:Depends}
- ${misc:Depends},
+ ${maven:Depends},
+ ${misc:Depends}
+Breaks:
+ libtomcatjss-java (<< 8.5.0)
+Replaces:
+ libtomcatjss-java (<< 8.5.0)
 Description: Network Security Services for Java
  Network Security Services for Java (JSS) is a Java interface
  to NSS. It supports most of the security standards and
  encryption technologies supported by NSS. JSS also provides
  a pure Java interface for ASN.1 types and BER/DER encoding.
 
-#Package: libjss-tools
-#Architecture: any
-#Depends: ${shlibs:Depends}, ${misc:Depends},
-#Description: Network Security Services for Java -- tools
-# Network Security Services for Java (JSS) is a Java interface
-# to NSS. It supports most of the security standards and
-# encryption technologies supported by NSS. JSS also provides
-# a pure Java interface for ASN.1 types and BER/DER encoding.
-# .
-# This package includes JSS tools.
+Package: libjss-tools
+Architecture: any
+Depends:
+ ${shlibs:Depends},
+ ${misc:Depends}
+Description: Network Security Services for Java -- tools
+ Network Security Services for Java (JSS) is a Java interface
+ to NSS. It supports most of the security standards and
+ encryption technologies supported by NSS. JSS also provides
+ a pure Java interface for ASN.1 types and BER/DER encoding.
+ .
+ This package contains utility tools from JSS.
+


=====================================
debian/copyright
=====================================
@@ -1,590 +1,186 @@
-X-Format-Specification: http://wiki.debian.org/Proposals/CopyrightFormat
-X-Debianized-By: Michele Baldessari <michele at acksyn.org>
-X-Debianized-Date: Thu, 27 Mar 2008 23:36:42 +0200.
-X-Source-Downloaded-From: ftp://ftp.mozilla.org/pub/mozilla.org/security/jss/releases/
+Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
+Upstream-Name: jss
+Upstream-Contact:
+ Developers <devel at lists.dogtagpki.org>
+Source: https://github.com/dogtagpki/jss
+
+Files: *
+Copyright:
+ © 1998 Netscape Communications Corporation
+ © 1998-2008 The Mozilla Project
+License: GPL-2+ or LGPL-2.1+ or MPL-1.1 or MPL-2.0
+
+Files:
+ tools/src/main/native/sslget/sslget.c
+Copyright:
+ © 1998 Netscape Communications Corporation
+ © 1998-2008 The Mozilla Project
+License: GPL-2
+
+Files:
+ tools/src/main/native/sslget/getopt.c
+Copyright:
+ © 1998 Netscape Communications Corporation
+ © 1998-2008 The Mozilla Project
+License: GPL-2+ or MPL-1.1
+
+Files:
+ base/src/main/java/org/mozilla/jss/*
+ native/src/main/native/org/mozilla/jss/*
+ tools/src/main/native/p12tool/*
+ base/src/test/java/org/mozilla/jss/tests/*
+ examples/src/main/java/examples/pkcs12.java
+ examples/src/main/java/examples/PQGGen.java
+ lib/jss.map
+Copyright:
+ © 1998 Netscape Communications Corporation
+ © 1998-2008 The Mozilla Project
+License: MPL-2.0
+
+Files:
+ tools/src/main/native/p7tool/*
+ base/src/main/java/org/mozilla/jss/crypto/SymmetricKeyDeriver.java
+ base/src/main/java/org/mozilla/jss/pkcs11/PK11SymmetricKeyDeriver.java
+ base/src/main/java/org/mozilla/jss/pkix/cmc/BodyPartReference.java
+ base/src/main/java/org/mozilla/jss/pkix/cmc/CMCStatusInfoV2.java
+ base/src/main/java/org/mozilla/jss/pkix/cmc/DecryptedPOP.java
+ base/src/main/java/org/mozilla/jss/pkix/cmc/EncryptedPOP.java
+ base/src/main/java/org/mozilla/jss/pkix/cmc/ExtendedFailInfo.java
+ base/src/main/java/org/mozilla/jss/pkix/cmc/IdentityProofV2.java
+ base/src/main/java/org/mozilla/jss/pkix/cmc/OtherReqMsg.java
+ base/src/main/java/org/mozilla/jss/pkix/cmc/PopLinkWitnessV2.java
+ base/src/main/java/org/mozilla/jss/pkix/cmc/RevokeRequest.java
+ base/src/test/java/org/mozilla/jss/tests/SymKeyDeriving.java
+ native/src/main/native/org/mozilla/jss/asn1/ASN1Util.c
+Copyright:
+ © 1998 Netscape Communications Corporation
+ © 1998-2008 The Mozilla Project
+License: GPL-2+ or LGPL-2.1+ or MPL-1.1
+
+Files:
+ tomcat-9.0/src/main/java/org/dogtagpki/jss/tomcat/*
+ tomcat-10.1/src/main/java/org/dogtagpki/jss/tomcat/*
+ tomcat/src/main/java/org/dogtagpki/jss/tomcat/*
+Copyright:
+ © 1998 Netscape Communications Corporation
+ © 1998-2008 The Mozilla Project
+License: LGPL-2.1+
+
+Files:
+ tomcat-10.1/src/main/java/org/dogtagpki/jss/tomcat/JSSNioEndpoint.java
+ tomcat-10.1/src/main/java/org/dogtagpki/jss/tomcat/JSSSecureNioChannel.java
+ tomcat-9.0/src/main/java/org/dogtagpki/jss/tomcat/JSSNioEndpoint.java
+ tomcat-9.0/src/main/java/org/dogtagpki/jss/tomcat/JSSSecureNioChannel.java
+Copyright:
+ © 1998 Netscape Communications Corporation
+ © 1998-2008 The Mozilla Project
+ 2017 Red Hat, Inc.
+License: Apache-2.0 or LGPL-2.1+
+
+Files:
+ symkey/*
+ base/src/main/java/org/mozilla/jss/symkey/*
+ base/src/main/java/org/mozilla/jss/netscape/*
+ base/src/main/java/org/mozilla/jss/provider/javax/crypto/*
+ base/src/main/java/org/mozilla/jss/pkcs11/PK11DSAParams.java
+Copyright: 2007 Red Hat, Inc.
+License: GPL-2
+
+Files:
+ base/src/test/java/org/mozilla/jss/tests/EnumerationZeroTest.java
+Copyright: 2009-2018 Red Hat, Inc.
+License: GPL-2
+
+Files:
+ base/src/main/java/org/mozilla/jss/crypto/KEMAlgorithm.java
+ base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSKEMDecapsulatorSpi.java
+ base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSKEMEncapsulatorSpi.java
+ base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSKEMSpi.java
+ base/src/test/java/org/mozilla/jss/tests/KeyEncapsulating.java
+ base/src/test/java/org/mozilla/jss/tests/MLKEMKeyWrapping.java
+ native/src/main/native/org/mozilla/jss/provider/javax/crypto/JSSKEMDecapsulatorSpi.c
+ native/src/main/native/org/mozilla/jss/provider/javax/crypto/JSSKEMEncapsulatorSpi.c
+ Dockerfile
+Copyright: Red Hat, Inc.
+License: GPL-2+
+
+Files:
+ base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSTokenKeyManager.java
+ base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSTrustManager.java
+Copyright: 2007 Red Hat, Inc.
+License: LGPL-2.1+
+
+Files: tools/logging.properties
+Copyright: 2020 Red Hat, Inc.
+License: Apache-2.0
+
+Files:
+ cmake/FindNSPR.cmake
+ cmake/FindNSS.cmake
+Copyright: 2006-2010, Andreas Schneider <asn at redhat.com>
+License: BSD-3-clause
+
+Files:
+ cmake/Java.cmake
+ cmake/JavaFileList.cmake
+Copyright:
+ 2012 Red Hat, Inc.
+License: GPL-2
+
+Files:
+ jss.spec
+Copyright:
+ 2012 Red Hat, Inc.
+License: MPL-1.1
 
-Files: mozilla/security/coreconf/*, mozilla/security/jss/Makefile,
- mozilla/security/jss/manifest.nm, mozilla/security/jss/config/*,
- mozilla/security/jss/lib/*, mozilla/security/jss/org/mozilla/jss/*,
- mozilla/security/jss/samples/*
-Copyright: © 1998 Netscape Communications Corporation
-           © 1998-2008 The Mozilla Project
-License: LGPL-2.1+ | GPL-2+ | MPL-1.1
- 
 Files: debian/*
 Copyright: © 2008 Michele Baldessari <michele at acksyn.org>
-License: LGPL-2.1+ | GPL-2+ | MPL-1.1
-
-Licence: MPL-1.1
-                          MOZILLA PUBLIC LICENSE
-                                Version 1.1
-
-                              ---------------
-
- 1. Definitions.
-
-     1.0.1. "Commercial Use" means distribution or otherwise making the
-     Covered Code available to a third party.
-
-     1.1. "Contributor" means each entity that creates or contributes to
-     the creation of Modifications.
-
-     1.2. "Contributor Version" means the combination of the Original
-     Code, prior Modifications used by a Contributor, and the Modifications
-     made by that particular Contributor.
-
-     1.3. "Covered Code" means the Original Code or Modifications or the
-     combination of the Original Code and Modifications, in each case
-     including portions thereof.
-
-     1.4. "Electronic Distribution Mechanism" means a mechanism generally
-     accepted in the software development community for the electronic
-     transfer of data.
-
-     1.5. "Executable" means Covered Code in any form other than Source
-     Code.
-
-     1.6. "Initial Developer" means the individual or entity identified
-     as the Initial Developer in the Source Code notice required by Exhibit
-     A.
-
-     1.7. "Larger Work" means a work which combines Covered Code or
-     portions thereof with code not governed by the terms of this License.
-
-     1.8. "License" means this document.
-
-     1.8.1. "Licensable" means having the right to grant, to the maximum
-     extent possible, whether at the time of the initial grant or
-     subsequently acquired, any and all of the rights conveyed herein.
-
-     1.9. "Modifications" means any addition to or deletion from the
-     substance or structure of either the Original Code or any previous
-     Modifications. When Covered Code is released as a series of files, a
-     Modification is:
-          A. Any addition to or deletion from the contents of a file
-          containing Original Code or previous Modifications.
-
-          B. Any new file that contains any part of the Original Code or
-          previous Modifications.
-
-     1.10. "Original Code" means Source Code of computer software code
-     which is described in the Source Code notice required by Exhibit A as
-     Original Code, and which, at the time of its release under this
-     License is not already Covered Code governed by this License.
-
-     1.10.1. "Patent Claims" means any patent claim(s), now owned or
-     hereafter acquired, including without limitation,  method, process,
-     and apparatus claims, in any patent Licensable by grantor.
-
-     1.11. "Source Code" means the preferred form of the Covered Code for
-     making modifications to it, including all modules it contains, plus
-     any associated interface definition files, scripts used to control
-     compilation and installation of an Executable, or source code
-     differential comparisons against either the Original Code or another
-     well known, available Covered Code of the Contributor's choice. The
-     Source Code can be in a compressed or archival form, provided the
-     appropriate decompression or de-archiving software is widely available
-     for no charge.
-
-     1.12. "You" (or "Your")  means an individual or a legal entity
-     exercising rights under, and complying with all of the terms of, this
-     License or a future version of this License issued under Section 6.1.
-     For legal entities, "You" includes any entity which controls, is
-     controlled by, or is under common control with You. For purposes of
-     this definition, "control" means (a) the power, direct or indirect,
-     to cause the direction or management of such entity, whether by
-     contract or otherwise, or (b) ownership of more than fifty percent
-     (50%) of the outstanding shares or beneficial ownership of such
-     entity.
-
- 2. Source Code License.
-
-     2.1. The Initial Developer Grant.
-     The Initial Developer hereby grants You a world-wide, royalty-free,
-     non-exclusive license, subject to third party intellectual property
-     claims:
-          (a)  under intellectual property rights (other than patent or
-          trademark) Licensable by Initial Developer to use, reproduce,
-          modify, display, perform, sublicense and distribute the Original
-          Code (or portions thereof) with or without Modifications, and/or
-          as part of a Larger Work; and
-
-          (b) under Patents Claims infringed by the making, using or
-          selling of Original Code, to make, have made, use, practice,
-          sell, and offer for sale, and/or otherwise dispose of the
-          Original Code (or portions thereof).
-
-          (c) the licenses granted in this Section 2.1(a) and (b) are
-          effective on the date Initial Developer first distributes
-          Original Code under the terms of this License.
-
-          (d) Notwithstanding Section 2.1(b) above, no patent license is
-          granted: 1) for code that You delete from the Original Code; 2)
-          separate from the Original Code;  or 3) for infringements caused
-          by: i) the modification of the Original Code or ii) the
-          combination of the Original Code with other software or devices.
-
-     2.2. Contributor Grant.
-     Subject to third party intellectual property claims, each Contributor
-     hereby grants You a world-wide, royalty-free, non-exclusive license
-
-          (a)  under intellectual property rights (other than patent or
-          trademark) Licensable by Contributor, to use, reproduce, modify,
-          display, perform, sublicense and distribute the Modifications
-          created by such Contributor (or portions thereof) either on an
-          unmodified basis, with other Modifications, as Covered Code
-          and/or as part of a Larger Work; and
-
-          (b) under Patent Claims infringed by the making, using, or
-          selling of  Modifications made by that Contributor either alone
-          and/or in combination with its Contributor Version (or portions
-          of such combination), to make, use, sell, offer for sale, have
-          made, and/or otherwise dispose of: 1) Modifications made by that
-          Contributor (or portions thereof); and 2) the combination of
-          Modifications made by that Contributor with its Contributor
-          Version (or portions of such combination).
-
-          (c) the licenses granted in Sections 2.2(a) and 2.2(b) are
-          effective on the date Contributor first makes Commercial Use of
-          the Covered Code.
-
-          (d)    Notwithstanding Section 2.2(b) above, no patent license is
-          granted: 1) for any code that Contributor has deleted from the
-          Contributor Version; 2)  separate from the Contributor Version;
-          3)  for infringements caused by: i) third party modifications of
-          Contributor Version or ii)  the combination of Modifications made
-          by that Contributor with other software  (except as part of the
-          Contributor Version) or other devices; or 4) under Patent Claims
-          infringed by Covered Code in the absence of Modifications made by
-          that Contributor.
-
- 3. Distribution Obligations.
-
-     3.1. Application of License.
-     The Modifications which You create or to which You contribute are
-     governed by the terms of this License, including without limitation
-     Section 2.2. The Source Code version of Covered Code may be
-     distributed only under the terms of this License or a future version
-     of this License released under Section 6.1, and You must include a
-     copy of this License with every copy of the Source Code You
-     distribute. You may not offer or impose any terms on any Source Code
-     version that alters or restricts the applicable version of this
-     License or the recipients' rights hereunder. However, You may include
-     an additional document offering the additional rights described in
-     Section 3.5.
-
-     3.2. Availability of Source Code.
-     Any Modification which You create or to which You contribute must be
-     made available in Source Code form under the terms of this License
-     either on the same media as an Executable version or via an accepted
-     Electronic Distribution Mechanism to anyone to whom you made an
-     Executable version available; and if made available via Electronic
-     Distribution Mechanism, must remain available for at least twelve (12)
-     months after the date it initially became available, or at least six
-     (6) months after a subsequent version of that particular Modification
-     has been made available to such recipients. You are responsible for
-     ensuring that the Source Code version remains available even if the
-     Electronic Distribution Mechanism is maintained by a third party.
-
-     3.3. Description of Modifications.
-     You must cause all Covered Code to which You contribute to contain a
-     file documenting the changes You made to create that Covered Code and
-     the date of any change. You must include a prominent statement that
-     the Modification is derived, directly or indirectly, from Original
-     Code provided by the Initial Developer and including the name of the
-     Initial Developer in (a) the Source Code, and (b) in any notice in an
-     Executable version or related documentation in which You describe the
-     origin or ownership of the Covered Code.
-
-     3.4. Intellectual Property Matters
-          (a) Third Party Claims.
-          If Contributor has knowledge that a license under a third party's
-          intellectual property rights is required to exercise the rights
-          granted by such Contributor under Sections 2.1 or 2.2,
-          Contributor must include a text file with the Source Code
-          distribution titled "LEGAL" which describes the claim and the
-          party making the claim in sufficient detail that a recipient will
-          know whom to contact. If Contributor obtains such knowledge after
-          the Modification is made available as described in Section 3.2,
-          Contributor shall promptly modify the LEGAL file in all copies
-          Contributor makes available thereafter and shall take other steps
-          (such as notifying appropriate mailing lists or newsgroups)
-          reasonably calculated to inform those who received the Covered
-          Code that new knowledge has been obtained.
-
-          (b) Contributor APIs.
-          If Contributor's Modifications include an application programming
-          interface and Contributor has knowledge of patent licenses which
-          are reasonably necessary to implement that API, Contributor must
-          also include this information in the LEGAL file.
-
-               (c)    Representations.
-          Contributor represents that, except as disclosed pursuant to
-          Section 3.4(a) above, Contributor believes that Contributor's
-          Modifications are Contributor's original creation(s) and/or
-          Contributor has sufficient rights to grant the rights conveyed by
-          this License.
-
-     3.5. Required Notices.
-     You must duplicate the notice in Exhibit A in each file of the Source
-     Code.  If it is not possible to put such notice in a particular Source
-     Code file due to its structure, then You must include such notice in a
-     location (such as a relevant directory) where a user would be likely
-     to look for such a notice.  If You created one or more Modification(s)
-     You may add your name as a Contributor to the notice described in
-     Exhibit A.  You must also duplicate this License in any documentation
-     for the Source Code where You describe recipients' rights or ownership
-     rights relating to Covered Code.  You may choose to offer, and to
-     charge a fee for, warranty, support, indemnity or liability
-     obligations to one or more recipients of Covered Code. However, You
-     may do so only on Your own behalf, and not on behalf of the Initial
-     Developer or any Contributor. You must make it absolutely clear than
-     any such warranty, support, indemnity or liability obligation is
-     offered by You alone, and You hereby agree to indemnify the Initial
-     Developer and every Contributor for any liability incurred by the
-     Initial Developer or such Contributor as a result of warranty,
-     support, indemnity or liability terms You offer.
-
-     3.6. Distribution of Executable Versions.
-     You may distribute Covered Code in Executable form only if the
-     requirements of Section 3.1-3.5 have been met for that Covered Code,
-     and if You include a notice stating that the Source Code version of
-     the Covered Code is available under the terms of this License,
-     including a description of how and where You have fulfilled the
-     obligations of Section 3.2. The notice must be conspicuously included
-     in any notice in an Executable version, related documentation or
-     collateral in which You describe recipients' rights relating to the
-     Covered Code. You may distribute the Executable version of Covered
-     Code or ownership rights under a license of Your choice, which may
-     contain terms different from this License, provided that You are in
-     compliance with the terms of this License and that the license for the
-     Executable version does not attempt to limit or alter the recipient's
-     rights in the Source Code version from the rights set forth in this
-     License. If You distribute the Executable version under a different
-     license You must make it absolutely clear that any terms which differ
-     from this License are offered by You alone, not by the Initial
-     Developer or any Contributor. You hereby agree to indemnify the
-     Initial Developer and every Contributor for any liability incurred by
-     the Initial Developer or such Contributor as a result of any such
-     terms You offer.
-
-     3.7. Larger Works.
-     You may create a Larger Work by combining Covered Code with other code
-     not governed by the terms of this License and distribute the Larger
-     Work as a single product. In such a case, You must make sure the
-     requirements of this License are fulfilled for the Covered Code.
-
- 4. Inability to Comply Due to Statute or Regulation.
-
-     If it is impossible for You to comply with any of the terms of this
-     License with respect to some or all of the Covered Code due to
-     statute, judicial order, or regulation then You must: (a) comply with
-     the terms of this License to the maximum extent possible; and (b)
-     describe the limitations and the code they affect. Such description
-     must be included in the LEGAL file described in Section 3.4 and must
-     be included with all distributions of the Source Code. Except to the
-     extent prohibited by statute or regulation, such description must be
-     sufficiently detailed for a recipient of ordinary skill to be able to
-     understand it.
-
- 5. Application of this License.
-
-     This License applies to code to which the Initial Developer has
-     attached the notice in Exhibit A and to related Covered Code.
-
- 6. Versions of the License.
-
-     6.1. New Versions.
-     Netscape Communications Corporation ("Netscape") may publish revised
-     and/or new versions of the License from time to time. Each version
-     will be given a distinguishing version number.
-
-     6.2. Effect of New Versions.
-     Once Covered Code has been published under a particular version of the
-     License, You may always continue to use it under the terms of that
-     version. You may also choose to use such Covered Code under the terms
-     of any subsequent version of the License published by Netscape. No one
-     other than Netscape has the right to modify the terms applicable to
-     Covered Code created under this License.
-
-     6.3. Derivative Works.
-     If You create or use a modified version of this License (which you may
-     only do in order to apply it to code which is not already Covered Code
-     governed by this License), You must (a) rename Your license so that
-     the phrases "Mozilla", "MOZILLAPL", "MOZPL", "Netscape",
-     "MPL", "NPL" or any confusingly similar phrase do not appear in your
-     license (except to note that your license differs from this License)
-     and (b) otherwise make it clear that Your version of the license
-     contains terms which differ from the Mozilla Public License and
-     Netscape Public License. (Filling in the name of the Initial
-     Developer, Original Code or Contributor in the notice described in
-     Exhibit A shall not of themselves be deemed to be modifications of
-     this License.)
-
- 7. DISCLAIMER OF WARRANTY.
-
-     COVERED CODE IS PROVIDED UNDER THIS LICENSE ON AN "AS IS" BASIS,
-     WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING,
-     WITHOUT LIMITATION, WARRANTIES THAT THE COVERED CODE IS FREE OF
-     DEFECTS, MERCHANTABLE, FIT FOR A PARTICULAR PURPOSE OR NON-INFRINGING.
-     THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE COVERED CODE
-     IS WITH YOU. SHOULD ANY COVERED CODE PROVE DEFECTIVE IN ANY RESPECT,
-     YOU (NOT THE INITIAL DEVELOPER OR ANY OTHER CONTRIBUTOR) ASSUME THE
-     COST OF ANY NECESSARY SERVICING, REPAIR OR CORRECTION. THIS DISCLAIMER
-     OF WARRANTY CONSTITUTES AN ESSENTIAL PART OF THIS LICENSE. NO USE OF
-     ANY COVERED CODE IS AUTHORIZED HEREUNDER EXCEPT UNDER THIS DISCLAIMER.
-
- 8. TERMINATION.
-
-     8.1.  This License and the rights granted hereunder will terminate
-     automatically if You fail to comply with terms herein and fail to cure
-     such breach within 30 days of becoming aware of the breach. All
-     sublicenses to the Covered Code which are properly granted shall
-     survive any termination of this License. Provisions which, by their
-     nature, must remain in effect beyond the termination of this License
-     shall survive.
-
-     8.2.  If You initiate litigation by asserting a patent infringement
-     claim (excluding declatory judgment actions) against Initial Developer
-     or a Contributor (the Initial Developer or Contributor against whom
-     You file such action is referred to as "Participant")  alleging that:
-
-     (a)  such Participant's Contributor Version directly or indirectly
-     infringes any patent, then any and all rights granted by such
-     Participant to You under Sections 2.1 and/or 2.2 of this License
-     shall, upon 60 days notice from Participant terminate prospectively,
-     unless if within 60 days after receipt of notice You either: (i)
-     agree in writing to pay Participant a mutually agreeable reasonable
-     royalty for Your past and future use of Modifications made by such
-     Participant, or (ii) withdraw Your litigation claim with respect to
-     the Contributor Version against such Participant.  If within 60 days
-     of notice, a reasonable royalty and payment arrangement are not
-     mutually agreed upon in writing by the parties or the litigation claim
-     is not withdrawn, the rights granted by Participant to You under
-     Sections 2.1 and/or 2.2 automatically terminate at the expiration of
-     the 60 day notice period specified above.
-
-     (b)  any software, hardware, or device, other than such Participant's
-     Contributor Version, directly or indirectly infringes any patent, then
-     any rights granted to You by such Participant under Sections 2.1(b)
-     and 2.2(b) are revoked effective as of the date You first made, used,
-     sold, distributed, or had made, Modifications made by that
-     Participant.
-
-     8.3.  If You assert a patent infringement claim against Participant
-     alleging that such Participant's Contributor Version directly or
-     indirectly infringes any patent where such claim is resolved (such as
-     by license or settlement) prior to the initiation of patent
-     infringement litigation, then the reasonable value of the licenses
-     granted by such Participant under Sections 2.1 or 2.2 shall be taken
-     into account in determining the amount or value of any payment or
-     license.
-
-     8.4.  In the event of termination under Sections 8.1 or 8.2 above,
-     all end user license agreements (excluding distributors and resellers)
-     which have been validly granted by You or any distributor hereunder
-     prior to termination shall survive termination.
-
- 9. LIMITATION OF LIABILITY.
-
-     UNDER NO CIRCUMSTANCES AND UNDER NO LEGAL THEORY, WHETHER TORT
-     (INCLUDING NEGLIGENCE), CONTRACT, OR OTHERWISE, SHALL YOU, THE INITIAL
-     DEVELOPER, ANY OTHER CONTRIBUTOR, OR ANY DISTRIBUTOR OF COVERED CODE,
-     OR ANY SUPPLIER OF ANY OF SUCH PARTIES, BE LIABLE TO ANY PERSON FOR
-     ANY INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES OF ANY
-     CHARACTER INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF GOODWILL,
-     WORK STOPPAGE, COMPUTER FAILURE OR MALFUNCTION, OR ANY AND ALL OTHER
-     COMMERCIAL DAMAGES OR LOSSES, EVEN IF SUCH PARTY SHALL HAVE BEEN
-     INFORMED OF THE POSSIBILITY OF SUCH DAMAGES. THIS LIMITATION OF
-     LIABILITY SHALL NOT APPLY TO LIABILITY FOR DEATH OR PERSONAL INJURY
-     RESULTING FROM SUCH PARTY'S NEGLIGENCE TO THE EXTENT APPLICABLE LAW
-     PROHIBITS SUCH LIMITATION. SOME JURISDICTIONS DO NOT ALLOW THE
-     EXCLUSION OR LIMITATION OF INCIDENTAL OR CONSEQUENTIAL DAMAGES, SO
-     THIS EXCLUSION AND LIMITATION MAY NOT APPLY TO YOU.
-
- 10. U.S. GOVERNMENT END USERS.
-
-     The Covered Code is a "commercial item," as that term is defined in
-     48 C.F.R. 2.101 (Oct. 1995), consisting of "commercial computer
-     software" and "commercial computer software documentation," as such
-     terms are used in 48 C.F.R. 12.212 (Sept. 1995). Consistent with 48
-     C.F.R. 12.212 and 48 C.F.R. 227.7202-1 through 227.7202-4 (June 1995),
-     all U.S. Government End Users acquire Covered Code with only those
-     rights set forth herein.
-
- 11. MISCELLANEOUS.
-
-     This License represents the complete agreement concerning subject
-     matter hereof. If any provision of this License is held to be
-     unenforceable, such provision shall be reformed only to the extent
-     necessary to make it enforceable. This License shall be governed by
-     California law provisions (except to the extent applicable law, if
-     any, provides otherwise), excluding its conflict-of-law provisions.
-     With respect to disputes in which at least one party is a citizen of,
-     or an entity chartered or registered to do business in the United
-     States of America, any litigation relating to this License shall be
-     subject to the jurisdiction of the Federal Courts of the Northern
-     District of California, with venue lying in Santa Clara County,
-     California, with the losing party responsible for costs, including
-     without limitation, court costs and reasonable attorneys' fees and
-     expenses. The application of the United Nations Convention on
-     Contracts for the International Sale of Goods is expressly excluded.
-     Any law or regulation which provides that the language of a contract
-     shall be construed against the drafter shall not apply to this
-     License.
-
- 12. RESPONSIBILITY FOR CLAIMS.
-
-     As between Initial Developer and the Contributors, each party is
-     responsible for claims and damages arising, directly or indirectly,
-     out of its utilization of rights under this License and You agree to
-     work with Initial Developer and Contributors to distribute such
-     responsibility on an equitable basis. Nothing herein is intended or
-     shall be deemed to constitute any admission of liability.
-
- 13. MULTIPLE-LICENSED CODE.
-
-     Initial Developer may designate portions of the Covered Code as
-     "Multiple-Licensed".  "Multiple-Licensed" means that the Initial
-     Developer permits you to utilize portions of the Covered Code under
-     Your choice of the NPL or the alternative licenses, if any, specified
-     by the Initial Developer in the file described in Exhibit A.
-
- EXHIBIT A -Mozilla Public License.
-
-     ``The contents of this file are subject to the Mozilla Public License
-     Version 1.1 (the "License"); you may not use this file except in
-     compliance with the License. You may obtain a copy of the License at
-     http://www.mozilla.org/MPL/
-
-     Software distributed under the License is distributed on an "AS IS"
-     basis, WITHOUT WARRANTY OF ANY KIND, either express or implied. See the
-     License for the specific language governing rights and limitations
-     under the License.
-
-     The Original Code is ______________________________________.
-
-     The Initial Developer of the Original Code is ________________________.
-     Portions created by ______________________ are Copyright (C) ______
-     _______________________. All Rights Reserved.
-
-     Contributor(s): ______________________________________.
-
-     Alternatively, the contents of this file may be used under the terms
-     of the _____ license (the  "[___] License"), in which case the
-     provisions of [______] License are applicable instead of those
-     above.  If you wish to allow use of your version of this file only
-     under the terms of the [____] License and not to allow others to use
-     your version of this file under the MPL, indicate your decision by
-     deleting  the provisions above and replace  them with the notice and
-     other provisions required by the [___] License.  If you do not delete
-     the provisions above, a recipient may use your version of this file
-     under either the MPL or the [___] License."
-
-     [NOTE: The text of this Exhibit A may differ slightly from the text of
-     the notices in the Source Code files of the Original Code. You should
-     use the text of this Exhibit A rather than the text found in the
-     Original Code Source Code for Your Modifications.]
-
-     ----------------------------------------------------------------------
-
-     AMENDMENTS
-
-     The Netscape Public License Version 1.1 ("NPL") consists of the
-     Mozilla Public License Version 1.1 with the following Amendments,
-     including Exhibit A-Netscape Public License.  Files identified with
-     "Exhibit A-Netscape Public License" are governed by the Netscape
-     Public License Version 1.1.
-
-     Additional Terms applicable to the Netscape Public License.
-          I. Effect.
-          These additional terms described in this Netscape Public
-          License -- Amendments shall apply to the Mozilla Communicator
-          client code and to all Covered Code under this License.
-
-          II. "Netscape's Branded Code" means Covered Code that Netscape
-          distributes and/or permits others to distribute under one or more
-          trademark(s) which are controlled by Netscape but which are not
-          licensed for use under this License.
-
-          III. Netscape and logo.
-          This License does not grant any rights to use the trademarks
-          "Netscape", the "Netscape N and horizon" logo or the "Netscape
-          lighthouse" logo, "Netcenter", "Gecko", "Java" or "JavaScript",
-          "Smart Browsing" even if such marks are included in the Original
-          Code or Modifications.
-
-          IV. Inability to Comply Due to Contractual Obligation.
-          Prior to licensing the Original Code under this License, Netscape
-          has licensed third party code for use in Netscape's Branded Code.
-          To the extent that Netscape is limited contractually from making
-          such third party code available under this License, Netscape may
-          choose to reintegrate such code into Covered Code without being
-          required to distribute such code in Source Code form, even if
-          such code would otherwise be considered "Modifications" under
-          this License.
-
-          V. Use of Modifications and Covered Code by Initial Developer.
-               V.1. In General.
-               The obligations of Section 3 apply to Netscape, except to
-               the extent specified in this Amendment, Section V.2 and V.3.
-
-               V.2. Other Products.
-               Netscape may include Covered Code in products other than the
-               Netscape's Branded Code which are released by Netscape
-               during the two (2) years following the release date of the
-               Original Code, without such additional products becoming
-               subject to the terms of this License, and may license such
-               additional products on different terms from those contained
-               in this License.
-
-               V.3. Alternative Licensing.
-               Netscape may license the Source Code of Netscape's Branded
-               Code, including Modifications incorporated therein, without
-               such Netscape Branded Code becoming subject to the terms of
-               this License, and may license such Netscape Branded Code on
-               different terms from those contained in this License.
-
-          VI. Litigation.
-          Notwithstanding the limitations of Section 11 above, the
-          provisions regarding litigation in Section 11(a), (b) and (c) of
-          the License shall apply to all disputes relating to this License.
-
-     EXHIBIT A-Netscape Public License.
-
-          "The contents of this file are subject to the Netscape Public
-          License Version 1.1 (the "License"); you may not use this file
-          except in compliance with the License. You may obtain a copy of
-          the License at http://www.mozilla.org/NPL/
-
-          Software distributed under the License is distributed on an "AS
-          IS" basis, WITHOUT WARRANTY OF ANY KIND, either express or
-          implied. See the License for the specific language governing
-          rights and limitations under the License.
-
-          The Original Code is Mozilla Communicator client code, released
-          March 31, 1998.
-
-          The Initial Developer of the Original Code is Netscape
-          Communications Corporation. Portions created by Netscape are
-          Copyright (C) 1998-1999 Netscape Communications Corporation. All
-          Rights Reserved.
-
-          Contributor(s): ______________________________________.
-
-          Alternatively, the contents of this file may be used under the
-          terms of the _____ license (the "[___] License"), in which case
-          the provisions of [______] License are applicable  instead of
-          those above.  If you wish to allow use of your version of this
-          file only under the terms of the [____] License and not to allow
-          others to use your version of this file under the NPL, indicate
-          your decision by deleting  the provisions above and replace  them
-          with the notice and other provisions required by the [___]
-          License.  If you do not delete the provisions above, a recipient
-          may use your version of this file under either the NPL or the
-          [___] License."
-
-
-On Debian machines, the full text of the GNU Lesser General Public License
-be found in the file /usr/share/common-licenses/LGPL, the full text of the
-GNU General Public License in the file /usr/share/common-licenses/GPL.
+License: LGPL-2.1+ or GPL-2+ or MPL-1.1
+
+License: Apache-2.0
+ On Debian systems, the complete text of the Apache License version 2 can be 
+ found in "/usr/share/common-licenses/Apache-2.0".
+
+License: GPL-2+
+ On Debian systems, the complete text of the GNU General
+ Public License version 2 can be found in "/usr/share/common-licenses/GPL-2".
+
+License: GPL-2
+ On Debian systems, the complete text of the GNU General
+ Public License version 2 can be found in "/usr/share/common-licenses/GPL-2".
+
+License: LGPL-2.1+
+ On Debian systems, the complete text of the GNU Lesser General Public
+ License can be found in "/usr/share/common-licenses/LGPL-2.1".
+
+License: MPL-1.1
+ On Debian systems, the complete text of the Mozilla Public
+ License version 1.1 can be found in "/usr/share/common-licenses/MPL-1.1".
+
+License: MPL-2.0
+ On Debian systems, the complete text of the Mozilla Public
+ License version 2.0 can be found in "/usr/share/common-licenses/MPL-2.0".
+
+License: BSD-3-clause
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+ .
+ 1. Redistributions of source code must retain the copyright
+   notice, this list of conditions and the following disclaimer.
+ 2. Redistributions in binary form must reproduce the copyright
+   notice, this list of conditions and the following disclaimer in the
+   documentation and/or other materials provided with the distribution.
+ 3. The name of the author may not be used to endorse or promote products
+   derived from this software without specific prior written permission.
+ .
+ THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
+ IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
+ OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
+ IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
+ INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
+ NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
+ THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.


=====================================
debian/libjss-java.install
=====================================
@@ -1,3 +1,2 @@
-usr/share/java/jss.jar
 usr/lib/jss/libjss.so
 usr/lib/jss/libjss-symkey.so


=====================================
debian/libjss-java.jlibs
=====================================
@@ -0,0 +1 @@
+base/target/jss.jar


=====================================
debian/lrc.config
=====================================
@@ -0,0 +1,3 @@
+gpl.txt
+lgpl.txt
+MPL-1.1.txt


=====================================
debian/not-installed
=====================================
@@ -0,0 +1 @@
+debian/tmp/jss/tests/*


=====================================
debian/patches/0001-fix-use-size_t-in-call-to-JSS_FromByteArray.patch deleted
=====================================
@@ -1,72 +0,0 @@
-From fd53e10bc1c5be78fbfc272d8044f5ad0985278a Mon Sep 17 00:00:00 2001
-From: Vladimir Petko <vladimir.petko at canonical.com>
-Date: Mon, 9 Mar 2026 14:39:12 +1300
-Subject: [PATCH] fix: use size_t in call to JSS_FromByteArray
-Bug: https://github.com/dogtagpki/jss/pull/1078
-Bug-Debian: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1091274
-Bug-Ubuntu: https://bugs.launchpad.net/ubuntu/+source/jss/+bug/2143687
-
----
- .../native/org/mozilla/jss/crypto/JSSOAEPParameterSpec.c   | 7 ++++++-
- native/src/main/native/org/mozilla/jss/crypto/KBKDF.c      | 7 ++++++-
- 2 files changed, 12 insertions(+), 2 deletions(-)
-
-diff --git a/native/src/main/native/org/mozilla/jss/crypto/JSSOAEPParameterSpec.c b/native/src/main/native/org/mozilla/jss/crypto/JSSOAEPParameterSpec.c
-index 2480ca3f..8aa88a15 100644
---- a/native/src/main/native/org/mozilla/jss/crypto/JSSOAEPParameterSpec.c
-+++ b/native/src/main/native/org/mozilla/jss/crypto/JSSOAEPParameterSpec.c
-@@ -47,6 +47,7 @@ oaep_GetSpecifiedSourceData(JNIEnv *env, jobject this, jclass this_class, CK_VOI
- {
-     jfieldID field_id = NULL;
-     jbyteArray data = NULL;
-+    size_t st_ret_len = 0;
- 
-     field_id = (*env)->GetFieldID(env, this_class, "sourceData", "[B");
-     if (field_id == NULL) {
-@@ -60,10 +61,14 @@ oaep_GetSpecifiedSourceData(JNIEnv *env, jobject this, jclass this_class, CK_VOI
-         return PR_SUCCESS;
-     }
- 
--    if (!JSS_FromByteArray(env, data, (uint8_t **)ret, ret_len)) {
-+    if (!JSS_FromByteArray(env, data, (uint8_t **)ret, &st_ret_len)) {
-         return PR_FAILURE;
-     }
- 
-+    if (ret_len != NULL) {
-+        *ret_len = st_ret_len;
-+    }
-+
-     return PR_SUCCESS;
- }
- 
-diff --git a/native/src/main/native/org/mozilla/jss/crypto/KBKDF.c b/native/src/main/native/org/mozilla/jss/crypto/KBKDF.c
-index bc1195d7..f3ebd9c5 100644
---- a/native/src/main/native/org/mozilla/jss/crypto/KBKDF.c
-+++ b/native/src/main/native/org/mozilla/jss/crypto/KBKDF.c
-@@ -757,6 +757,7 @@ kbkdf_GetInitialValue(JNIEnv *env, jobject this, jclass this_class, CK_ULONG *in
- {
-     jfieldID field_id = NULL;
-     jobjectArray iv_array = NULL;
-+    size_t st_initial_value_length = 0;
- 
-     field_id = (*env)->GetFieldID(env, this_class, "initial_value", "[B");
-     if (field_id == NULL) {
-@@ -770,10 +771,14 @@ kbkdf_GetInitialValue(JNIEnv *env, jobject this, jclass this_class, CK_ULONG *in
-         return PR_SUCCESS;
-     }
- 
--    if (!JSS_FromByteArray(env, iv_array, initial_value, initial_value_length)) {
-+    if (!JSS_FromByteArray(env, iv_array, initial_value, &st_initial_value_length)) {
-         return PR_FAILURE;
-     }
- 
-+    if (initial_value_length != NULL) {
-+        *initial_value_length = st_initial_value_length;
-+    }
-+
-     return PR_SUCCESS;
- }
- 
--- 
-2.51.0
-


=====================================
debian/patches/fix-ml-kem-dsa.patch
=====================================
@@ -0,0 +1,60 @@
+Description: Add preprocessor guards to unguarded PQ code
+ These parts of the code do not respect JSS_MLKEM_ENABLED and
+ JSS_MLDSA_ENABLED, respectively, which causes JSS to fail to compile on
+ platforms where PQ algorithms are not suported.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: https://github.com/dogtagpki/jss/pull/1123
+Last-Update: 2026-09-25
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
+--- a/native/src/main/native/org/mozilla/jss/pkcs11/PK11KeyWrapper.c
++++ b/native/src/main/native/org/mozilla/jss/pkcs11/PK11KeyWrapper.c
+@@ -429,11 +429,21 @@
+     /* Workaround: NSS PK11_GetKeyType() doesn't map PKCS#11 v3.2 PQC mechanisms
+      * Without this, it returns CKK_GENERIC_SECRET (0x10) which also works,
+      * but using the proper key types is clearer and more correct */
++
++     // Use CK_UNAVAILABLE_INFORMATION as the initial value of keyType
++     // so we can conditionally compile
++     keyType = CK_UNAVAILABLE_INFORMATION;
++#ifdef JSS_MLKEM_ENABLED
+     if (keyTypeMech == CKM_ML_KEM_KEY_PAIR_GEN || keyTypeMech == CKM_ML_KEM) {
+         keyType = CKK_ML_KEM;  /* 0x49 from PKCS#11 v3.2 */
+-    } else if (keyTypeMech == CKM_ML_DSA_KEY_PAIR_GEN || keyTypeMech == CKM_ML_DSA) {
++    }
++#endif
++#ifdef JSS_MLDSA_ENABLED
++    if (keyTypeMech == CKM_ML_DSA_KEY_PAIR_GEN || keyTypeMech == CKM_ML_DSA) {
+         keyType = CKK_ML_DSA;  /* 0x48 from PKCS#11 v3.2 */
+-    } else {
++    }
++#endif
++    if (keyType == CK_UNAVAILABLE_INFORMATION) {
+         keyType = PK11_GetKeyType(keyTypeMech, 0);
+     }
+ 
+@@ -476,6 +486,7 @@
+         attribs[0] = CKA_DERIVE;
+         numAttribs = 1;
+ 	break;
++#ifdef JSS_MLKEM_ENABLED
+     case CKK_ML_KEM:
+         /* ML-KEM is a KEM (Key Encapsulation Mechanism), not a signature key
+          * Set CKA_DECAPSULATE to indicate intended usage per PKCS#11 v3.2 */
+@@ -486,6 +497,8 @@
+             numAttribs = 2;
+         }
+ 	break;
++#endif
++#ifdef JSS_MLDSA_ENABLED
+     case CKK_ML_DSA:
+         /* ML-DSA is a digital signature algorithm
+          * Set CKA_SIGN to indicate intended usage per PKCS#11 v3.2 */
+@@ -496,6 +509,7 @@
+             numAttribs = 2;
+         }
+ 	break;
++#endif
+     default:
+         /* unknown key type */
+         PR_ASSERT(PR_FALSE);


=====================================
debian/patches/fix-versions.diff
=====================================
@@ -0,0 +1,96 @@
+Description: Fix versions in pom.xml
+ The versions specified in various pom.xml files does not match the actual
+ release version.
+Author: Jarl Gullberg <jarl.gullberg at visar-systems.com>
+Forwarded: not-needed
+Last-Update: 2026-09-26
+---
+This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
+--- a/base/pom.xml
++++ b/base/pom.xml
+@@ -8,7 +8,7 @@
+     <parent>
+         <groupId>org.dogtagpki.jss</groupId>
+         <artifactId>jss-parent</artifactId>
+-        <version>5.10.0-SNAPSHOT</version>
++        <version>5.10.1</version>
+     </parent>
+ 
+     <artifactId>jss-base</artifactId>
+--- a/examples/pom.xml
++++ b/examples/pom.xml
+@@ -8,7 +8,7 @@
+     <parent>
+         <groupId>org.dogtagpki.jss</groupId>
+         <artifactId>jss-parent</artifactId>
+-        <version>5.10.0-SNAPSHOT</version>
++        <version>5.10.1</version>
+     </parent>
+ 
+     <artifactId>jss-examples</artifactId>
+--- a/native/pom.xml
++++ b/native/pom.xml
+@@ -8,7 +8,7 @@
+     <parent>
+         <groupId>org.dogtagpki.jss</groupId>
+         <artifactId>jss-parent</artifactId>
+-        <version>5.10.0-SNAPSHOT</version>
++        <version>5.10.1</version>
+     </parent>
+ 
+     <artifactId>libjss</artifactId>
+--- a/pom.xml
++++ b/pom.xml
+@@ -6,7 +6,7 @@
+     <modelVersion>4.0.0</modelVersion>
+     <groupId>org.dogtagpki.jss</groupId>
+     <artifactId>jss-parent</artifactId>
+-    <version>5.10.0-SNAPSHOT</version>
++    <version>5.10.1</version>
+     <packaging>pom</packaging>
+ 
+     <properties>
+--- a/symkey/pom.xml
++++ b/symkey/pom.xml
+@@ -8,7 +8,7 @@
+     <parent>
+         <groupId>org.dogtagpki.jss</groupId>
+         <artifactId>jss-parent</artifactId>
+-        <version>5.10.0-SNAPSHOT</version>
++        <version>5.10.1</version>
+     </parent>
+ 
+     <artifactId>libjss-symkey</artifactId>
+--- a/tomcat-10.1/pom.xml
++++ b/tomcat-10.1/pom.xml
+@@ -8,7 +8,7 @@
+     <parent>
+         <groupId>org.dogtagpki.jss</groupId>
+         <artifactId>jss-parent</artifactId>
+-        <version>5.10.0-SNAPSHOT</version>
++        <version>5.10.1</version>
+     </parent>
+ 
+     <artifactId>jss-tomcat-10.1</artifactId>
+--- a/tomcat-9.0/pom.xml
++++ b/tomcat-9.0/pom.xml
+@@ -8,7 +8,7 @@
+     <parent>
+         <groupId>org.dogtagpki.jss</groupId>
+         <artifactId>jss-parent</artifactId>
+-        <version>5.10.0-SNAPSHOT</version>
++        <version>5.10.1</version>
+     </parent>
+ 
+     <artifactId>jss-tomcat-9.0</artifactId>
+--- a/tomcat/pom.xml
++++ b/tomcat/pom.xml
+@@ -8,7 +8,7 @@
+     <parent>
+         <groupId>org.dogtagpki.jss</groupId>
+         <artifactId>jss-parent</artifactId>
+-        <version>5.10.0-SNAPSHOT</version>
++        <version>5.10.1</version>
+     </parent>
+ 
+     <artifactId>jss-tomcat</artifactId>


=====================================
debian/patches/series
=====================================
@@ -1 +1,2 @@
-0001-fix-use-size_t-in-call-to-JSS_FromByteArray.patch
+fix-ml-kem-dsa.patch
+fix-versions.diff


=====================================
debian/rules
=====================================
@@ -1,62 +1,57 @@
 #!/usr/bin/make -f
 
-include /usr/share/quilt/quilt.make
+include /usr/share/dpkg/pkg-info.mk
 
-UPSTREAM_VERSION := $(shell dpkg-parsechangelog | sed -n 's/^Version: *\(.*\)-.*$$/\1/ p' | sed -e 's/~.*//')
-MOD_MAJOR_VERSION := $(word 1, $(subst ., ,$(UPSTREAM_VERSION)))
-MOD_MINOR_VERSION := $(word 2, $(subst ., ,$(UPSTREAM_VERSION)))
-MOD_PATCH_VERSION := $(word 3, $(subst ., ,$(UPSTREAM_VERSION)))
+export DEB_BUILD_MAINT_OPTIONS = hardening=+all
 
-override_dh_clean:
-	dh_clean -O--buildsystem=maven
-	dh_clean
-	rm -rf build2/* build2/.targets
-	rm -f org/mozilla/jss/util/jssver.h
+ENABLE_PQ_ALGORITHMS = $(shell dpkg --compare-versions "$$(dpkg-query -f '$${source:Upstream-Version}' -W libnss3-dev)" ge "3.116" && echo ON || echo OFF)
+
+override_dh_auto_clean:
+	dh_auto_clean --buildsystem=maven
+	dh_auto_clean --builddirectory=build2 --buildsystem=cmake
 
 override_dh_auto_configure:
-	dh_auto_configure -O--buildsystem=maven
-	dh_auto_configure -O-Bbuild2
+	dh_auto_configure --buildsystem=maven
+	dh_auto_configure --builddirectory=build2 --buildsystem=cmake -- \
+		-DWITH_MLDSA=$(ENABLE_PQ_ALGORITHMS) \
+		-DWITH_MLKEM=$(ENABLE_PQ_ALGORITHMS) \
+		-DWITH_JAVA=OFF \
+		-DWITH_JAVADOC=OFF
 
 override_dh_auto_build:
-	dh_auto_build -O--buildsystem=maven
+	dh_auto_build --buildsystem=maven
 
+	# create links to Maven-built classes for CMake
 	mkdir -p build2/classes/jss
-	ln -sf ../../../base/target/classes/org build2/classes/jss
+	ln -sf -t build2/classes/jss ../../../base/target/classes/org
 	mkdir -p build2/classes/tests
-	ln -sf ../../../base/target/test-classes/org build2/classes/tests
+	ln -sf -t build2/classes/tests ../../../base/target/test-classes/org
 
-	ln -sf ../base/target/jss.jar build2
-	ln -sf ../base/target/jss-tests.jar build2
+	# create links to Maven-built JAR files for CMake
+	ln -sf -T ../base/target/jss.jar build2/jss.jar
+	ln -sf -T ../base/target/jss-tests.jar build2/jss-tests.jar
 
+	# create links to Maven-built headers for CMake
 	mkdir -p build2/include/jss
-	ln -sf ../../../base/target/include/_jni build2/include/jss/_jni
+	rmdir build2/include/jss/_jni || true # CMake may create this directory
+	ln -sf -t build2/include/jss/ ../../../base/target/include/_jni
 
-	dh_auto_build -O-Bbuild2
+	dh_auto_build --builddirectory=build2 --buildsystem=cmake -- native
 
 override_dh_auto_install:
-	dh_auto_install -O--buildsystem=maven
-	dh_auto_install -O-Bbuild2 --destdir=debian/tmp
-
-	# tests
-	rm -rf debian/tmp/jss
-
-	rm -rf debian/tmp/usr/share/javadoc
-
-	mkdir -p debian/tmp/usr/share
-	mv debian/tmp/usr/lib/java debian/tmp/usr/share
-	rm -f debian/tmp/usr/lib/jss/*.jar
-
-	rm -f debian/tmp/usr/bin/*
+	dh_auto_install --buildsystem=maven --destdir=debian/tmp
+	dh_auto_install --builddirectory=build2 --destdir=debian/tmp
 
 override_dh_auto_test:
+ifeq (,$(filter nocheck,$(DEB_BUILD_PROFILES)))
 	cd build && ctest --output-on-failure || true
+endif
 
 # For maintainer use only, generate a tarball:
-gentarball: UV=$(shell dpkg-parsechangelog|awk '/^Version:/ {print $$2}'|sed 's/-.*$$//')
 gentarball:
-	git archive --format=tar upstream --prefix=jss-$(UV)/ | \
+	git archive --format=tar upstream --prefix=jss-$(DEB_VERSION_UPSTREAM)/ ":(exclude)debian" | \
 		xz --best \
-		> ../jss_$(UV).orig.tar.xz
+		> ../jss_$(DEB_VERSION_UPSTREAM).orig.tar.xz
 
 %:
-	dh $@
+	dh $@ --with javahelper



View it on GitLab: https://salsa.debian.org/freeipa-team/jss/-/compare/1e82013bad804c8c7c3ef9d9e47bbf8070c02895...c4f44ff4180e3501f92ebbf92883d035a6460a8b

-- 
View it on GitLab: https://salsa.debian.org/freeipa-team/jss/-/compare/1e82013bad804c8c7c3ef9d9e47bbf8070c02895...c4f44ff4180e3501f92ebbf92883d035a6460a8b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-freeipa-devel/attachments/20260927/c17a01b2/attachment-0001.htm>


More information about the Pkg-freeipa-devel mailing list