Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-36300

c10s crypto-policies needs to start controlling TLS-REQUIRE-EMS NSS keyword

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • rhel-10.0.beta
    • rhel-10.0.beta, CentOS Stream 10, rhel-10.0
    • crypto-policies
    • None
    • sst_security_crypto
    • ssg_security
    • 26
    • False
    • Hide

      None

      Show
      None
    • No
    • Red Hat Enterprise Linux
    • Hide

      AC proposal:

      • [Sanity/retention] /etc/crypto-policies/back-ends/nss.config
      • for DEFAULT and other key policies: contains no `TLS-REQUIRE-EMS` keyword
      • for FIPS: contains a `TLS-REQUIRE-EMS` keyword under `config=`
      • for FIPS:NO-ENFORCE-EMS: contains no `TLS-REQUIRE-EMS` keyword
      • [manual inspection] crypto-policies conflicts with a versions of NSS older than the one that understands the keyword
      Show
      AC proposal: [Sanity/retention] /etc/crypto-policies/back-ends/nss.config for DEFAULT and other key policies: contains no `TLS-REQUIRE-EMS` keyword for FIPS: contains a `TLS-REQUIRE-EMS` keyword under `config=` for FIPS:NO-ENFORCE-EMS: contains no `TLS-REQUIRE-EMS` keyword [manual inspection] crypto-policies conflicts with a versions of NSS older than the one that understands the keyword
    • Proposed

      crypto-policies in Fedora and, soon, c10s, doesn't use TLS-REQUIRE-EMS keyword when generating NSS configs.

      Filing it as a bug instead of fixing it right away because

      1. c10s NSS does not currently recognize the keyword (RHEL-36299)
      2. I don't want to create workarounds for tests only to remove them later
      3. if I do and it's silently fixed, I won't remember to fix the same thing in Fedora

            asosedki@redhat.com Alexander Sosedkin
            asosedki@redhat.com Alexander Sosedkin
            Alexander Sosedkin Alexander Sosedkin
            Ondrej Moris Ondrej Moris
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: