Back to bug 2071981

Who When What Removed Added
Red Hat Bugzilla 2022-04-05 10:57:07 UTC Pool ID sst_security_crypto_rhel_8
Red Hat One Jira (issues.redhat.com) 2022-04-05 10:59:31 UTC Link ID Red Hat Issue Tracker RHELPLAN-117874
Petr Menšík 2022-04-05 11:04:05 UTC Severity unspecified low
Alexander Sosedkin 2022-05-03 14:43:43 UTC Keywords Triaged
Priority unspecified low
Red Hat One Jira (issues.redhat.com) 2022-09-13 15:52:52 UTC Link ID Red Hat Issue Tracker CRYPTO-8263
Alexander Sosedkin 2022-12-12 14:10:46 UTC Doc Text Feature: NSEC3DSA support in crypto-policies

Reason: crypto-policies has been extended to control NSEC3DSA

Result: NSEC3DSA usage in bind is now disableable through crypto-policies
Doc Type If docs needed, set a value Enhancement
Ondrej Moriš 2022-12-12 14:15:49 UTC Doc Text Feature: NSEC3DSA support in crypto-policies

Reason: crypto-policies has been extended to control NSEC3DSA

Result: NSEC3DSA usage in bind is now disableable through crypto-policies
If this bug requires documentation, please select an appropriate Doc Type value.
CC omoris
QA Contact qe-baseos-security omoris
Alexander Sosedkin 2022-12-12 18:50:03 UTC Flags needinfo?(pemensik)
Petr Menšík 2022-12-12 19:23:07 UTC Flags needinfo?(pemensik)
Alexander Sosedkin 2022-12-13 11:05:17 UTC Flags needinfo?(pemensik)
Petr Menšík 2022-12-14 13:01:59 UTC Flags needinfo?(pemensik)
Alexander Sosedkin 2022-12-14 18:08:51 UTC Link ID Gitlab redhat-crypto/fedora-crypto-policies/-/merge_requests/126
Status NEW POST
Alexander Sosedkin 2022-12-15 16:17:59 UTC Fixed In Version crypto-policies-20221215-1.gitece0092.el8
Status POST MODIFIED
errata-xmlrpc 2022-12-15 16:28:57 UTC Status MODIFIED ON_QA
Ondrej Moriš 2022-12-16 15:37:41 UTC Status ON_QA VERIFIED
Jan Fiala 2023-05-03 08:35:55 UTC Doc Text If this bug requires documentation, please select an appropriate Doc Type value. .`crypto-policies` now disable `NSEC3DSA` for BIND

Previously, the system-wide cryptographic policies did not control the `NSEC3DSA` algorithm in the BIND configuration. Consequently, `NSEC3DSA`, which does not meet current security requirements, was not disabled on DNS servers. With this update, all cryptographic policies disable `NSEC3DSA` in the BIND configuration by default.
CC jafiala
Docs Contact jafiala
Jan Fiala 2023-05-03 10:11:09 UTC Doc Type Enhancement Bug Fix
errata-xmlrpc 2023-05-09 00:12:40 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2023-05-16 09:11:00 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2023-05-16 09:11:00 UTC
errata-xmlrpc 2023-05-16 09:11:07 UTC Link ID Red Hat Product Errata RHBA-2023:3025

Back to bug 2071981