Bug 1715233

Summary: Need OSPP v4.2 crypto policy (enabled in the system FIPS mode)
Product: Red Hat Enterprise Linux 8 Reporter: Steve Grubb <sgrubb>
Component: crypto-policiesAssignee: Tomas Mraz <tmraz>
Status: CLOSED ERRATA QA Contact: Ondrej Moriš <omoris>
Severity: high Docs Contact:
Priority: high    
Version: 8.0CC: jjaburek, jpazdziora, mhaicman, nmavrogi, ssorce, szidek
Target Milestone: rcKeywords: Triaged
Target Release: 8.2Flags: pm-rhel: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: crypto-policies-20191127-1.git1179826.el8 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-04-28 16:46:50 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1746025, 1755139    

Description Steve Grubb 2019-05-29 21:05:23 UTC
Description of problem:
Common Criteria for OSPP v 4.2 has crypto requirements that overlap with FIPS but are stricter than FIPS allows. To make things easier for end users, it would be nice if the settings were encapsulated into a specific policy that users could invoke. At some point in the future, new crypto requirements will be specified in an OSPP v4.3 Protection Profile. But this is likely to be a year away.

The list of ciphers, modes, and algorithms will be detailed in comments below.

Comment 6 Steve Grubb 2019-11-19 17:09:13 UTC
It was just reported today by the lab that we are doing TLS 1.3 connections. Turns out that OSPP v4.2 must be limited to TLSv1.2. This includes changing a setting for rsyslog-gnutls to drop 1.3 protocol.

Comment 16 errata-xmlrpc 2020-04-28 16:46:50 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:1811