Bug 1731484

Summary: support for SHA384withRSA signing algo missing
Product: Red Hat Enterprise Linux 8 Reporter: Kaleem <ksiddiqu>
Component: ipaAssignee: Thomas Woerner <twoerner>
Status: CLOSED ERRATA QA Contact: ipa-qe <ipa-qe>
Severity: unspecified Docs Contact: Josip Vilicic <jvilicic>
Priority: high    
Version: 8.1CC: abokovoy, cheimes, frenaud, gfialova, jvilicic, myusuf, ndehadra, pasik, pcech, pvoborni, rcritten, rjeffman, ssidhaye, sumenon, tscherf, twoerner
Target Milestone: rcKeywords: Triaged
Target Release: 8.3   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ipa-4.9.8-1.module+el8.6.0+13486+dbe20af2 Doc Type: Enhancement
Doc Text:
.Identity Management now supports SHA384withRSA signing by default With this update, the Certificate Authority (CA) in IdM supports the SHA-384 With RSA Encryption signing algorithm. SHA384withRSA is compliant with the Federal Information Processing Standard (FIPS).
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-05-10 14:08:44 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Kaleem 2019-07-19 13:56:06 UTC
Description of problem:
There is no support of SHA384withRSA signing algo in IPA and we should add it

This is raised with CS team in https://bugzilla.redhat.com/show_bug.cgi?id=1578389#c5 which got added on dogtag side.

Comment 1 Rob Crittenden 2019-07-19 15:18:24 UTC
For clarity this is fixed in https://bugzilla.redhat.com/show_bug.cgi?id=1554055 which is the BZ pointed to in the comment on 1578389.

Comment 12 Rob Crittenden 2021-06-30 15:11:57 UTC
Upstream ticket:
https://pagure.io/freeipa/issue/8906

Comment 13 Rob Crittenden 2021-07-09 17:21:50 UTC
Fixed upstream
master:
https://pagure.io/freeipa/c/02e19d0a396286d9de5a516f62f60699b5ee2527

Comment 14 Florence Blanc-Renaud 2021-07-12 07:02:45 UTC
Fixed upstream
ipa-4-9:
https://pagure.io/freeipa/c/ca8c7010e8aa0f87bde11c36947fefd549bae8fd

Comment 23 Florence Blanc-Renaud 2022-01-14 14:13:20 UTC
Test added upstream
master:
https://pagure.io/freeipa/c/75645760d285b30ee5f4c0146dc3ed690376d0b6

Comment 27 Sumedh Sidhaye 2022-01-17 11:16:24 UTC
Build used for verification:

ipa-server-4.9.8-2.module+el8.6.0+13621+937b8cd9

Verified using latest RHEL-8.6.0 nightly repo
http://download.devel.redhat.com/rhel-8/nightly/RHEL-8/latest-RHEL-8.6/compose/AppStream/

============================= test session starts ==============================
platform linux -- Python 3.6.8, pytest-3.10.1, py-1.11.0, pluggy-1.0.0 -- /usr/bin/python3
cachedir: .pytest_cache
metadata: {'Python': '3.6.8', 'Platform': 'Linux-4.18.0-359.el8.x86_64-x86_64-with-redhat-8.6-Ootpa', 'Packages': {'pytest': '3.10.1', 'py': '1.11.0', 'pluggy': '1.0.0'}, 'Plugins': {'metadata': '1.11.0', 'html': '1.22.1', 'multihost': '3.0', 'sourceorder': '0.5'}}
rootdir: /tmp/wp/freeipa, inifile: tox.ini
plugins: metadata-1.11.0, html-1.22.1, multihost-3.0, sourceorder-0.5
collecting ... collected 2 items

ipatests/test_integration/test_installation.py::TestInstallwithSHA384withRSA::test_install_master_withalgo_sha384withrsa PASSED [ 50%]
ipatests/test_integration/test_installation.py::TestInstallwithSHA384withRSA::test_install_master_modify_existing PASSED [100%]

------------------ generated xml file: /tmp/wp/twd/junit.xml -------------------
------------- generated html file: file:///tmp/wp/twd/report.html --------------
========================= 2 passed in 1143.39 seconds ==========================

Based on above test results, marking Bugzilla Verified

Comment 33 errata-xmlrpc 2022-05-10 14:08:44 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (idm:client and idm:DL1 bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2022:1884