Bug 1813064

Summary: Update OSPP settings
Product: Red Hat Enterprise Linux 8 Reporter: Steve Grubb <sgrubb>
Component: crypto-policiesAssignee: Tomas Mraz <tmraz>
Status: CLOSED ERRATA QA Contact: Ondrej Moriš <omoris>
Severity: high Docs Contact:
Priority: high    
Version: 8.2CC: nmavrogi, omoris, szidek
Target Milestone: rcKeywords: Triaged
Target Release: 8.3Flags: pm-rhel: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: crypto-policies-20200527-1.git0a29b28.el8 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-11-04 01:58:27 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1761915    

Description Steve Grubb 2020-03-12 20:31:00 UTC
Description of problem:
There have been some Technical Decisions for OSPP that allows a little more flexibility. We like a couple things amended to ease some restrictions:

sshd_config
Ciphers aes128- gcm, aes256-gcm
RekeyLimit change back to 1G

ssh_config
Ciphers aes128- gcm, aes256-gcm
RekeyLimit change back to 1G

Comment 4 Matěj Týč 2020-03-31 07:54:16 UTC
*** Bug 1813066 has been marked as a duplicate of this bug. ***

Comment 5 Tomas Mraz 2020-05-05 10:52:15 UTC
Steve, can you please clarify that the existing policy for SSH Ciphers should be?

Would the GCM ciphers be added to the existing set?

I.E. the final list would be:

Ciphers aes256-gcm,aes256-ctr,aes256-cbc,aes128-gcm,aes128-ctr,aes128-cbc

Is that correct?

Comment 6 Steve Grubb 2020-05-05 14:52:24 UTC
The current specification is here:
https://www.niap-ccevs.org/Documents_and_Guidance/view_td.cfm?TD=0446

I think your list looks correct.

Comment 14 errata-xmlrpc 2020-11-04 01:58:27 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (crypto-policies bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:4536