Bug 2055796

Summary: Enable SHA-1 signatures through LEGACY policy configuration
Product: Red Hat Enterprise Linux 9 Reporter: Sahana Prasad <sahana>
Component: crypto-policiesAssignee: Alexander Sosedkin <asosedki>
Status: CLOSED ERRATA QA Contact: Ondrej Moriš <omoris>
Severity: low Docs Contact:
Priority: high    
Version: CentOS StreamCC: asosedki, bstinson, cllang, dbelyavs, hkario, jwboyer, omoris
Target Milestone: rcKeywords: Triaged
Target Release: ---Flags: pm-rhel: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: crypto-policies-20220223-1.git5203b41.el9 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-05-17 15:54:53 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2022-02-28   

Description Sahana Prasad 2022-02-17 16:28:43 UTC
OpenSSL 3.0.0 in RHEL-9 does not support SHA-1 for signature creation and verification by default (SHA-1 KDFs and HMACs are still supported). However, to support backwards compatibility with RHEL-8 systems that still use SHA-1 for signatures, a new configuration option - ‘rh-allow-sha1-signatures’ is introduced in RHEL-9. This config option, if enabled in the ‘alg_section’ of openssl.cnf, additionally permits the creation and verification of SHA-1 signatures.

We would like this option would be automatically set if the LEGACY policy is set via crypto-policies. 

Exact name of the config option - rh-allow-sha1-signatures could vary. It will be implemented as part of https://bugzilla.redhat.com/show_bug.cgi?id=2031742

Comment 7 Sandro Bonazzola 2022-03-01 10:43:36 UTC
Can we get https://kojihub.stream.centos.org/koji/buildinfo?buildID=16754 pushed to mirrors? The package is not available yet there and it will simplify setting openssl for supporting COPR and CentOS SIGs rpms installation

Comment 9 Josh Boyer 2022-03-01 16:50:43 UTC
(In reply to Sandro Bonazzola from comment #7)
> Can we get https://kojihub.stream.centos.org/koji/buildinfo?buildID=16754
> pushed to mirrors? The package is not available yet there and it will
> simplify setting openssl for supporting COPR and CentOS SIGs rpms
> installation

There's other work that needs to land before this can be made available.  It will be tagged in as soon as possible.

Comment 11 errata-xmlrpc 2022-05-17 15:54:53 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (new packages: crypto-policies), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:3953

Comment 12 Red Hat Bugzilla 2023-09-15 01:52:00 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 365 days