Bug 2073081
Summary: | [knot-resolver] SHA-1 DNSSEC signatures are broken in DEFAULT crypto-policy | ||
---|---|---|---|
Product: | [Fedora] Fedora EPEL | Reporter: | Petr Menšík <pemensik> |
Component: | knot-resolver | Assignee: | Vladimír Čunát <vladimir.cunat> |
Status: | CLOSED WORKSFORME | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | epel9 | CC: | dns-sig, jakub.ruzicka, jv+fedora, nicki, peter.van.dijk, pspacek |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2022-07-15 08:54:48 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 2073066 |
Description
Petr Menšík
2022-04-07 15:27:00 UTC
Note: I know knot-resolver does not yet have a build for EPEL9. This is just to make you aware of a potential problem. If there won't be any, please close this bug. I believe this has never been broken. Since crypto policies of Fedora, in 2020 we started to respect GnuTLS's policies [1]. So SHA1 zones were treated as insecure in there already, and based on my earlier testing this also worked in CentOS 9 without changing anything (after you switched to stronger restrictions). In the meantime we also managed to get the package into EPEL 9. [1] https://gitlab.nic.cz/knot/knot-dns/-/commit/b0c6f0709a |