Bug 2091903

Summary: allow signature verification using RSA keys <2k in FIPS mode
Product: Red Hat Enterprise Linux 9 Reporter: Clemens Lang <cllang>
Component: gnutlsAssignee: Daiki Ueno <dueno>
Status: CLOSED CURRENTRELEASE QA Contact: Alexander Sosedkin <asosedki>
Severity: unspecified Docs Contact:
Priority: medium    
Version: 9.0CC: afarley, asosedki, zfridric
Target Milestone: rcKeywords: Triaged, ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: gnutls-3.7.6-11.el9 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of:
: 2119770 (view as bug list) Environment:
Last Closed: 2023-05-25 14:29:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2119770    

Description Clemens Lang 2022-05-31 09:57:29 UTC
Description of problem:

We clarified with lab that we should be able to use the RSA keys for signature verification if they are of the following sizes:

  1024, 1280, 1536, 1792

Consider adapting GnuTLS to also support these shorter key sizes. We may not want to enable these short key sizes by default in TLS, though.