Bug 2092503
| Summary: | FIPS compliance of signature APIs used by OpenSSH [rhel-8] | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Hubert Kario <hkario> |
| Component: | openssh | Assignee: | Norbert Pócs <npocs> |
| Status: | CLOSED WONTFIX | QA Contact: | Marek Havrila <mhavrila> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 8.6 | CC: | cllang, dbelyavs, jjelen, npocs, qe-baseos-security |
| Target Milestone: | rc | Keywords: | Reopened, Triaged |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | 2091694 | Environment: | |
| Last Closed: | 2023-05-30 07:28:23 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2091694 | ||
| Bug Blocks: | |||
|
Description
Hubert Kario
2022-06-01 17:14:23 UTC
What should be done: In the function sshkey_calculate_signature/sshkey_verify_signature we should use the DigestSignInit/Update/Final API ECDSA_do_sign/verify calls should be eliminated from both SSH and ssh_pam (leave just in sk-dummy.c) DH/ECDH key exchanges should be rewritten to use EVP_PKEY API After the discussion, we don't have to switch to DigestSignInit/Update/Final API in RHEL8 After evaluating this issue, there are no plans to address it further or fix it in an upcoming release. Therefore, it is being closed. If plans change such that this issue will be fixed in an upcoming release, then the bug can be reopened. |