Bug 2122193

Summary: RHEL9 provided libfido2 release is behind EPEL8
Product: Red Hat Enterprise Linux 9 Reporter: Iker Pedrosa <ipedrosa>
Component: libfido2Assignee: Dmitry Belyavskiy <dbelyavs>
Status: CLOSED ERRATA QA Contact: George Pantelakis <gpantela>
Severity: medium Docs Contact:
Priority: medium    
Version: 9.0CC: atikhono, gpantela, mupadhye, szidek
Target Milestone: rcKeywords: Triaged
Target Release: ---Flags: pm-rhel: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: libfido2-1.13.0-1.el9 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-11-07 08:52:11 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Iker Pedrosa 2022-08-29 13:21:09 UTC
Description of problem:
RHEL9 libfido2 package version (1.6.0) is behind the EPEL8 version (1.11.0). This is generating a confusing user experience for those relying on these library.

I would at least need to have defined FIDO_DISABLE_U2F_FALLBACK, which was included upstream in https://github.com/Yubico/libfido2/commit/35966e6486f8ffca63641210b4ca878a43338602. But I may need other interfaces or definitions as the development phase continues, thus as I mentioned before, I'd prefer to update the RHEL9 version of this package to 1.11.0.

Comment 2 Dmitry Belyavskiy 2022-09-05 09:45:25 UTC
We definitely wouldn't do it for RHEL 9.0/9.1

It can be done for 9.2 if no backward compatibility is broken and nobody depends on soname 1.6.0

Comment 3 Iker Pedrosa 2022-09-07 07:02:36 UTC
We are also targeting 9.2 so that sounds good.

I hope you don't mind but I set ITR to 9.2 so that we don't miss it.

Comment 5 Iker Pedrosa 2022-11-14 08:15:18 UTC
I think we should target for a rebase of version 1.11.0, as previous versions contain bugs if we are to use OpenSSSL 3+.

Comment 14 errata-xmlrpc 2023-11-07 08:52:11 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (libfido2 bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2023:6614

Comment 15 Red Hat Bugzilla 2024-03-07 04:25:13 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days