Bug 2164763
Summary: | In FIPS mode, openssl should reject short KDF input or output keys or provide an indicator | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 9 | Reporter: | Clemens Lang <cllang> | |
Component: | openssl | Assignee: | Clemens Lang <cllang> | |
Status: | CLOSED ERRATA | QA Contact: | Alicja Kario <hkario> | |
Severity: | high | Docs Contact: | ||
Priority: | high | |||
Version: | 9.0 | CC: | cllang, dbelyavs, hkario, ssorce | |
Target Milestone: | rc | Keywords: | Triaged, ZStream | |
Target Release: | --- | |||
Hardware: | x86_64 | |||
OS: | Linux | |||
Whiteboard: | ||||
Fixed In Version: | openssl-3.0.7-17.el9 | Doc Type: | No Doc Update | |
Doc Text: | Story Points: | --- | ||
Clone Of: | ||||
: | 2175864 2175865 2175866 (view as bug list) | Environment: | ||
Last Closed: | 2023-11-07 08:52:59 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | ||||
Bug Blocks: | 2175864, 2175865, 2175866 |
Description
Clemens Lang
2023-01-26 12:34:54 UTC
For calls to EVP_KDF_derive() with short output lengths, we decided to also change the explicit indicator queried from the EVP_KDF_CTX. We will set the indicator to unapproved when any EVP_KDF_derive() invocation uses a short key length, and will not re-set it when a subsequent call uses a longer output key length. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (openssl bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2023:6627 |