Bug 2188180
| Summary: | Enable support for brainpool curves in ECC in RHEL | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | Sahana Prasad <shebburn> |
| Component: | openssl | Assignee: | Sahana Prasad <shebburn> |
| Status: | VERIFIED --- | QA Contact: | Hubert Kario <hkario> |
| Severity: | medium | Docs Contact: | Mirek Jahoda <mjahoda> |
| Priority: | medium | ||
| Version: | 9.3 | CC: | cllang, dbelyavs, hkario, shebburn |
| Target Milestone: | rc | Keywords: | Triaged |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | openssl-3.0.7-21.el9 | Doc Type: | Enhancement |
| Doc Text: |
Feature: Enable support for brainpool curves in ECC
Reason:
There were requests from customers to enable brainpool curves in RHEL. This update therefore enables long brainpool curves by default in ECC in RHEL 9.3
Result:
The following brainpool curves are enabled and available for use in RHEL 9.3
brainpoolP256r1
brainpoolP256t1
brainpoolP320r1
brainpoolP320t1
brainpoolP384r1
brainpoolP384t1
brainpoolP512r1
brainpoolP512t1
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | Bug | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Sahana Prasad
2023-04-20 02:29:44 UTC
Setting a doc type, but we still need to fill the doc text. Dev testing logs on 1minute-tip machine: [root@vm-10-0-185-157 ~]# [root@vm-10-0-185-157 ~]# openssl ecparam -list_curves secp224r1 : NIST/SECG curve over a 224 bit prime field secp384r1 : NIST/SECG curve over a 384 bit prime field secp521r1 : NIST/SECG curve over a 521 bit prime field prime256v1: X9.62/SECG curve over a 256 bit prime field [root@vm-10-0-185-157 ~]# uname -a Linux vm-10-0-185-157.hosted.upshift.rdu2.redhat.com 5.14.0-329.el9.x86_64 #1 SMP PREEMPT_DYNAMIC Sat Jun 17 15:36:40 EDT 2023 x86_64 x86_64 x86_64 GNU/Linux [root@vm-10-0-185-157 ~]# cat /proc/sys/crypto/fips_enabled 1 |