Bug 1959016
| Summary: | SHA-1 support in legacy mode at SECLEVEL 1 | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | Sahana Prasad <sahana> |
| Component: | openssl | Assignee: | Sahana Prasad <sahana> |
| Status: | CLOSED WONTFIX | QA Contact: | Alicja Kario <hkario> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | medium | ||
| Version: | CentOS Stream | CC: | asosedki, bstinson, hkario, jwboyer, omoris, szidek |
| Target Milestone: | beta | Keywords: | Triaged |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Enhancement | |
| Doc Text: |
Feature:
SHA-1 is only supported in LEGACY mode in RHEL-9
Reason:
SHA-1 support is still needed for backwards compatibility with RHEL-8 to verify signatures. This will also help users that haven't migrated from using SHA-1 yet.
Internally for OpenSSL in RHEL-9, SHA-1 support will be at SECLEVEL 1. SECLEVEL1 will inherit all it's algorithms and key sizes from SECLEVEL2, except that it would also support SHA-1
Upstream definitions of SELEVELs can be found here:
https://www.openssl.org/docs/manmaster/man3/SSL_CTX_get_security_level.html
Result:
Successful verification of SHA-1 certs and signatures in LEGACY mode.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-12-13 11:29:04 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1960700 | ||
|
Description
Sahana Prasad
2021-05-10 15:05:59 UTC
*** Bug 1954616 has been marked as a duplicate of this bug. *** |