Bug 1961428 - [RFE] support FIPS-186-5 (eddsa) (RHCS / NSS)
Summary: [RFE] support FIPS-186-5 (eddsa) (RHCS / NSS)
Keywords:
Status: NEW
Alias: None
Product: Red Hat Enterprise Linux 9
Classification: Red Hat
Component: nss
Version: 9.1
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Bob Relyea
QA Contact: Alexander Sosedkin
URL:
Whiteboard:
Depends On:
Blocks: 2054156
TreeView+ depends on / blocked
 
Reported: 2021-05-17 22:09 UTC by Marc Sauton
Modified: 2023-07-31 22:37 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Mozilla Foundation 1325335 0 P3 ASSIGNED Integrate HACL* EdDSA over Curve25519 2022-01-06 17:15:03 UTC
Red Hat Issue Tracker CRYPTO-7667 0 None None None 2022-06-22 14:58:31 UTC
Red Hat Issue Tracker RHELPLAN-104901 0 None None None 2021-12-06 20:13:15 UTC

Description Marc Sauton 2021-05-17 22:09:21 UTC
Description of problem:

this is a really wide statement: support FIPS-186-5

we "only" reference and support FIPS-186-4 from July 2013 in the install guide at
"
https://access.redhat.com/documentation/en-us/red_hat_certificate_system/10/pdf/planning_installation_and_deployment_guide/Red_Hat_Certificate_System-10-Planning_Installation_and_Deployment_Guide-en-US.pdf
3.2. ALLOWED KEY ALGORITHMS AND THEIR SIZES
"

FIPS-186-5 has been superseding FIPS-186-4 since October 2019

I do not know all the differences and implications, but this should be explored.

For example, one public sector customer has a requirement for "Edwards-Curve Digital Signature Algorithm" / EdDSA support, which we do not have in NSS.


Version-Release number of selected component (if applicable):
RHCS-10 on RHEL-8


How reproducible:


Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:

Comment 2 Marc Sauton 2021-05-17 22:20:43 UTC
Edwards-Curve Digital Signature Algorithm (EdDSA)
https://datatracker.ietf.org/doc/html/rfc8032


Note You need to log in before you can comment on or make changes to this bug.