Bug 2003034
| Summary: | Revert default gnupg2 keys from ed25519/cv25519 to have unified default for FIPS (was: GPG generated with default algorithm is not accepted by rpm --addsign) [rhel-9.0.0] | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | RHEL Program Management Team <pgm-rhel-tools> |
| Component: | gnupg2 | Assignee: | Jakub Jelen <jjelen> |
| Status: | CLOSED ERRATA | QA Contact: | Stanislav Zidek <szidek> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 9.0 | CC: | emrakova, hkario, jblazek, jpazdziora, jwboyer, mdomonko, pvlasin, ssorce, szidek |
| Target Milestone: | rc | Keywords: | Triaged |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | gnupg2-2.3.1-3.el9 | Doc Type: | Bug Fix |
| Doc Text: |
Cause: The new GnuPG generates ed25519/curve25519 keys by default.
Consequence: The ed25519/curve25519 keys are not approved in FIPS mode so mixed deployment (FIPS/non-FIPS/older systems) could have interoperability issues.
Fix: The default was reverted to 3k RSA keys.
Result: The GnuPG generated RSA keys by default, which should not cause interoperability problems with FIPS machines or older systems.
|
Story Points: | --- |
| Clone Of: | 2001937 | Environment: | |
| Last Closed: | 2022-05-17 15:37:05 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2001937 | ||
| Bug Blocks: | |||
|
Comment 5
errata-xmlrpc
2022-05-17 15:37:05 UTC
|