Bug 2027525
| Summary: | Backport request: KBKDF R parameter | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Peter Robinson <perobins> |
| Component: | openssl | Assignee: | Dmitry Belyavskiy <dbelyavs> |
| Status: | CLOSED WONTFIX | QA Contact: | BaseOS QE Security Team <qe-baseos-security> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 8.6 | CC: | amurdaca, bbreard, dbelyavs, perobins, qe-baseos-security, sahana |
| Target Milestone: | rc | Keywords: | Triaged |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | 2027261 | Environment: | |
| Last Closed: | 2022-11-28 09:31:24 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1989930, 2027261 | ||
| Bug Blocks: | |||
|
Description
Peter Robinson
2021-11-29 22:00:51 UTC
One further note: RHEL8 is also missing the UseL parameter, which we also require. To preserve the existing FIPS 140-2 certification of OpenSSL in RHEL 8, we will not be implementing this change and closing this issue. Modifications except for (a) CVE fixes, (b) adaptions to new FIPS requirements, or (c) changes that do not affect security relevant code would not be accepted for re-certification by NIST. We have determined that this issue does not meet these criteria. |