Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 2162624

Summary: [IBM 9.3 FEAT] ibmca implicit rejection (openssl-ibmca)
Product: Red Hat Enterprise Linux 9 Reporter: IBM Bug Proxy <bugproxy>
Component: openssl-ibmcaAssignee: Dan Horák <dhorak>
Status: CLOSED ERRATA QA Contact: Karel Srot <ksrot>
Severity: high Docs Contact:
Priority: high    
Version: 9.3CC: bugproxy, jomiller, tstaudt
Target Milestone: rcKeywords: FutureFeature, OtherQA, Patch, TestOnly, Triaged
Target Release: 9.3Flags: pm-rhel: mirror+
Hardware: s390x   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-11-07 08:55:36 UTC Type: Feature Request
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version: 2.4.0
Embargoed:
Bug Depends On:    
Bug Blocks: 2116377    

Description IBM Bug Proxy 2023-01-20 08:20:25 UTC

Comment 1 IBM Bug Proxy 2023-01-20 08:20:31 UTC
1. Feature Overview:
Feature Id: [201321]
a. Name of Feature: [9.3 FEAT] ibmca implicit rejection (openssl-ibmca)
b. Feature Description

Add configurable support for implicit rejection to the RSA implementation in the ibmca provider.
The ibmca provider shall have the same default behaviour as the default provider.
Remediation against CVEs like CVE-2020-25659 and CVE-2020-25657, see https://github.com/openssl/openssl/issues/13421

2. Feature Details:
Sponsor: ---
Architectures:  zSeries - 64 native, 

Arch Specificity: purely arch specific code
Affects Kernel Modules: No
Delivery Mechanism: Direct from Community
Category: other
Request Type: Package - Update Version
d. Upstream Acceptance: In Progress
Sponsor Priority P1
f. Severity: high
IBM Confidential: Yes
Code Contribution: ---
g. Component Version Target: Yes

3. Business Case
Security

4. Primary contact at Red Hat, email, phone (chat):
Joshua Miller
jomiller
919-740-7804

5. Primary contacts at Partner:
Project Management Contact:
Thomas Staudt, tstaudt.com

Technical contact(s):
Thomas Staudt, tstaudt.com

Comment 3 Dan Horák 2023-04-21 07:39:29 UTC
IBM/Thomas, what is the status of this feature, is it part of the 2.4.0 release? Does https://github.com/opencryptoki/openssl-ibmca/commit/276e3ddf55a2993c3de5666003b856ef6f8d7d24 fulfill the requirement?

Comment 4 IBM Bug Proxy 2023-04-24 06:11:11 UTC
------- Comment From tstaudt.com 2023-04-24 02:05 EDT-------
(In reply to comment #6)
> IBM/Thomas, what is the status of this feature, is it part of the 2.4.0
> release? Does
> https://github.com/opencryptoki/openssl-ibmca/commit/
> 276e3ddf55a2993c3de5666003b856ef6f8d7d24 fulfill the requirement?

Hi Dan,

it is included in openssl-ibmca 2.4.0 and I assume this is the commit.

Comment 10 IBM Bug Proxy 2023-08-14 07:31:48 UTC
------- Comment From ifranzki.com 2023-08-10 09:18 EDT-------
Successfully verified this on RHEL 9.3 nightly from 2023/08/07 with openssl-ibmca-2.4.0-4.el9.
Please set to VERIFIED.

Comment 13 errata-xmlrpc 2023-11-07 08:55:36 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (openssl-ibmca bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2023:6678