Bug 2227258
| Summary: | Support requiring EMS in TLS 1.2, default to it when in FIPS mode [rhel-9.0.0.z] | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | RHEL Program Management Team <pgm-rhel-tools> |
| Component: | gnutls | Assignee: | Daiki Ueno <dueno> |
| Status: | CLOSED ERRATA | QA Contact: | Alexander Sosedkin <asosedki> |
| Severity: | unspecified | Docs Contact: | Mirek Jahoda <mjahoda> |
| Priority: | high | ||
| Version: | 9.0 | CC: | asosedki, mjahoda, ssorce, zfridric |
| Target Milestone: | rc | Keywords: | Triaged, ZStream |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | gnutls-3.7.6-19.el9_0 | Doc Type: | Enhancement |
| Doc Text: |
.GnuTLS requires EMS with TLS 1.2 in FIPS mode
To comply with the FIPS-140-3 standard, GnuTLS servers and clients by default require the Extended Master Secret (EMS) extension (RFC 7627) for all TLS 1.2 connections negotiated in FIPS mode. If your scenario requires preserving compatibility with older servers and clients that do not support EMS and you cannot use TLS 1.3, you can opt-out of the system-wide cryptographic policies by adding the `tls-session-hash` option with the `request` value to the `/etc/crypto-policies/local.d/gnutls-no-ems.config` configuration file:
----
[overrides]
tls-session-hash = request
----
After you add the option to `/etc/crypto-policies/local.d/gnutls-no-ems.config`, make the changes effective by entering the `update-crypto-policies` command.
WARNING: If you allow TLS 1.2 connections without EMS, your system no longer meets the FIPS-140-3 requirements.
|
Story Points: | --- |
| Clone Of: | 2157953 | Environment: | |
| Last Closed: | 2023-08-29 09:18:32 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2157953 | ||
| Bug Blocks: | |||
|
Comment 8
errata-xmlrpc
2023-08-29 09:18:32 UTC
|