Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-6628

FIPS: OSO18: python-google-auth pulls in python-rsa

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Major Major
    • rhos-18.0.0
    • None
    • python-google-auth
    • None
    • Moderate

      The python-google-auth library implements a fallback mechanism wherein it tries to import signing from python-cryptography (thereby using openssl) and falling back to python-rsa.

      To the extent possible, we should be eliminating usage and references to encryption libraries that are not being validated for usage in FIPS-required environments.

      Since python-rsa is not going to be a supported encryption algorithm in FIPS environments and we do provide python-cryptography, we should patch the dependency out of python-google-auth.

            shrjoshi@redhat.com Shreshtha Joshi
            rhn-engineering-lhh Lon Hohberger
            rhos-dfg-reldel
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: