Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-104607

enable ED25519 in RHEL-9 NSS policy

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • crypto-policies-20250721-1.git162e4cb.el9
    • No
    • Low
    • 1
    • rhel-security-crypto
    • 21
    • 26
    • 0.2
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Crypto25August
    • Hide

      AC1) ED25519 is allowerd in NSS generated policies (all except FIPS).

      Show
      AC1) ED25519 is allowerd in NSS generated policies (all except FIPS).
    • Pass
    • Enabled
    • Automated
    • Enhancement
    • Hide
      .`crypto-policies` support Ed25519 in NSS

      With this update to the system-wide cryptographic policies, support for the SHA-512 variant of the Edwards-curve Digital Signature Algorithm (EdDSA), Ed25519, is available for Network Security Services (NSS). As a result, `crypto-policies` enable Ed25519 in DEFAULT, LEGACY, and FUTURE policies for NSS by default.
      Show
      .`crypto-policies` support Ed25519 in NSS With this update to the system-wide cryptographic policies, support for the SHA-512 variant of the Edwards-curve Digital Signature Algorithm (EdDSA), Ed25519, is available for Network Security Services (NSS). As a result, `crypto-policies` enable Ed25519 in DEFAULT, LEGACY, and FUTURE policies for NSS by default.
    • Done
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      NSS RHEL-9 crypto-policy doesn't have ED25519, which is likely just an oversight. Wire it up to `sign = EDDSA-ED25519`.

              asosedki@redhat.com Alexander Sosedkin
              asosedki@redhat.com Alexander Sosedkin
              Malhar Jivrajani
              Alexander Sosedkin Alexander Sosedkin
              Ondrej Moris Ondrej Moris
              Mirek Jahoda Mirek Jahoda
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: