Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-106866

Enable ML-KEM hybrids in NSS in PQ subpolicy [rhel-9]

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • crypto-policies-20250804-1.git2c74f3d.el9
    • No
    • Low
    • 1
    • rhel-security-crypto
    • 26
    • 0.5
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Crypto25August
    • Hide

      AC1) NSS generated policy for DEFAULT:PQ contains mlkem768x25519, mlkem768secp256r1, and mlkem1024secp384r1 MLKEM groups.

      Show
      AC1) NSS generated policy for DEFAULT:PQ contains mlkem768x25519, mlkem768secp256r1, and mlkem1024secp384r1 MLKEM groups.
    • Pass
    • Enabled
    • Automated
    • Enhancement
    • Hide
      .`crypto-polices` enables ML-KEM for NSS

      With this update, the `crypto-polices` component enables Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) for NSS in the DEFAULT:PQ subpolicy. As a result, NSS use the ML-KEM in TLS if the system has enabled the PQ subpolicy or a custom subpolicy and the other peer supports it as well.
      Show
      .`crypto-polices` enables ML-KEM for NSS With this update, the `crypto-polices` component enables Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) for NSS in the DEFAULT:PQ subpolicy. As a result, NSS use the ML-KEM in TLS if the system has enabled the PQ subpolicy or a custom subpolicy and the other peer supports it as well.
    • In Progress
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      as NSS nss-3.112 got support for hybrid groups with ML-KEM in TLS, we should enable it in crypto-policies. In RHEL-9 that'd be PQ subpolicy specifically.

      Please enable the mlkem768x25519, mlkem768secp256r1, and mlkem1024secp384r1 groups

      Using crypto-policies-20250721-1.git162e4cb.el9.noarch

              asosedki@redhat.com Alexander Sosedkin
              hkario@redhat.com Alicja Kario
              Alexander Sosedkin Alexander Sosedkin
              Ondrej Moris Ondrej Moris
              Mirek Jahoda Mirek Jahoda
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: