Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-106868

Enable the mlkem1024secp384r1 group for NSS

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • crypto-policies-20250804-1.git2ca4115.el10
    • No
    • Low
    • 1
    • rhel-security-crypto
    • 26
    • 0.5
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Crypto25August
    • Hide

      AC1) Generated policy for NSS contains all three mlkem groups, ie. mlkem768x25519, mlkem768secp256r1 and mlkem1024secp384r1.

      Show
      AC1) Generated policy for NSS contains all three mlkem groups, ie. mlkem768x25519, mlkem768secp256r1 and mlkem1024secp384r1.
    • Pass
    • Enabled
    • Automated
    • Enhancement
    • Hide
      .`crypto-policies` enables `secp384r1mlkem1024`

      With this update, the `crypto-polices` component enables the `secp384r1mlkem1024` hybrid Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) group for NSS. The addition of `secp384r1mlkem1024` completes `crypto-policies` enabling all three hybrid ML-KEM groups, `mlkem768x25519`, `secp256r1mlkem768`, and `secp384r1mlkem1024`. As a result, NSS considers `secp384r1mlkem1024` for negotiation in TLS if enabled by the currently active system-wide cryptographic policy, such as DEFAULT.
      Show
      .`crypto-policies` enables `secp384r1mlkem1024` With this update, the `crypto-polices` component enables the `secp384r1mlkem1024` hybrid Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) group for NSS. The addition of `secp384r1mlkem1024` completes `crypto-policies` enabling all three hybrid ML-KEM groups, `mlkem768x25519`, `secp256r1mlkem768`, and `secp384r1mlkem1024`. As a result, NSS considers `secp384r1mlkem1024` for negotiation in TLS if enabled by the currently active system-wide cryptographic policy, such as DEFAULT.
    • Done
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      The new NSS in RHEL-10.1 supports all three hybrid ML-KEM groups, but crypto-policies enable only mlkem768x25519 and mlkem768secp256r1, please add also mlkem1024secp384r1.

      Using crypto-policies-20250714-1.git95bf40e.el10.noarch

      Also, probably the names are wrong? shouldn't they be secp256r1mlkem768 and secp384r1mlkem1024 (to mirror the on-the-wire order)?

              asosedki@redhat.com Alexander Sosedkin
              hkario@redhat.com Alicja Kario
              Alexander Sosedkin Alexander Sosedkin
              Ondrej Moris Ondrej Moris
              Mirek Jahoda Mirek Jahoda
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: