Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-113008

crypto-policies in RHEL 10.1 should obsolete crypto-policies-pq-preview

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • crypto-policies-20250905-2.gitc7eb7b2.el10_1
    • No
    • Moderate
    • 1
    • rhel-security-crypto-spades
    • 31
    • 32
    • 0.5
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • Crypto25September
    • Approved Exception
    • Hide

      AC) With RHEL-10.0 and crypto-policies-pq-preview installed you can update the system to RHEL-10.1. Package crypto-policies-pq-preview will be removed but if TEST-PQ subpolicy is active, it will remain so after the update (although it is different on 10.1 and 10.0)

      Show
      AC) With RHEL-10.0 and crypto-policies-pq-preview installed you can update the system to RHEL-10.1. Package crypto-policies-pq-preview will be removed but if TEST-PQ subpolicy is active, it will remain so after the update (although it is different on 10.1 and 10.0)
    • Pass
    • Not Needed
    • Manual
    • Unspecified Release Note Type - Unknown
    • Unspecified
    • Unspecified
    • Unspecified
    • All
    • None

      What were you trying to do that didn't work?

      We have crypto-policies from 10.0 + crypto-policies-pq-preview to enable PQ crypto in RHEL 10.0

       

      # dnf update
      Updating Subscription Management repositories.
      Unable to read consumer identity
      This system is not registered with an entitlement server. You can use "rhc" or "subscription-manager" to register.
      rhel                                                                                                                                                 44 MB/s | 1.5 MB     00:00
      rhel-AppStream                                                                                                                                       48 MB/s | 1.5 MB     00:00
      Error:
       Problem 1: package crypto-policies-pq-preview-20250214-1.gitfd9b9b9.el10_0.1.noarch from @System requires crypto-policies = 20250214-1.gitfd9b9b9.el10_0.1, but none of the providers can be installed
        - cannot install both crypto-policies-20250804-1.git2ca4115.el10.noarch from rhel and crypto-policies-20250214-1.gitfd9b9b9.el10_0.1.noarch from @System
        - cannot install both crypto-policies-20250214-1.gitfd9b9b9.el10_0.1.noarch from rhel-updates and crypto-policies-20250804-1.git2ca4115.el10.noarch from rhel
        - cannot install the best update candidate for package crypto-policies-pq-preview-20250214-1.gitfd9b9b9.el10_0.1.noarch
        - cannot install the best update candidate for package crypto-policies-20250214-1.gitfd9b9b9.el10_0.1.noarch
       Problem 2: problem with installed package crypto-policies-pq-preview-20250214-1.gitfd9b9b9.el10_0.1.noarch
        - package crypto-policies-pq-preview-20250214-1.gitfd9b9b9.el10_0.1.noarch from @System requires oqsprovider, but none of the providers can be installed
        - package crypto-policies-pq-preview-20250214-1.gitfd9b9b9.el10_0.1.noarch from rhel-AppStream-updates requires oqsprovider, but none of the providers can be installed
        - package openssl-1:3.5.1-3.el10.x86_64 from rhel obsoletes oqsprovider < 0.9.0 provided by oqsprovider-0.8.0-5.el10.x86_64 from @System
        - package openssl-1:3.5.1-3.el10.x86_64 from rhel obsoletes oqsprovider < 0.9.0 provided by oqsprovider-0.8.0-5.el10.x86_64 from rhel-AppStream
        - package openssl-1:3.5.1-3.el10.x86_64 from rhel obsoletes oqsprovider < 0.9.0 provided by oqsprovider-0.8.0-5.el10.x86_64 from rhel-AppStream-updates
        - cannot install the best update candidate for package openssl-1:3.2.2-16.el10.x86_64
      (try to add '--allowerasing' to command line to replace conflicting packages or '--skip-broken' to skip uninstallable packages or '--nobest' to use not only best candidate packages)
      

       

      What is the impact of this issue to you?

      On upgrade from 10.0 to 10.1 the crypto policies should remove crypto-policies-pq-preview

      Please provide the package NVR for which the bug is seen:

      How reproducible is this bug?:

      Steps to reproduce

      1.  
      2.  
      3.  

      Expected results

      Actual results

              cllang@redhat.com Clemens Lang
              dbelyavs@redhat.com Dmitry Belyavskiy
              Clemens Lang Clemens Lang
              Ondrej Moris Ondrej Moris
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: