Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-126826

Upstream libvirt support for loading multiple sets of x509 certificates for PQC hybrid mode

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • 1
    • rhel-virt-confidential-virt
    • ConfVirt Sprint 3
    • 5
    • False
    • Hide

      None

      Show
      None
    • None

      To support hybrid mode for PQC, the TLS library (GNUTLS for libvirt) must be provided multiple distinct sets of certificates. One set using classic DSA algorithm, and one set using ML-DSA algorithm.

      This requires calling gnutls_certificate_set_x509_key() with different pem files loaded, which is not something libvirt is currently able to do. 

      This task tracks the upstream impl & subsystem merge

              rhn-engineering-berrange Daniel Berrangé
              rhn-engineering-berrange Daniel Berrangé
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated: