Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-133522

Enable MLKEM in all libssh policies

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Minor Minor
    • rhel-10.2
    • rhel-10.2
    • crypto-policies
    • crypto-policies-20260216-1.git0e54016.el10
    • Moderate
    • rhel-security-crypto-spades
    • 26
    • 0
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • None
    • Hide

      AC) mlkem768x25519-sha256 becomes the top kex in all libssh policies we ship

      Show
      AC) mlkem768x25519-sha256 becomes the top kex in all libssh policies we ship
    • Pass
    • Enabled
    • Automated
    • Enhancement
    • Hide
      Feature, enhancement: crypto-policies now supports mlkem768x25519-sha256 in libssh
      Reason: libssh 0.12 now supports mlkem768x25519-sha256 key exchange
      Result: mlkem768x25519-sha256 effectively enabling it by default with the highest priority in all the predefined cryptographic policies shipped in RHEL, bringing it closer to openssh
      Show
      Feature, enhancement: crypto-policies now supports mlkem768x25519-sha256 in libssh Reason: libssh 0.12 now supports mlkem768x25519-sha256 key exchange Result: mlkem768x25519-sha256 effectively enabling it by default with the highest priority in all the predefined cryptographic policies shipped in RHEL, bringing it closer to openssh
    • Proposed
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Libssh 0.12 will support MLKEM key exchange and we need to crypto-policies to support that as well (in all base policies, analogously to openssh mlkem support).

              omoris Ondrej Moris
              omoris Ondrej Moris
              Alexander Sosedkin Alexander Sosedkin
              Ondrej Moris Ondrej Moris
              Mirek Jahoda Mirek Jahoda
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: