Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-138448

Due to RHEL-111491, CIS check "1.6.3 Ensure system wide crypto policy disables sha1 hash andsignature support (Automated)" now fails

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • rhel-9.7
    • crypto-policies
    • None
    • None
    • Moderate
    • rhel-security-crypto-spades
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      With RHEL-111491 fixing, a new hash@rpm = ... SHA1 was introduced in the crypto policy.
      This makes CIS check {{1.6.3 Ensure system wide crypto policy disables sha1 hash and
      signature support (Automated)}} fail because a line is returned:

      # awk -F= '($1~/(hash|sign)/ && $2~/SHA1/ && $2!~/^\s*\-
      \s*([^#\n\r]+)?SHA1/){print}' /etc/crypto-policies/state/CURRENT.pol
      hash@rpm = SHA2-256 SHA2-384 SHA2-512 SHA3-256 SHA3-384 SHA3-512 SHA2-224 SHA3-224 SHAKE-256 SHA1
      

      (Page 196 of the attached PDF)

      The above check searches for "SHA1" in any "hash" or "sign" key, whatever the provider is, and IMHO it's right to do so.

      What is the impact of this issue to you?

      Failure to comply the CIS standard

      Please provide the package NVR for which the bug is seen:

      crypto-policies-20250905-1.git377cc42.el9_7.noarch

      How reproducible is this bug?

      Always, see above.

              asosedki@redhat.com Alexander Sosedkin
              rhn-support-rmetrich Renaud Métrich
              Vojtech Polasek
              Alexander Sosedkin Alexander Sosedkin
              Ondrej Moris Ondrej Moris
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: