Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-148560

Allow hybrid ML-KEM in OpenSSH

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • rhel-10.2
    • rhel-10.2
    • crypto-policies
    • None
    • crypto-policies-20260216-1.git0e54016.el10
    • Moderate
    • rhel-security-crypto-spades
    • 0
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • None
    • Hide

      AC1) In all policies the mlkem768nistp256-sha256 and mlkem1024nistp384-sha384 key exchange algorithms are allowed.

      AC2) In all policies except FIPS mlkem768x25519-sha256 key exchange algorithm is allowed.

      Show
      AC1) In all policies the mlkem768nistp256-sha256 and mlkem1024nistp384-sha384 key exchange algorithms are allowed. AC2) In all policies except FIPS mlkem768x25519-sha256 key exchange algorithm is allowed.
    • Pass
    • Enabled
    • Automated
    • Enhancement
    • Hide
      Feature, enhancement: crypto-policies enables mlkem768nistp256-sha256 and mlkem1024nistp384-sha384 key exchange algorithms in FIPS mode for openssh
      Reason: openssh gained support for using ML-KEM NIST curve hybrids in FIPS mode
      Result: 10.2 hosts in FIPS mode with FIPS policy active should perform key exchange with mlkem768nistp256-sha256 or mlkem1024nistp384-sha384 should the other peer support and prefer them.
      Show
      Feature, enhancement: crypto-policies enables mlkem768nistp256-sha256 and mlkem1024nistp384-sha384 key exchange algorithms in FIPS mode for openssh Reason: openssh gained support for using ML-KEM NIST curve hybrids in FIPS mode Result: 10.2 hosts in FIPS mode with FIPS policy active should perform key exchange with mlkem768nistp256-sha256 or mlkem1024nistp384-sha384 should the other peer support and prefer them.
    • Proposed
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      The following hybrid ML_KEMs should be allowed:

      • NIST curves + ML-KEM - FIPS/non-FIPS modes
      • ed25519 + ML-KEM - non-FIPS mode, FIPS mode when we have fips-provider-next (if distinguishable)

              asosedki@redhat.com Alexander Sosedkin
              dbelyavs@redhat.com Dmitry Belyavskiy
              Alexander Sosedkin
              Mirek Jahoda Mirek Jahoda
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: