Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-151580

openssh explodes with FIPS:PQ in FIPS [rhel-9]

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • rhel-9.8
    • rhel-9.8
    • openssh
    • None
    • No
    • Important
    • rhel-security-crypto-diamonds
    • 27
    • 28
    • 0
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • Approved Exception
    • Pass
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      Enable mlkem768x25519-sha256 in crypto-policies (https://issues.redhat.com/browse/RHEL-151499)

      What is the impact of this issue to you?

      Can't enable it in 9 PQ for fears that someone might be driving FIPS:PQ.

      That leaves 9.8 without PQ SSH unless one forces an algorithm.

      Please provide the package NVR for which the bug is seen:

      openssh-9.9p1-3.el9

      How reproducible is this bug?:

      reliably

      Steps to reproduce

      1. be in FIPS mode
      2. update-crypto-policies --set FIPS:PQ

      Expected results

      the algorithm is skipped, connections happen with a different kex, sshd doesn't just crash

      Actual results

      your ssh complains that "mlkem768x25519-sha256" is not allowed in FIPS mode, and your sshd is down

              dbelyavs@redhat.com Dmitry Belyavskiy
              asosedki@redhat.com Alexander Sosedkin
              Dmitry Belyavskiy Dmitry Belyavskiy
              Miluse Bezo Konecna Miluse Bezo Konecna
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: