-
Bug
-
Resolution: Unresolved
-
Normal
-
rhel-10.0.beta
-
openssl-3.2.2-7.el10
-
None
-
None
-
1
-
rhel-sst-security-crypto
-
ssg_security
-
26
-
1
-
QE ack, Dev ack
-
False
-
-
No
-
Crypto24Q3
-
- SHA-1 signature creation and verification with DEFAULT policy doesn't work in any context (TLS or outside of TLS)
- SHA-1 signature creation and verification with LEGACY policy works outside the TLS context
-
Pass
-
Automated
-
Release Note Not Required
-
None
with openssl-3.2.1-3 both creating and verifying SHA-1 signatures works in normal mode. Unless the sha-1 policy is enabled that shouldn't work.
- is related to
-
RHEL-50106 LEGACY policy should not permit SHA-1 signature use
- Release Pending
-
RHEL-47210 -cipher DEFAULT:@SECLEVEL=0 -sigalgs SHA1+RSA does not enable support for SHA-1 signatures
- Release Pending
- links to
-
RHBA-2024:133129 OpenSSL bugfix release