Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-39734

Create FIPS-compliant PKCS#12 when in FIPS mode

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • rhel-10.0.beta
    • gnutls
    • gnutls-3.8.7-1.el10
    • None
    • None
    • FutureFeature
    • 1
    • rhel-sst-security-crypto
    • ssg_security
    • 1
    • False
    • Hide

      None

      Show
      None
    • None
    • Crypto24Q3
    • None

      GnuTLS should create PKCS #12 that are FIPS compliant by default: use the PBMAC1 for the PKCS #12 files MAC.

      We should support reading files like this in normal mode, have ability to create them in normal mode, but probably not create them by default in normal mode.

      IOW: implement RFC 9579 and use it by default in FIPS mode

              dueno@redhat.com Daiki Ueno
              hkario@redhat.com Alicja Kario
              Daiki Ueno Daiki Ueno
              Alexander Sosedkin Alexander Sosedkin
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: