-
Bug
-
Resolution: Done-Errata
-
Normal
-
rhel-9.4, rhel-9.4.z
-
openssh-9.9p1-11.el10
-
None
-
Moderate
-
FutureFeature
-
2
-
rhel-security-crypto
-
ssg_security
-
26
-
0.5
-
False
-
False
-
-
Yes
-
Red Hat Enterprise Linux
-
Crypto25Q2, Crypto25July
-
-
Pass
-
Not Needed
-
New Test Coverage
-
Enhancement
-
-
Done
-
Done
-
Done
-
Unspecified
-
-
All
-
None
We are starting to get requests for this feature due to the US Government OMB mandate M-22-09: (III.A.3) "When authorizing users to access resources, agencies must consider at least one device-level signal alongside identity information about the authenticated user".
We are trying to enforce authentication indicators in Kerberos when using OpenSSH.
I believe that https://github.com/openssh/openssh-portable/compare/master...abbra:openssh-portable:gssapi-indicators has already implemented this.
- links to
-
RHSA-2025:148796
openssh security update