Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-64746

specify allow-rsa-pkcs1-encrypt = false for gnutls

    • crypto-policies-20241105-1.git978ac26.el10
    • No
    • Low
    • 1
    • rhel-sst-security-crypto
    • ssg_security
    • 13
    • 1
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Crypto24Q4
    • Hide

      gnutls configs gain an extra line, `allow-rsa-pkcs1-encrypt = true` in LEGACY and `allow-rsa-pkcs1-encrypt = false` in the other policies
      [/CoreOS/crypto-policies/Sanity/retention]

      it's wired to __rsaes_pkcs1_v1_5_encrypt_decrypt = ALLOW/DISALLOW [manual one-time inspection]

      Show
      gnutls configs gain an extra line, `allow-rsa-pkcs1-encrypt = true` in LEGACY and `allow-rsa-pkcs1-encrypt = false` in the other policies [/CoreOS/crypto-policies/Sanity/retention] it's wired to __rsaes_pkcs1_v1_5_encrypt_decrypt = ALLOW/DISALLOW [manual one-time inspection]
    • Pass
    • Enabled
    • Automated
    • Deprecated Functionality
    • Hide
      GnuTLS will block encrypting and decrypting with RSA PKCS#1 v1.5 padding by default.

      Note: Deprecation means removal of support in a future major release.
      Description (describe the discontinued feature):
      Consequence (describe the recommended replacement, if applicable. In addition, add a deprecation event to the Package Evolution Service (PES)):
      Show
      GnuTLS will block encrypting and decrypting with RSA PKCS#1 v1.5 padding by default. Note: Deprecation means removal of support in a future major release. Description (describe the discontinued feature): Consequence (describe the recommended replacement, if applicable. In addition, add a deprecation event to the Package Evolution Service (PES)):
    • Proposed
    • None

      gnutls has introduced an allow-rsa-pkcs1-encrypt option. we want it off in DEFAULT and the rest, but, probably, on in LEGACY.

       

      option name suggestion: `__rsaes_pkcs1_v1_5_encrypt_decrypt` defaulting to 0 and being set to 1 in LEGACY only.

              asosedki@redhat.com Alexander Sosedkin
              asosedki@redhat.com Alexander Sosedkin
              Alexander Sosedkin Alexander Sosedkin
              Ondrej Moris Ondrej Moris
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: