Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-84719

Disallow use of RC4 HMAC-MD5 for session keys by default (CVE-2025-3576) [rhel-10]

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Undefined Undefined
    • rhel-10.1
    • rhel-10.0.z
    • krb5
    • No
    • Moderate
    • rhel-idm-ipa
    • ssg_idm
    • 0
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • None
    • None
    • None
    • CVE - Common Vulnerabilities and Exposures
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      An change was mad upstream to disallow use of RC4 by default (an additional configuration parameter has to be set to allow it):
      https://github.com/krb5/krb5/commit/1b57a4d134bbd0e7c52d5885a92eccc815726463

      This restriction is also part of MS-KILE:
      https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-kile/6cfc7b50-11ed-4b4d-846d-6f08f0812919

      This change was reverted to avoid conflicts with the crypto-policy system. But it may still be needed for restricting use of RC4 for session keys specifically.

              jrische@redhat.com Julien Rische
              jrische@redhat.com Julien Rische
              Julien Rische Julien Rische
              Michal Polovka Michal Polovka
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: