-
Bug
-
Resolution: Unresolved
-
Major
-
None
-
crypto-policies-20250424-1.git9267dee.el10
-
No
-
Moderate
-
1
-
rhel-security-crypto
-
ssg_security
-
9
-
10
-
1.5
-
-
False
-
-
Yes
-
Crypto25Q2
-
-
Pass
-
Not Needed
-
Automated
-
Enhancement
-
-
Proposed
-
Unspecified
-
Unspecified
-
Unspecified
-
None
we are planning the following:
OpenSSL in RHEL will be rebased to 3.5 (the version that has the native support of PQ crypto) as soon as it is released (currently the release is planned to Apr 8, 2025). The new version will obsolete the oqsprovider package used for providing PQ crypto in 10.0.
PQ crypto algorithms ML-DSA (pure) and ML-KEM(hybrid) will be added to DEFAULT, LEGACY, and FUTURE crypto-policies with the highest priority.
Some extended support of other PQ algorithms (pure ML-KEM, hybrid ML-DSA, etc) might be kept in the optional TEST-PQ crypto policies.
These changes are to land by CTC1.
We may also want to implement NO-PQ subpolicy
Acceptance Criteria proposal:
1. SanityOnly LEGACY/DEFAULT/FUTURE policies:
- prepend the following to group: X25519-MLKEM768, P256-MLKEM768, P384-MLKEM1024 and MLKEM768-X25519
- prepend the following to sign: MLDSA44, MLDSA65 and MLDSA87
- prepend the following to key_exchange: KEM-ECDH
2. newly introduced NO-PQ subpolicy disables the algorithms above
3. Applying these policies does not cause warnings.
- is blocked by
-
RHEL-80811 Rebase OpenSSL to 3.5
-
- Release Pending
-
- relates to
-
RHEL-85078 Change TEST-PQ to include only long-term supported algorithms
-
- Closed
-
- links to
-
RHBA-2025:148296 crypto-policies bug fix and enhancement update