Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-86951

wpa_supplicant: use pkcs11 provider

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • rhel-10.1
    • rhel-10.0
    • wpa_supplicant
    • wpa_supplicant-2.11-4.el10
    • No
    • Important
    • 3
    • rhel-net-core-2
    • ssg_networking
    • 12
    • 16
    • 2
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • NST-Core2-25W22, NST-Core2-25W26, NST-Core2-25W30
    • Bug Fix
    • Hide
      .Network authentication methods using PKCS #11 with `wpa_supplicant` has been fixed

      In RHEL 10, engines that are not compatible with the Federal Information Processing Standard (FIPS), such as the OpenSSL engine API, have been removed. Consequently, the dependent `wpa_supplicant` service could not load X.509 certificates and keys stored in PKCS #11 URI format. This prevented any EAP-TLS authentication method and variants using PKCS #11 did not connect to the relevant network. To fix this problem, `wpa_supplicant` now depends on the `pkcs11-provider` package and uses the same-named library to load X.509 certificates and keys from a PKCS #11 storage. As a result, network authentication methods using PKCS #11 work as expected.
      Show
      .Network authentication methods using PKCS #11 with `wpa_supplicant` has been fixed In RHEL 10, engines that are not compatible with the Federal Information Processing Standard (FIPS), such as the OpenSSL engine API, have been removed. Consequently, the dependent `wpa_supplicant` service could not load X.509 certificates and keys stored in PKCS #11 URI format. This prevented any EAP-TLS authentication method and variants using PKCS #11 did not connect to the relevant network. To fix this problem, `wpa_supplicant` now depends on the `pkcs11-provider` package and uses the same-named library to load X.509 certificates and keys from a PKCS #11 storage. As a result, network authentication methods using PKCS #11 work as expected.
    • Done
    • Done
    • Done
    • Not Required
    • None

            dcaratti@redhat.com Davide Caratti
            dcaratti@redhat.com Davide Caratti
            Davide Caratti Davide Caratti
            Laura Trivelloni Laura Trivelloni
            Marc Muehlfeld Marc Muehlfeld
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated: