Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-91181

Relax GSS Kex restriction in FIPS mode

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • rhel-10.2
    • rhel-10.0
    • openssh
    • openssh-9.9p1-14.el10
    • No
    • Low
    • 2
    • rhel-security-crypto-diamonds
    • ssg_security
    • 10
    • 1.5
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Crypto25August, Crypto25September
    • Hide

      AC1 manually check that patch fixing this issue is correctly applied and present in compose
      AC2 manually checked the compatibility with previous version: client with patched openssh version succesfully connect to the server running with previous openssh version

      AC3 GSS Kex using groups KEX_GSS_GRP14_SHA256, KEX_GSS_GRP16_SHA512, KEX_GSS_NISTP256_SHA256 are permitted in FIPS mode

      Show
      AC1 manually check that patch fixing this issue is correctly applied and present in compose AC2 manually checked the compatibility with previous version: client with patched openssh version succesfully connect to the server running with previous openssh version AC3 GSS Kex using groups KEX_GSS_GRP14_SHA256, KEX_GSS_GRP16_SHA512, KEX_GSS_NISTP256_SHA256 are permitted in FIPS mode
    • Pass
    • Not Needed
    • New Test Coverage
    • Enhancement
    • GSS KEX is currently allowed in FIPS mode (DH group 14/16, ECDH)
    • Proposed
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      In FIPS mode we since 2014 forbid GSS key exchange on the code level. I see customer's request to relax this requirement and move it to crypto policies. We should consider it

              dbelyavs@redhat.com Dmitry Belyavskiy
              dbelyavs@redhat.com Dmitry Belyavskiy
              Dmitry Belyavskiy Dmitry Belyavskiy
              Miluse Bezo Konecna Miluse Bezo Konecna
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated: