-
Bug
-
Resolution: Unresolved
-
Normal
-
rhel-10.0
-
openssh-9.9p1-14.el10
-
No
-
Low
-
2
-
rhel-security-crypto-diamonds
-
ssg_security
-
10
-
1.5
-
False
-
False
-
-
Yes
-
Crypto25August, Crypto25September
-
-
Pass
-
Not Needed
-
New Test Coverage
-
Enhancement
-
GSS KEX is currently allowed in FIPS mode (DH group 14/16, ECDH)
-
Proposed
-
Unspecified
-
Unspecified
-
Unspecified
-
None
In FIPS mode we since 2014 forbid GSS key exchange on the code level. I see customer's request to relax this requirement and move it to crypto policies. We should consider it
- relates to
-
RHEL-99890 crypto-policies not properly handling GSSAPIKexAlgorithms in FIPS policy
-
- Closed
-
- links to
-
RHBA-2025:154134 openssh update