-
Bug
-
Resolution: Done-Errata
-
Major
-
rhel-9.7
-
crypto-policies-20250602-1.gita839241.el9
-
No
-
Low
-
1
-
rhel-security-crypto
-
ssg_security
-
26
-
1.5
-
False
-
False
-
-
Yes
-
Crypto25August
-
-
Pass
-
Enabled
-
Automated
-
Feature
-
-
Done
-
Unspecified
-
Unspecified
-
Unspecified
-
None
RHEL-9 currently has ML-KEM / ML-DSA support in OpenSSL and ML-KEM support in NSS.
crypto-policies should add a PQ subpolicy for those willing to try these algorithms,
enabling, with the highest priority, higher-to-lower:
- hybrid ML-KEM for openssl: X25519-MLKEM768 P256-MLKEM768 P384-MLKEM1024
hybrid ML-KEM for nss:X25519-MLKEM768 P256-MLKEM768– {{3.101.0-10.el9 does not recognize the keywords yet}}- pure ML-DSA for openssl: MLDSA44 MLDSA65 MLDSA87
The subpolicy should apply without warnings.
- links to
-
RHBA-2025:150605
crypto-policies update