Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-98732

Update crypto policies to support PQC in sequoia

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • crypto-policies-20250714-1.git95bf40e.el10
    • No
    • Low
    • 1
    • rhel-security-crypto
    • 21
    • 26
    • 0.5
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Crypto25August
    • Hide

      AC1) sequoia-policy-config from https://gitlab.com/sequoia-pgp/sequoia-policy-config/ validates the config

      AC2) FIPS policy enables none of the "mlkem768-x25519", "mlkem1024-x448", "mldsa65-ed25519" or "mldsa87-ed448" for both sequoia and rpm-sequoia configs, lists them under ignore_invalid

      AC3)All policies other than FIPS enable "mlkem768-x25519", "mlkem1024-x448", "mldsa65-ed25519" and "mldsa87-ed448" for both sequoia and rpm-sequoia configs, lists them under ignore_invalid

      Show
      AC1) sequoia-policy-config from https://gitlab.com/sequoia-pgp/sequoia-policy-config/ validates the config AC2) FIPS policy enables none of the "mlkem768-x25519", "mlkem1024-x448", "mldsa65-ed25519" or "mldsa87-ed448" for both sequoia and rpm-sequoia configs, lists them under ignore_invalid AC3)All policies other than FIPS enable "mlkem768-x25519", "mlkem1024-x448", "mldsa65-ed25519" and "mldsa87-ed448" for both sequoia and rpm-sequoia configs, lists them under ignore_invalid
    • Pass
    • Not Needed
    • Automated
    • Enhancement
    • Hide
      Feature, enhancement:
      Reason:
      Result:
      Show
      Feature, enhancement: Reason: Result:
    • Proposed
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      The sequoia follows crypto policies and without updating them, it will not be able to use the new PQ algorithms for signing, verification, encryption ...

      What is the impact of this issue to you?

      Inability to use PQC from sequoia tools and verify PQC signatures or RPMs.

      Please provide the package NVR for which the bug is seen:

      Tested with pre-release sequoia tools.

      How reproducible is this bug?:

      always

      Steps to reproduce

      1. Attempt to sign with sequoia using PQC

      Expected results

      Signature is performed

      Actual results

      Sequoia reports the PQC key is not signing capable.

      The change has already landed in upstream:

      https://gitlab.com/redhat-crypto/fedora-crypto-policies/-/merge_requests/251

              asosedki@redhat.com Alexander Sosedkin
              jjelen@redhat.com Jakub Jelen
              Alexander Sosedkin Alexander Sosedkin
              Ondrej Moris Ondrej Moris
              Mirek Jahoda Mirek Jahoda
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated: