Uploaded image for project: 'Container Tools'
  1. Container Tools
  2. RUN-3239

Podman Security Enhancements for Post-Quantum Cryptography

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • None
    • None
    • PODMANPQC
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • To Do
    • rhel-container-tools
    • 0% To Do, 100% In Progress, 0% Done

      Summary: Implement foundational changes in Podman to support advanced cryptographic algorithms, specifically addressing future post-quantum cryptography (PQC) requirements for image integrity and security.

      Description:

      As the cryptographic landscape evolves and the threat of quantum computing becomes more tangible, it's crucial for container platforms like Podman to prepare for post-quantum cryptography (PQC) standards. This epic focuses on laying the groundwork for Podman to adopt and utilize PQC-resistant cryptographic algorithms for critical operations such as image hashing, signing, and verification.

      The goal is to ensure Podman remains secure and compliant with future cryptographic mandates, providing users with the ability to build, distribute, and run images with enhanced integrity and authenticity guarantees. This epic will encompass various stories and tasks, starting with fundamental changes to digest algorithms and potentially extending to broader PQC-compliant signing and verification mechanisms.

      Acceptance Criteria:

      • Podman has a clear path and initial implementation for supporting alternative and stronger digest algorithms for images.
      • Users can configure and utilize PQC-relevant digest algorithms for image operations.
      • The architecture allows for future expansion to PQC-compliant signing and verification methods.
      • Documentation clearly outlines the new cryptographic options and their implications.
      • Podman's security posture is demonstrably improved in anticipation of future cryptographic requirements.

              lmandvek Lokesh Mandvekar
              mheon@redhat.com Matt Heon
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: