Uploaded image for project: 'Satellite'
  1. Satellite
  2. SAT-36257

Support Post-Quantum Cryptography certificates

XMLWordPrintable

    • Icon: Feature Feature
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • Installation
    • None
    • False
    • sat-rocket
    • None
    • None
    • None

      For RHEL 10.1 the crypto-policy will by default support PQC, RHEL 9.7 users can opt into PQC by switching to the DEFAULT:PQ policy.

      After supporting PQC key exchanges (SAT-36256) the second phase is support PQC certificates. Supporting ML-DSA certificates besides RSA will require changes throughout the stack.

      Apache needs to be configured with another pair of SSLCertificateFile and SSLCertificateKeyFile statements to serve both RSA and ML-DSA certificates. Candlepin will also need support and a lot of software needs to be verified. For example, Foreman receives the client certificate to extract some data. Will that continue to work?

              Unassigned Unassigned
              ekohlvan@redhat.com Ewoud Kohl van Wijngaarden
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: