When FIPS provider is in use, we forbid only some padding modes - spec

Resolves: rhbz#2053289
epel8
Dmitry Belyavskiy 2 years ago
parent 067b6b249b
commit 6ba0e5efa3

@ -15,7 +15,7 @@
Summary: Utilities from the general purpose cryptography library with TLS implementation Summary: Utilities from the general purpose cryptography library with TLS implementation
Name: openssl Name: openssl
Version: 3.0.1 Version: 3.0.1
Release: 24%{?dist} Release: 25%{?dist}
Epoch: 1 Epoch: 1
# We have to remove certain patented algorithms from the openssl source # We have to remove certain patented algorithms from the openssl source
# tarball with the hobble-openssl script which is included below. # tarball with the hobble-openssl script which is included below.
@ -94,6 +94,8 @@ Patch55: 0055-nonlegacy-fetch-null-deref.patch
Patch56: 0056-strcasecmp.patch Patch56: 0056-strcasecmp.patch
# https://github.com/openssl/openssl/pull/18175 # https://github.com/openssl/openssl/pull/18175
Patch57: 0057-strcasecmp-fix.patch Patch57: 0057-strcasecmp-fix.patch
# https://bugzilla.redhat.com/show_bug.cgi?id=2053289
Patch58: 0058-FIPS-limit-rsa-encrypt.patch
License: ASL 2.0 License: ASL 2.0
URL: http://www.openssl.org/ URL: http://www.openssl.org/
@ -424,6 +426,11 @@ install -m644 %{SOURCE9} \
%ldconfig_scriptlets libs %ldconfig_scriptlets libs
%changelog %changelog
* Mon May 02 2022 Dmitry Belyavskiy <dbelyavs@redhat.com> - 1:3.0.1-25
- FIPS provider should block RSA encryption for key transport.
- Other RSA encryption options should still be available
- Resolves: rhbz#2053289
* Thu Apr 28 2022 Clemens Lang <cllang@redhat.com> - 1:3.0.1-24 * Thu Apr 28 2022 Clemens Lang <cllang@redhat.com> - 1:3.0.1-24
- Fix regression in evp_pkey_name2type caused by tr_TR locale fix - Fix regression in evp_pkey_name2type caused by tr_TR locale fix
Resolves: rhbz#2071631 Resolves: rhbz#2071631

Loading…
Cancel
Save