Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

crypto-policies-20200527-4.gitb234a47.fc33 RPM for noarch

From Fedora Rawhide for ppc64le / c

Name: crypto-policies Distribution: Fedora Project
Version: 20200527 Vendor: Fedora Project
Release: 4.gitb234a47.fc33 Build date: Fri May 29 19:14:02 2020
Group: Unspecified Build host: buildhw-08.phx2.fedoraproject.org
Size: 87774 Source RPM: crypto-policies-20200527-4.gitb234a47.fc33.src.rpm
Packager: Fedora Project
Url: https://gitlab.com/redhat-crypto/fedora-crypto-policies
Summary: System-wide crypto policies
This package provides pre-built configuration files with
cryptographic policies for various cryptographic back-ends,
such as SSL/TLS libraries.

Provides

Requires

License

LGPLv2+

Changelog

* Fri May 29 2020 Tomáš Mráz <tmraz@redhat.com> - 20200527-4.gitb234a47
  - move the symlink fix-up script to post and fix it
* Fri May 29 2020 Tomáš Mráz <tmraz@redhat.com> - 20200527-3.gitb234a47
  - automatically set up FIPS policy in FIPS mode on first install
* Thu May 28 2020 Tomáš Mráz <tmraz@redhat.com> - 20200527-2.gitb234a47
  - require the base package from scripts subpackage
  - add Recommends for fips-mode-setup to the scripts subpackage
* Wed May 27 2020 Tomáš Mráz <tmraz@redhat.com> - 20200527-1.gitb234a47
  - explicitly enable DHE-DSS in gnutls config if enabled in policy
  - use grubby with --update-kernel=ALL to avoid breaking kernelopts
  - OSPP subpolicy: Allow GCM for SSH protocol
  - openssh: Support newly standardized ECDHE-GSS and DHE-GSS key exchanges
  - if the policy in FIPS mode is not a FIPS policy print a message
  - openssl: Add SignatureAlgorithms support
* Thu Mar 12 2020 Tomáš Mráz <tmraz@redhat.com> - 20200312-1.git3ae59d2
  - custom crypto policies: enable completely overriding contents of the list
    value
  - added ECDHE-ONLY.pmod policy module example
  - openssh: make LEGACY policy to prefer strong public key algorithms
  - openssh: support FIDO/U2F (with the exception of FIPS policy)
  - gnutls: add support for GOST ciphers
  - various python code cleanups
  - update-crypto-policies: dump the current policy to
    /etc/crypto-policies/state/CURRENT.pol
* Tue Jan 28 2020 Fedora Release Engineering <releng@fedoraproject.org> - 20191128-5.gitcd267a5
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Tue Jan 14 2020 Tomáš Mráz <tmraz@redhat.com> - 20191128-4.gitcd267a5
  - the base package must ship the DEFAULT policy config symlinks in case
    the scripts package is not installed via the weak dependency
* Tue Jan 07 2020 Andrew Jeddeloh <ajeddelo@redhat.com> 20191128-3.gitcd267a5
  - split scripts into their own subpackage. See
    https://github.com/coreos/fedora-coreos-tracker/issues/280 for more details.
* Mon Dec 16 2019 Tomáš Mráz <tmraz@redhat.com> - 20191128-2.gitcd267a5
  - move the pre-built .config files to /usr/share/crypto-policies/back-ends
* Thu Nov 28 2019 Tomáš Mráz <tmraz@redhat.com> - 20191128-1.gitcd267a5
  - add FIPS subpolicy for OSPP
  - fips-mode-setup: do not reload daemons when changing policy
  - fips-mode-setup: gracefully handle OSTree-based systems
  - gnutls: use new configuration file format
* Tue Oct 29 2019 Tomáš Mráz <tmraz@redhat.com> - 20191002-1.gitc93dc99
  - update-crypto-policies: fix handling of list operations in policy modules
  - update-crypto-policies: fix updating of the current policy marker
  - fips-mode-setup: fixes related to containers and non-root execution
* Tue Sep 24 2019 Tomáš Mráz <tmraz@redhat.com> - 20190816-4.gitbb9bf99
  - add the /etc/crypto-policies/state directory
* Tue Sep 10 2019 Tomáš Mráz <tmraz@redhat.com> - 20190816-3.gitbb9bf99
  - make it possible to use fips-mode-setup --check without dracut
  - add .config symlinks so a crypto policy can be set with read-only
    /etc by bind-mounting /usr/share/crypto-policies/<policy> to
    /etc/crypto-policies/back-ends
* Mon Aug 19 2019 Tomáš Mráz <tmraz@redhat.com> - 20190816-2.gitbb9bf99
  - run the update-crypto-policies in posttrans
  - the current config should work fine with OpenSSL >= 7.9p1
  - fix the python bytecompilation
* Fri Aug 16 2019 Tomáš Mráz <tmraz@redhat.com> - 20190816-1.gitbb9bf99
  - custom crypto policies support
  - openssh: Support new configuration option CASignatureAlgorithms
  - libssh: Add libssh as supported backend
  - multiple fixes in fips-mode-setup, BLS support
* Wed Jul 24 2019 Fedora Release Engineering <releng@fedoraproject.org> - 20190527-2.git0b3add8
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Mon May 27 2019 Tomáš Mráz <tmraz@redhat.com> - 20190211-1.git0b3add8
  - libreswan: coalesce proposals to avoid IKE packet fragmentation
  - openssh: add missing curve25519-sha256 to the key exchange list
  - nss: map X25519 to CURVE25519
* Thu Apr 25 2019 Tomáš Mráz <tmraz@redhat.com> - 20190211-4.gite3eacfc
  - do not fail in the Java test if the EMPTY policy is not really empty
* Thu Mar 07 2019 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 20190211-3.gite3eacfc
  - Split out fips-mode-setup into separate subpackage
* Mon Feb 11 2019 Tomáš Mráz <tmraz@redhat.com> - 20190211-2.gite3eacfc
  - add crypto-policies.7 manual page
  - Java: Fix FIPS and FUTURE policy to allow RSA certificates in TLS
  - cleanup duplicate and incorrect information from update-crypto-policies.8
    manual page
  - update-crypto-policies: Fix endless loop
  - update-crypto-policies: Add warning about the need of system restart
  - FUTURE: Add mistakenly ommitted EDDSA-ED25519 signature algorithm
  - openssh: Add missing SHA2 variants of RSA certificates to the policy
  - return exit code 2 when printing usage from all the tools
  - update-crypto-policies: add --no-reload option for testing
* Thu Jan 31 2019 Fedora Release Engineering <releng@fedoraproject.org> - 20181122-2.git70769d9
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Thu Nov 22 2018 Tomáš Mráz <tmraz@redhat.com> - 20181122-1.git70769d9
  - update-crypto-policies: fix error on multiple matches in local.d
* Tue Nov 20 2018 Tomáš Mráz <tmraz@redhat.com> - 20181120-1.gitd2b3bc4
  - Print warning when update-crypto-policies --set is used in the FIPS mode
  - Java: Add 3DES and RC4 to legacy algorithms in LEGACY policy
  - OpenSSL: Properly disable non AEAD and AES128 ciphersuites in FUTURE
  - libreswan: Add chacha20_poly1305 to all policies and drop ikev1 from LEGACY
* Fri Oct 26 2018 Tomáš Mráz <tmraz@redhat.com> - 20181026-1.gitd42aaa6
  - Fix regression in discovery of additional configuration
  - NSS: add DSA keyword to LEGACY policy
  - GnuTLS: Add 3DES and RC4 to LEGACY policy
* Tue Sep 25 2018 Tomáš Mráz <tmraz@redhat.com> - 20180925-1.git71ca85f
  - Use Recommends instead of Requires for grubby
  - Revert setting of HostKeyAlgorithms for ssh client for now
* Fri Sep 21 2018 Tomáš Mráz <tmraz@redhat.com> - 20180921-2.git391ed9f
  - Fix requires for grubby
* Fri Sep 21 2018 Tomáš Mráz <tmraz@redhat.com> - 20180921-1.git391ed9f
  - OpenSSH: Generate policy for sign algorithms
  - Enable >= 255 bits EC curves in FUTURE policy
  - OpenSSH: Add group1 key exchanges in LEGACY policy
  - NSS: Add SHA224 to hash lists
  - Print warning when update-crypto-policies --set FIPS is used
  - fips-mode-setup: Kernel boot options are now modified with grubby
* Thu Aug 02 2018 Tomáš Mráz <tmraz@redhat.com> - 20180802-1.git1626592
  - Introduce NEXT policy
* Mon Jul 30 2018 Tomáš Mráz <tmraz@redhat.com> - 20180730-1.git9d9f21d
  - Add OpenSSL configuration file include support
* Tue Jul 24 2018 Tomáš Mráz <tmraz@redhat.com> - 20180723-1.gitdb825c0
  - Initial FIPS mode setup support
  - NSS: Add tests for the generated policy
  - Enable TLS-1.3 if available in the respective TLS library
  - Enable SHA1 in certificates in LEGACY policy
  - Disable CAMELLIA
  - libreswan: Multiple bug fixes in policies
* Thu Jul 12 2018 Fedora Release Engineering <releng@fedoraproject.org> - 20180425-6.git6ad4018
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild

Files

/etc/crypto-policies
/etc/crypto-policies/back-ends
/etc/crypto-policies/back-ends/bind.config
/etc/crypto-policies/back-ends/gnutls.config
/etc/crypto-policies/back-ends/java.config
/etc/crypto-policies/back-ends/krb5.config
/etc/crypto-policies/back-ends/libreswan.config
/etc/crypto-policies/back-ends/libssh.config
/etc/crypto-policies/back-ends/nss.config
/etc/crypto-policies/back-ends/openssh.config
/etc/crypto-policies/back-ends/opensshserver.config
/etc/crypto-policies/back-ends/openssl.config
/etc/crypto-policies/back-ends/opensslcnf.config
/etc/crypto-policies/config
/etc/crypto-policies/local.d
/etc/crypto-policies/policies
/etc/crypto-policies/policies/modules
/etc/crypto-policies/state
/etc/crypto-policies/state/CURRENT.pol
/etc/crypto-policies/state/current
/usr/share/crypto-policies
/usr/share/crypto-policies/DEFAULT
/usr/share/crypto-policies/DEFAULT/bind.txt
/usr/share/crypto-policies/DEFAULT/gnutls.txt
/usr/share/crypto-policies/DEFAULT/java.txt
/usr/share/crypto-policies/DEFAULT/krb5.txt
/usr/share/crypto-policies/DEFAULT/libreswan.txt
/usr/share/crypto-policies/DEFAULT/libssh.txt
/usr/share/crypto-policies/DEFAULT/nss.txt
/usr/share/crypto-policies/DEFAULT/openssh.txt
/usr/share/crypto-policies/DEFAULT/opensshserver.txt
/usr/share/crypto-policies/DEFAULT/openssl.txt
/usr/share/crypto-policies/DEFAULT/opensslcnf.txt
/usr/share/crypto-policies/EMPTY
/usr/share/crypto-policies/EMPTY/bind.txt
/usr/share/crypto-policies/EMPTY/gnutls.txt
/usr/share/crypto-policies/EMPTY/java.txt
/usr/share/crypto-policies/EMPTY/krb5.txt
/usr/share/crypto-policies/EMPTY/libreswan.txt
/usr/share/crypto-policies/EMPTY/libssh.txt
/usr/share/crypto-policies/EMPTY/nss.txt
/usr/share/crypto-policies/EMPTY/openssh.txt
/usr/share/crypto-policies/EMPTY/opensshserver.txt
/usr/share/crypto-policies/EMPTY/openssl.txt
/usr/share/crypto-policies/EMPTY/opensslcnf.txt
/usr/share/crypto-policies/FIPS
/usr/share/crypto-policies/FIPS/bind.txt
/usr/share/crypto-policies/FIPS/gnutls.txt
/usr/share/crypto-policies/FIPS/java.txt
/usr/share/crypto-policies/FIPS/krb5.txt
/usr/share/crypto-policies/FIPS/libreswan.txt
/usr/share/crypto-policies/FIPS/libssh.txt
/usr/share/crypto-policies/FIPS/nss.txt
/usr/share/crypto-policies/FIPS/openssh.txt
/usr/share/crypto-policies/FIPS/opensshserver.txt
/usr/share/crypto-policies/FIPS/openssl.txt
/usr/share/crypto-policies/FIPS/opensslcnf.txt
/usr/share/crypto-policies/FUTURE
/usr/share/crypto-policies/FUTURE/bind.txt
/usr/share/crypto-policies/FUTURE/gnutls.txt
/usr/share/crypto-policies/FUTURE/java.txt
/usr/share/crypto-policies/FUTURE/krb5.txt
/usr/share/crypto-policies/FUTURE/libreswan.txt
/usr/share/crypto-policies/FUTURE/libssh.txt
/usr/share/crypto-policies/FUTURE/nss.txt
/usr/share/crypto-policies/FUTURE/openssh.txt
/usr/share/crypto-policies/FUTURE/opensshserver.txt
/usr/share/crypto-policies/FUTURE/openssl.txt
/usr/share/crypto-policies/FUTURE/opensslcnf.txt
/usr/share/crypto-policies/LEGACY
/usr/share/crypto-policies/LEGACY/bind.txt
/usr/share/crypto-policies/LEGACY/gnutls.txt
/usr/share/crypto-policies/LEGACY/java.txt
/usr/share/crypto-policies/LEGACY/krb5.txt
/usr/share/crypto-policies/LEGACY/libreswan.txt
/usr/share/crypto-policies/LEGACY/libssh.txt
/usr/share/crypto-policies/LEGACY/nss.txt
/usr/share/crypto-policies/LEGACY/openssh.txt
/usr/share/crypto-policies/LEGACY/opensshserver.txt
/usr/share/crypto-policies/LEGACY/openssl.txt
/usr/share/crypto-policies/LEGACY/opensslcnf.txt
/usr/share/crypto-policies/NEXT
/usr/share/crypto-policies/NEXT/bind.txt
/usr/share/crypto-policies/NEXT/gnutls.txt
/usr/share/crypto-policies/NEXT/java.txt
/usr/share/crypto-policies/NEXT/krb5.txt
/usr/share/crypto-policies/NEXT/libreswan.txt
/usr/share/crypto-policies/NEXT/libssh.txt
/usr/share/crypto-policies/NEXT/nss.txt
/usr/share/crypto-policies/NEXT/openssh.txt
/usr/share/crypto-policies/NEXT/opensshserver.txt
/usr/share/crypto-policies/NEXT/openssl.txt
/usr/share/crypto-policies/NEXT/opensslcnf.txt
/usr/share/crypto-policies/back-ends
/usr/share/crypto-policies/back-ends/DEFAULT
/usr/share/crypto-policies/back-ends/DEFAULT/bind.config
/usr/share/crypto-policies/back-ends/DEFAULT/gnutls.config
/usr/share/crypto-policies/back-ends/DEFAULT/java.config
/usr/share/crypto-policies/back-ends/DEFAULT/krb5.config
/usr/share/crypto-policies/back-ends/DEFAULT/libreswan.config
/usr/share/crypto-policies/back-ends/DEFAULT/libssh.config
/usr/share/crypto-policies/back-ends/DEFAULT/nss.config
/usr/share/crypto-policies/back-ends/DEFAULT/openssh.config
/usr/share/crypto-policies/back-ends/DEFAULT/opensshserver.config
/usr/share/crypto-policies/back-ends/DEFAULT/openssl.config
/usr/share/crypto-policies/back-ends/DEFAULT/opensslcnf.config
/usr/share/crypto-policies/back-ends/FIPS
/usr/share/crypto-policies/back-ends/FIPS/bind.config
/usr/share/crypto-policies/back-ends/FIPS/gnutls.config
/usr/share/crypto-policies/back-ends/FIPS/java.config
/usr/share/crypto-policies/back-ends/FIPS/krb5.config
/usr/share/crypto-policies/back-ends/FIPS/libreswan.config
/usr/share/crypto-policies/back-ends/FIPS/libssh.config
/usr/share/crypto-policies/back-ends/FIPS/nss.config
/usr/share/crypto-policies/back-ends/FIPS/openssh.config
/usr/share/crypto-policies/back-ends/FIPS/opensshserver.config
/usr/share/crypto-policies/back-ends/FIPS/openssl.config
/usr/share/crypto-policies/back-ends/FIPS/opensslcnf.config
/usr/share/crypto-policies/back-ends/FUTURE
/usr/share/crypto-policies/back-ends/FUTURE/bind.config
/usr/share/crypto-policies/back-ends/FUTURE/gnutls.config
/usr/share/crypto-policies/back-ends/FUTURE/java.config
/usr/share/crypto-policies/back-ends/FUTURE/krb5.config
/usr/share/crypto-policies/back-ends/FUTURE/libreswan.config
/usr/share/crypto-policies/back-ends/FUTURE/libssh.config
/usr/share/crypto-policies/back-ends/FUTURE/nss.config
/usr/share/crypto-policies/back-ends/FUTURE/openssh.config
/usr/share/crypto-policies/back-ends/FUTURE/opensshserver.config
/usr/share/crypto-policies/back-ends/FUTURE/openssl.config
/usr/share/crypto-policies/back-ends/FUTURE/opensslcnf.config
/usr/share/crypto-policies/back-ends/LEGACY
/usr/share/crypto-policies/back-ends/LEGACY/bind.config
/usr/share/crypto-policies/back-ends/LEGACY/gnutls.config
/usr/share/crypto-policies/back-ends/LEGACY/java.config
/usr/share/crypto-policies/back-ends/LEGACY/krb5.config
/usr/share/crypto-policies/back-ends/LEGACY/libreswan.config
/usr/share/crypto-policies/back-ends/LEGACY/libssh.config
/usr/share/crypto-policies/back-ends/LEGACY/nss.config
/usr/share/crypto-policies/back-ends/LEGACY/openssh.config
/usr/share/crypto-policies/back-ends/LEGACY/opensshserver.config
/usr/share/crypto-policies/back-ends/LEGACY/openssl.config
/usr/share/crypto-policies/back-ends/LEGACY/opensslcnf.config
/usr/share/crypto-policies/back-ends/NEXT
/usr/share/crypto-policies/back-ends/NEXT/bind.config
/usr/share/crypto-policies/back-ends/NEXT/gnutls.config
/usr/share/crypto-policies/back-ends/NEXT/java.config
/usr/share/crypto-policies/back-ends/NEXT/krb5.config
/usr/share/crypto-policies/back-ends/NEXT/libreswan.config
/usr/share/crypto-policies/back-ends/NEXT/libssh.config
/usr/share/crypto-policies/back-ends/NEXT/nss.config
/usr/share/crypto-policies/back-ends/NEXT/openssh.config
/usr/share/crypto-policies/back-ends/NEXT/opensshserver.config
/usr/share/crypto-policies/back-ends/NEXT/openssl.config
/usr/share/crypto-policies/back-ends/NEXT/opensslcnf.config
/usr/share/crypto-policies/default-config
/usr/share/crypto-policies/policies
/usr/share/crypto-policies/policies/DEFAULT.pol
/usr/share/crypto-policies/policies/EMPTY.pol
/usr/share/crypto-policies/policies/FIPS.pol
/usr/share/crypto-policies/policies/FUTURE.pol
/usr/share/crypto-policies/policies/LEGACY.pol
/usr/share/crypto-policies/policies/NEXT.pol
/usr/share/crypto-policies/policies/modules
/usr/share/crypto-policies/policies/modules/ECDHE-ONLY.pmod
/usr/share/crypto-policies/policies/modules/GOST.pmod
/usr/share/crypto-policies/policies/modules/NO-CAMELLIA.pmod
/usr/share/crypto-policies/policies/modules/NO-SHA1.pmod
/usr/share/crypto-policies/policies/modules/OSPP.pmod
/usr/share/crypto-policies/reload-cmds.sh
/usr/share/licenses/crypto-policies
/usr/share/licenses/crypto-policies/COPYING.LESSER
/usr/share/man/man7/crypto-policies.7.gz


Generated by rpm2html 1.8.1

Fabrice Bellet, Wed Jun 10 00:14:28 2020