crypto-policies

Edit Package crypto-policies
No description set
Refresh
Refresh
Source Files
Filename Size Changed
README.SUSE 0000000171 171 Bytes
_service 0000000560 560 Bytes
_servicedata 0000000257 257 Bytes
crypto-policies-FIPS.patch 0000006181 6.04 KB
crypto-policies-no-build-manpages.patch 0000001278 1.25 KB
crypto-policies-nss.patch 0000002002 1.96 KB
crypto-policies-policygenerators.patch 0000001521 1.49 KB
crypto-policies-pylint.patch 0000000595 595 Bytes
crypto-policies-revert-rh-allow-sha1-signatures.patch 0000017009 16.6 KB
crypto-policies-rpmlintrc 0000000098 98 Bytes
crypto-policies-supported.patch 0000001371 1.34 KB
crypto-policies.7.gz 0000007322 7.15 KB
crypto-policies.changes 0000014409 14.1 KB
crypto-policies.spec 0000011432 11.2 KB
fedora-crypto-policies-20230920.570ea89.tar.gz 0000090127 88 KB
fips-finish-install.8.gz 0000000950 950 Bytes
fips-mode-setup.8.gz 0000001783 1.74 KB
update-crypto-policies.8.gz 0000004154 4.06 KB
Latest Revision
Marcus Rueckert's avatar Marcus Rueckert (darix) committed (revision 2)
- nss: Skip the NSS policy check if the mozilla-nss-tools package
  is not installed. This avoids adding more dependencies in ring0.
  * Add crypto-policies-nss.patch [bsc#1211301]

- Update to version 20230920.570ea89:
  * fips-mode-setup: more thorough --disable, still unsupported
  * FIPS:OSPP: tighten beyond reason for OSPP 4.3
  * krb5: sort enctypes mac-first, cipher-second, prioritize SHA-2 ones
  * openssl: implement relaxing EMS in FIPS (NO-ENFORCE-EMS)
  * gnutls: prepare for tls-session-hash option coming
  * nss: prepare for TLS-REQUIRE-EMS option coming
  * NO-ENFORCE-EMS: add subpolicy
  * FIPS: set __ems = ENFORCE
  * cryptopolicies: add enums and __ems tri-state
  * docs: replace `FIPS 140-2` with just `FIPS 140`
  * .gitlab-ci: remove forcing OPENSSH_MIN_RSA_SIZE
  * cryptopolicies: add comments on dunder options
  * nss: retire NSS_OLD and replace with NSS_LAX 3.80 check
  * BSI: start a BSI TR 02102 policy [jsc#PED-4933]
  * Rebase patches:
    - crypto-policies-policygenerators.patch
    - crypto-policies-revert-rh-allow-sha1-signatures.patch
    - crypto-policies-FIPS.patch

- Conditionally recommend the crypto-policies-scripts package
  when python is not installed in the system [bsc#1215201]

- Tests: Fix pylint versioning for TW and fix the parsing of the
  policygenerators to account for the commented lines correctly.
  * Add crypto-policies-pylint.patch
Comments 0
openSUSE Build Service is sponsored by