8
0
Files
crypto-policies/_service
Pedro Monreal Gonzalez a82b210eff Accepting request 1245664 from home:pmonrealgonzalez:branches:security:tls
- Remove dangling symlink for the libreswan config [bsc#1236858]
- Remove also sequoia config and generator files

- Update to version 20250124.4d262e7:
  * openssl: stricter enabling of Ciphersuites
  * openssl: make use of -CBC and -AESGCM keywords
  * openssl: add TLS 1.3 Brainpool identifiers
  * fix warning on using experimental key_exchanges
  * update-crypto-policies: don't output FIPS warning in fips mode
  * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256
  * openssh, libssh: refactor kx maps to use tuples
  * alg_lists: mark MLKEM768/SNTRUP kex experimental
  * nss: revert enabling mlkem768secp256r1
  * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber
  * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768
  * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768
  * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768
  * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256
  * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384...
  * python/update-crypto-policies: pacify pylint
  * fips-mode-setup: tolerate fips dracut module presence w/o FIPS
  * fips-mode-setup: small Argon2 detection fix
  * SHA1: add __openssl_block_sha1_signatures = 0
  * fips-mode-setup: block if LUKS devices using Argon2 are detected
  * update-crypto-policies: skip warning on --set=FIPS if bootc
  * fips-setup-helper: skip warning, BTW
  * fips-mode-setup: force --no-bootcfg when UKI is detected
  * fips-setup-helper: add a libexec helper for anaconda
  * fips-crypto-policy-overlay: automount FIPS policy
  * openssh: make dss no longer enableble, support is dropped

OBS-URL: https://build.opensuse.org/request/show/1245664
OBS-URL: https://build.opensuse.org/package/show/security:tls/crypto-policies?expand=0&rev=32
2025-02-13 14:07:46 +00:00

15 lines
560 B
Plaintext

<services>
<service name="tar_scm" mode="disabled">
<param name="url">https://gitlab.com/redhat-crypto/fedora-crypto-policies.git</param>
<param name="scm">git</param>
<param name="versionformat">%cd.%h</param>
<param name="changesgenerate">enable</param>
<param name="revision">4d262e79be1cd15c84cad55ad88c53a2d7712e85</param>
</service>
<service name="recompress" mode="disabled">
<param name="file">*.tar</param>
<param name="compression">gz</param>
</service>
<service name="set_version" mode="disabled"/>
</services>