ComplianceAsCode / ComplianceAsCode/content

crypto policy: NO-SHA1 is not needed for EL9

Open
#13,017 0 comments 0 reactions 0 assignees View on GitHub
enhancement triaged
Dominant language
Shell
Stars
2.8k
Forks
828
Avg merge
3d 8m
Merged PRs (30d)
80

Description

#### Share the context

EL 9 (RHEL / Alma / ...) DEFAULT crypto policy only uses SHA1 for HMAC where safe
https://access.redhat.com/articles/6846411
https://gitlab.com/redhat-crypto/fedora-crypto-policies/-/blob/rhel9/policies/DEFAULT.pol
https://gitlab.com/redhat-crypto/fedora-crypto-policies/-/blob/rhel9/policies/modules/NO-SHA1.pmod

#### Description of problem:

we direct users to use ` DEFAULT:NO-SHA1` but it's not needed

#### Proposed change:

Do not fail checks when user is using `DEFAULT`
`DEFAULT:NO-SHA1` doesn't change anything compared to `DEFAULT` on EL 9

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.