معرفی شرکت ها


crypto-policies-20211116-1.gitae470d6.el8.noarch.rpm


Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر

توضیحات

System-wide crypto policies
ویژگی مقدار
سیستم عامل Linux
توزیع CentOS 8-stream
مخزن Centos BaseOS noarch
نام بسته crypto-policies
نام فایل بسته crypto-policies-20211116-1.gitae470d6.el8.noarch.rpm
نسخه بسته 20211116
انتشار بسته 1.gitae470d6.el8
معماری بسته noarch
نگهدارنده -
تاریخ ساخت Wed Nov 24 08
هاست سازنده x86-02.mbox.centos.org
نوع بسته .rpm
آدرس صفحه اصلی https://gitlab.com/redhat-crypto/fedora-crypto-policies
مجوز LGPLv2+
حجم دانلود 64K
حجم نصب 71.542K
This package provides pre-built configuration files with cryptographic policies for various cryptographic back-ends, such as SSL/TLS libraries.


جایگزین ها



نیازمندی

مقدار نام
= 20211116-1.gitae470d6.el8 config(crypto-policies)


ارائه دهنده

مقدار نام
= 20211116-1.gitae470d6.el8 config(crypto-policies)
= 20211116-1.gitae470d6.el8 crypto-policies


نحوه نصب


نصب پکیج rpm crypto-policies:

    sudo dnf install crypto-policies-20211116-1.gitae470d6.el8.noarch.rpm


فایل ها

مسیرها
/etc/crypto-policies
/etc/crypto-policies/back-ends
/etc/crypto-policies/back-ends/bind.config
/etc/crypto-policies/back-ends/gnutls.config
/etc/crypto-policies/back-ends/java.config
/etc/crypto-policies/back-ends/krb5.config
/etc/crypto-policies/back-ends/libreswan.config
/etc/crypto-policies/back-ends/libssh.config
/etc/crypto-policies/back-ends/nss.config
/etc/crypto-policies/back-ends/openssh.config
/etc/crypto-policies/back-ends/opensshserver.config
/etc/crypto-policies/back-ends/openssl.config
/etc/crypto-policies/back-ends/opensslcnf.config
/etc/crypto-policies/config
/etc/crypto-policies/local.d
/etc/crypto-policies/policies
/etc/crypto-policies/policies/modules
/etc/crypto-policies/state
/etc/crypto-policies/state/CURRENT.pol
/etc/crypto-policies/state/current
/usr/share/crypto-policies
/usr/share/crypto-policies/DEFAULT
/usr/share/crypto-policies/DEFAULT/bind.txt
/usr/share/crypto-policies/DEFAULT/gnutls.txt
/usr/share/crypto-policies/DEFAULT/java.txt
/usr/share/crypto-policies/DEFAULT/krb5.txt
/usr/share/crypto-policies/DEFAULT/libreswan.txt
/usr/share/crypto-policies/DEFAULT/libssh.txt
/usr/share/crypto-policies/DEFAULT/nss.txt
/usr/share/crypto-policies/DEFAULT/openssh.txt
/usr/share/crypto-policies/DEFAULT/opensshserver.txt
/usr/share/crypto-policies/DEFAULT/openssl.txt
/usr/share/crypto-policies/DEFAULT/opensslcnf.txt
/usr/share/crypto-policies/EMPTY
/usr/share/crypto-policies/EMPTY/bind.txt
/usr/share/crypto-policies/EMPTY/gnutls.txt
/usr/share/crypto-policies/EMPTY/java.txt
/usr/share/crypto-policies/EMPTY/krb5.txt
/usr/share/crypto-policies/EMPTY/libreswan.txt
/usr/share/crypto-policies/EMPTY/libssh.txt
/usr/share/crypto-policies/EMPTY/nss.txt
/usr/share/crypto-policies/EMPTY/openssh.txt
/usr/share/crypto-policies/EMPTY/opensshserver.txt
/usr/share/crypto-policies/EMPTY/openssl.txt
/usr/share/crypto-policies/EMPTY/opensslcnf.txt
/usr/share/crypto-policies/FIPS
/usr/share/crypto-policies/FIPS/bind.txt
/usr/share/crypto-policies/FIPS/gnutls.txt
/usr/share/crypto-policies/FIPS/java.txt
/usr/share/crypto-policies/FIPS/krb5.txt
... and 97 more


گزارش تغییرات

تاریخ آخرین تغییر جزئیات
2021-11-16

fips-mode-setup, fips-finish-install: call zipl more often (s390x-specific)
libssh: enable diffie-hellman-group14-sha256 support
openssl: fix disabling ChaCha20

2021-06-17

implement scoped policies, e.g., cipher@SSH = ... (#1960266)
deprecate derived properties:
deprecate sha1_in_dnssec property
deprecate unscoped form of protocol property
update documentation
expand upstream test coverage
openssl: set MinProtocol / MaxProtocol separately for TLS and DTLS (#1946522)
support AES-192 ciphers in custom policies for non-TLS scenarios (#1876846)
stop claiming Camellia is disabled (#1925104)
disable CBC ciphers in FUTURE for everything but Kerberos (#1933016)
drop SHA224 from signature algorithms in FIPS:OSPP (#1934755)
condition ecdh-sha2-nistp384 on SECP384R1

2021-02-09

OSPP subpolicy: tweak for RHEL-8.3+
libssh: respect ssh_certs

2020-07-13

OSPP subpolicy: remove AES-CCM
openssl: handle the AES-CCM removal properly

2020-07-01

disallow X448/ED448 in FIPS policy with gnutls >= 3.6.12
add AD-SUPPORT policy module

2020-06-10

fallback to FIPS policy instead of the default-config in FIPS mode
java: Document properly how to override the crypto policy
krb5: No support for 3des anymore
reorder the signature algorithms to follow the order in default openssl list

2020-06-09

make the post script work in environments where /proc/sys is not available

2020-05-29

automatically set up FIPS policy in FIPS mode on first install

2020-05-28

explicitly enable DHE-DSS in gnutls config if enabled in policy
use grubby with --update-kernel=ALL to avoid breaking kernelopts
OSPP subpolicy: Allow GCM for SSH protocol
openssh: Support newly standardized ECDHE-GSS and DHE-GSS key exchanges
if the policy in FIPS mode is not a FIPS policy print a message
openssl: Add SignatureAlgorithms support
custom crypto policies: enable completely overriding contents of the list
added ECDHE-ONLY.pmod policy module example
openssh: make LEGACY policy to prefer strong public key algorithms
various python code cleanups
update-crypto-policies: dump the current policy to
policies/state/CURRENT.pol
split scripts into their own subpackage

2019-12-16

move the pre-built .config files to /usr/share/crypto-policies/back-ends

2019-11-29

fips-mode-setup: compatibility with RHCOS

2019-11-28

add FIPS subpolicy for OSPP

2019-10-29

custom crypto policies support
update-crypto-policies: fix handling of list operations in policy modules
update-crypto-policies: fix updating of the current policy marker
fips-mode-setup: fixes related to containers and non-root execution
make it possible to use fips-mode-setup --check without dracut
add .config symlinks so a crypto policy can be set with read-only
mounting /usr/share/crypto-policies/<policy> to
policies/back-ends
run the update-crypto-policies in posttrans

2019-08-07

gnutls: enable TLS-1.3 in the FIPS policy

2019-08-05

fix ownership of policy directories
nss: enable X25519 in appropriate policies and conflict with old nss
openssh: conflict with old incompatible openssh version

2019-06-13

openssh: add missing curve25519-sha256 to the key exchange list
openssh: fix RSA certificate support
fips-mode-setup: drop the kernel boot option if there is no separate
fips-finish-install: regenerate all initramdisks
add libssh configuration backend