Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 880121 - sys-auth/crypto-policies: new package to control systemwide crypto policies
Summary: sys-auth/crypto-policies: new package to control systemwide crypto policies
Status: CONFIRMED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 812794 880119
  Show dependency tree
 
Reported: 2022-11-07 04:53 UTC by Sam James
Modified: 2022-11-07 04:53 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-11-07 04:53:48 UTC
We've discussed adding hardened defaults to OpenSSL (bug 510798, bug 812794) and GnuTLS (bug 880119) in the past.

It turns out Fedora has a great way of handling this *systemwide* with various plugins to generate appropriate configs. This is great for us as a distribution but it's also great for users to easily customise and be sure the new settings are being respected.

I think we may want to try it out (https://gitlab.com/redhat-crypto/fedora-crypto-policies), probably with a fork which we rebase regularly to allow us to introduce config divergences easily (even if we have none at first).

Note that this gives us way more coverage over things like OpenSSH too!