Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-89979

[rhel-10.1] Support OpenSSL provider API

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • ipa-4.12.2-19.el10
    • Important
    • rhel-sst-idm-ipa
    • rhel-sst-idm-ipa
    • ssg_idm
    • 12
    • 18
    • 3
    • QE ack, Dev ack
    • False
    • Hide

      None

      Show
      None
    • Yes
    • None
    • Fail
    • Automated
    • Unspecified Release Note Type - Unknown
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Goal

      • For RHEL 10+ we have to use OpenSSL provider API as OpenSSL engine API is deprecated. This concerns BIND loading of the SoftHSM token holding DNSSEC keys

      Acceptance criteria

      A list of verification conditions, successful functional tests, or expected outcomes in order to declare this story/task successfully completed.

      • Use OpenSSL provider with BIND for RHEL10.1
      • DNS: detect when OpenSSL engine should be removed on upgrade
      • ipa-dnskeysyncd: use systemd-tmpfiles to handle tokens
      • update BIND-related dependencies
      • Make IPAAbstractVersion available to all platforms

              abokovoy@redhat.com Alexander Bokovoy
              ftrivino@redhat.com Francisco Trivino Garcia
              Florence Renaud Florence Renaud
              Sudhir Menon Sudhir Menon
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: