On Fri, 24 Jul 2026 at 13:20, Milan Broz <[email protected]> wrote:
>
> On 7/24/26 12:15 PM, Peter Robinson wrote:
> >
> > Can you provide details of where they are used in Fedora? I believe
> > these would only be used if a user when out of their way to use those,
> > generally via a manual install process.
>
> What kind of argument is that?
>
> Fedora was presented as a community OS, providing services to its users.
> It is not an embedded system living with one specific, limited set of software
> with default configurations.

It's also a OS that uses the upstream kernel without patching it. Is
it a good service to those users when the upstream kernel yanks it
without warning, with out the distro providing a service of warning
those users so they have time to work out what other options they
have.

> There are a lot of users who rely on VeraCrypt containers, and many of them
> use chained ciphers (AES/Serpent/Twofish).
> All of these will now stop working with cryptsetup built against the OpenSSL 
> backend.

Will stop working for those particular cipher configurations that
aren't supported by openssl, at least this change proposal at least
advertises they're going away so they have time to prepare a migration
to other options. This change is about advertising changes for
awareness. It's no different than the deprecation of openssl engines
in that regard.

> Yes, you can install VeraCrypt itself, which does not use a crypto library 
> butconfiguration options, other options will
> implements the algorithms internally.
>
> And yes, these ciphers and modes should be implemented in OpenSSL - even 
> external
> providers could do it. But that will not happen overnight.

And this change isn't completely removing it overnight, it's very much
about advertising the fact they're going away and reducing the
exposure so we can work out exactly what the impact is before it's
removed entirely from the upstream kernel where it won't be patched
back in.

> Cryptsetup can also switch to libgcrypt, which already implements them.
> It is only a configuration option. I am sure the security team at Red Hat
> would appreciate that (sorry for the sarcasm, I couldn't resist).

I'm sure the security team at Red Hat will be looking at what they
have to implement for RHEL-11 so I'm sure they're already looking, it
would be nice is they spoke up with their intentions. The security
team is used to rapid changes....
-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to