On Fri, 24 Jul 2026 at 13:20, Milan Broz <[email protected]> wrote: > > On 7/24/26 12:15 PM, Peter Robinson wrote: > > > > Can you provide details of where they are used in Fedora? I believe > > these would only be used if a user when out of their way to use those, > > generally via a manual install process. > > What kind of argument is that? > > Fedora was presented as a community OS, providing services to its users. > It is not an embedded system living with one specific, limited set of software > with default configurations.
It's also a OS that uses the upstream kernel without patching it. Is it a good service to those users when the upstream kernel yanks it without warning, with out the distro providing a service of warning those users so they have time to work out what other options they have. > There are a lot of users who rely on VeraCrypt containers, and many of them > use chained ciphers (AES/Serpent/Twofish). > All of these will now stop working with cryptsetup built against the OpenSSL > backend. Will stop working for those particular cipher configurations that aren't supported by openssl, at least this change proposal at least advertises they're going away so they have time to prepare a migration to other options. This change is about advertising changes for awareness. It's no different than the deprecation of openssl engines in that regard. > Yes, you can install VeraCrypt itself, which does not use a crypto library > butconfiguration options, other options will > implements the algorithms internally. > > And yes, these ciphers and modes should be implemented in OpenSSL - even > external > providers could do it. But that will not happen overnight. And this change isn't completely removing it overnight, it's very much about advertising the fact they're going away and reducing the exposure so we can work out exactly what the impact is before it's removed entirely from the upstream kernel where it won't be patched back in. > Cryptsetup can also switch to libgcrypt, which already implements them. > It is only a configuration option. I am sure the security team at Red Hat > would appreciate that (sorry for the sarcasm, I couldn't resist). I'm sure the security team at Red Hat will be looking at what they have to implement for RHEL-11 so I'm sure they're already looking, it would be nice is they spoke up with their intentions. The security team is used to rapid changes.... -- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
