- Issued:
- 2025-11-11
- Updated:
- 2025-11-11
RHBA-2025:20115 - Bug Fix Advisory
Synopsis
crypto-policies bug fix and enhancement update
Type/Severity
Bug Fix Advisory
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for crypto-policies is now available for Red Hat Enterprise Linux 10.
Description
For detailed information on changes in this release, see the Red Hat Enterprise Linux 10 Release Notes linked from the References section.
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
Affected Products
- Red Hat Enterprise Linux for x86_64 10 x86_64
- Red Hat Enterprise Linux for IBM z Systems 10 s390x
- Red Hat Enterprise Linux for Power, little endian 10 ppc64le
- Red Hat Enterprise Linux for ARM 64 10 aarch64
Fixes
- RHEL-86250 - crypto-policies FTBFS
- RHEL-59104 - Exclude integrity-only TLS 1.3 by CP
- RHEL-86059 - Enable PQ crypto in DEFAULT crypto policy
- RHEL-81979 - gnutls now supports P384-MLKEM1024
- RHEL-92148 - Enable PQC algorithms in FIPS mode
- RHEL-101123 - Enable support for ML-DSA in GnuTLS
- RHEL-97763 - *P:Q/*class:ics - use new openssl group selection syntax in crypto-policies
- RHEL-98732 - Update crypto policies to support PQC in sequoia
- RHEL-99813 - X25519-MLKEM768 should be aliased to MLKEM768-X25519
- RHEL-103962 - enable ML-DSA in NSS in crypto-policies
- RHEL-106868 - Enable the mlkem1024secp384r1 group for NSS
- RHEL-111245 - rpm --import mldsa87.pub fails in FIPS (crypto-policies)
- RHEL-112392 - allow PQ algorithms in all rpm-sequoia crypto-policies
- RHEL-113008 - crypto-policies in RHEL 10.1 should obsolete crypto-policies-pq-preview
CVEs
(none)
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 10
| SRPM | |
|---|---|
| crypto-policies-20250905-2.gitc7eb7b2.el10_1.src.rpm | SHA-256: f041ed8b2cbb8ebbd5781ec939251a7f04ffcd665da6a14dff8a73b2384189ac |
| x86_64 | |
| crypto-policies-20250905-2.gitc7eb7b2.el10_1.noarch.rpm | SHA-256: f12aa1c07ddbc7f6a10dbfcc890738574de55bfd95e5d0b21ac310d53e19f3e6 |
| crypto-policies-scripts-20250905-2.gitc7eb7b2.el10_1.noarch.rpm | SHA-256: 8ae36c56bb660172bf2168ddf9e4b1091b396e4584cdb071bd0af1bdf94b520e |
Red Hat Enterprise Linux for IBM z Systems 10
| SRPM | |
|---|---|
| crypto-policies-20250905-2.gitc7eb7b2.el10_1.src.rpm | SHA-256: f041ed8b2cbb8ebbd5781ec939251a7f04ffcd665da6a14dff8a73b2384189ac |
| s390x | |
| crypto-policies-20250905-2.gitc7eb7b2.el10_1.noarch.rpm | SHA-256: f12aa1c07ddbc7f6a10dbfcc890738574de55bfd95e5d0b21ac310d53e19f3e6 |
| crypto-policies-scripts-20250905-2.gitc7eb7b2.el10_1.noarch.rpm | SHA-256: 8ae36c56bb660172bf2168ddf9e4b1091b396e4584cdb071bd0af1bdf94b520e |
Red Hat Enterprise Linux for Power, little endian 10
| SRPM | |
|---|---|
| crypto-policies-20250905-2.gitc7eb7b2.el10_1.src.rpm | SHA-256: f041ed8b2cbb8ebbd5781ec939251a7f04ffcd665da6a14dff8a73b2384189ac |
| ppc64le | |
| crypto-policies-20250905-2.gitc7eb7b2.el10_1.noarch.rpm | SHA-256: f12aa1c07ddbc7f6a10dbfcc890738574de55bfd95e5d0b21ac310d53e19f3e6 |
| crypto-policies-scripts-20250905-2.gitc7eb7b2.el10_1.noarch.rpm | SHA-256: 8ae36c56bb660172bf2168ddf9e4b1091b396e4584cdb071bd0af1bdf94b520e |
Red Hat Enterprise Linux for ARM 64 10
| SRPM | |
|---|---|
| crypto-policies-20250905-2.gitc7eb7b2.el10_1.src.rpm | SHA-256: f041ed8b2cbb8ebbd5781ec939251a7f04ffcd665da6a14dff8a73b2384189ac |
| aarch64 | |
| crypto-policies-20250905-2.gitc7eb7b2.el10_1.noarch.rpm | SHA-256: f12aa1c07ddbc7f6a10dbfcc890738574de55bfd95e5d0b21ac310d53e19f3e6 |
| crypto-policies-scripts-20250905-2.gitc7eb7b2.el10_1.noarch.rpm | SHA-256: 8ae36c56bb660172bf2168ddf9e4b1091b396e4584cdb071bd0af1bdf94b520e |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.