Repository navigation
OpenSSL::TestSSL#test_pqc_sigalg is not working with RHEL 9.7 #964
Description
Activity
/cc @junaruga
Thanks for the heads up. It seems RHEL 9.7 disables ML-DSA for TLS by default:
bash-5.1# cat /etc/crypto-policies/back-ends/opensslcnf.config CipherString = @SECLEVEL=2:kEECDH:kRSA:kEDH:kPSK:kDHEPSK:kECDHEPSK:kRSAPSK:-aDSS:-3DES:!DES:!RC4:!RC2:!IDEA:-SEED:!eNULL:!aNULL:!MD5:-SHA384:-CAMELLIA:-ARIA:-AESCCM8 Ciphersuites = TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256:TLS_AES_128_CCM_SHA256 TLS.MinProtocol = TLSv1.2 TLS.MaxProtocol = TLSv1.3 DTLS.MinProtocol = DTLSv1.2 DTLS.MaxProtocol = DTLSv1.2 SignatureAlgorithms = ECDSA+SHA256:ECDSA+SHA384:ECDSA+SHA512:ed25519:ed448:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_sha512:rsa_pss_rsae_sha256:rsa_pss_rsae_sha384:rsa_pss_rsae_sha512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA224:RSA+SHA224 Groups = *X25519:secp256r1:X448:secp521r1:secp384r1:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192
Thank you for the report, and also for working on this!
I will take a look at this issue after tomorrow!I investigated this issue.
Maybe we had RHEL 9.6 last time on RubyCI, the installed OpenSSL version was 3.2.2. The
test_pqc_sigalgwas skipped the OpenSSL version was less than 3.5.0. However,openssl/test/openssl/test_ssl.rb
Lines 2072 to 2074 in 0aad4f8
def test_pqc_sigalg # PQC algorithm ML-DSA (FIPS 204) is supported on OpenSSL 3.5 or later. return unless openssl?(3, 5, 0) However, the install OpenSSL version is 3.5.1 in RHEL 9.7. So, the test was executed.
RHEL 9.7 introduced the PQC support.
RHEL 9.7 crypto-policies supports post-quantum cryptography
With this update of the system-wide cryptographic policies, you can enable support for post-quantum cryptography (PQC) through the new PQ subpolicy.3.1.2. Post-quantum cryptography
The current status is below in RubyCI's RHEL 9.7.
$ update-crypto-policies --show DEFAULTWe need to change the crypto policy from DEFAULT to DEFAULT:PQ if we want to enable PQC in RHEL 9.7. But maybe we don't want to change the default crypto policy in RHEL 9.7 on RubyCI.
The instruction is on the following document.
# update-crypto-policies --set DEFAULT:PQ # rebootI think the commit fac3a26 is great. Because ML-DSA is used in PQC supported environment, as RSA (PQC-not-supported) is disabled.
Added the following content on 24th November 2025
Note that RHEL 10.1 OpenSSL enables PQC by default.
1.1. Major changes in RHEL 10.1
...
The system-wide cryptographic policies enable post-quantum cryptography (PQC) algorithms in all policies by default.
I udpate to RHEL 9.7 from 9.5 in last week.
OpenSSL::TestSSL#test_pqc_sigalgis failed after that.https://rubyci.s3.amazonaws.com/rhel9/ruby-master/log/20251117T003003Z.fail.html.gz