Skip to content

fips package version for libgcrypt #128

Open
@jfaith0

Description

@jfaith0

on page https://github.com/cloudlinux/tuxcare-documentation/blob/master/docs/enterprise-support-for-almalinux/README.md
The following command is listed to install the libgcrypt library
dnf -y install gnutls-3.7.6-23.el9_2.tuxcare.3 nettle-3.8-3.el9_2.tuxcare.1 libgcrypt-1.10.0-10.el9_2.tuxcare.3 nss-3.90.0-6.el9_2.tuxcare.1

However at https://tuxcare.com/fips-for-almalinux/
The 'FIPS 140-3 Validated Packages for AlmaLinux 9.2' table at the bottom of the page lists
libgcrypt-1.10.0-11.el9_2.tuxcare.1

The 1.10.0-11 version is newer but the changelog is
Tue Nov 26 2024 Simon John [email protected] - 1.10.0-11

  • Synced to upstream plus ASN.1 patch
  • Tested on AlmaLinux 9.5
  • Fix CVE-2024-2236 (RHEL-34579)

I think the dnf command should be updated but the changelog refers to AlmaLinux9.5 so perhaps the table on the fips-for-almalinux page is wrong.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions