Actions
Feature #36325
openSupport setting key-algorithm for ISC DHCP
Status:
Ready For Testing
Priority:
Normal
Assignee:
Category:
DHCP
Target version:
-
Difficulty:
Triaged:
No
Bugzilla link:
Pull request:
Description
EL 8.2 introduced support for specifying key-algorithm in omshell (https://access.redhat.com/errata/RHBA-2021:1623) and Debian stable also supports this. If unspecified, it defaults to the insecure HMAC-MD5. Especially on FIPS (where MD5 is forbidden) this is problematic.
Actions