Skip to content

fips package version for libgcrypt #128

@jfaith0

Description

@jfaith0

on page https://github.com/cloudlinux/tuxcare-documentation/blob/master/docs/enterprise-support-for-almalinux/README.md
The following command is listed to install the libgcrypt library
dnf -y install gnutls-3.7.6-23.el9_2.tuxcare.3 nettle-3.8-3.el9_2.tuxcare.1 libgcrypt-1.10.0-10.el9_2.tuxcare.3 nss-3.90.0-6.el9_2.tuxcare.1

However at https://tuxcare.com/fips-for-almalinux/
The 'FIPS 140-3 Validated Packages for AlmaLinux 9.2' table at the bottom of the page lists
libgcrypt-1.10.0-11.el9_2.tuxcare.1

The 1.10.0-11 version is newer but the changelog is
Tue Nov 26 2024 Simon John sjohn@tuxcare.com - 1.10.0-11

  • Synced to upstream plus ASN.1 patch
  • Tested on AlmaLinux 9.5
  • Fix CVE-2024-2236 (RHEL-34579)

I think the dnf command should be updated but the changelog refers to AlmaLinux9.5 so perhaps the table on the fips-for-almalinux page is wrong.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions