CryptoPolicies: crypto-team -> fesco for exception approvals #1555
No reviewers
Labels
No labels
announce
bootstrap
Closed As
accepted
Closed As
duplicate
Closed As
exceptionexpired
Closed As
fixed
Closed As
invalid
Closed As
nothingtodo
Closed As
permanentexception
Closed As
rejected
Closed As
temporaryexception
Closed As
wontfix
cmake
committee
draftneeded
hasdraft
meeting
meson
needinfo
Priority
In Committee
Priority
Needs Review
Priority
Waiting For Reporter
rust
writeup
No milestone
No project
No assignees
4 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
packaging/guidelines!1555
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch ":main"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
see discussion and decision in
https://forge.fedoraproject.org/fesco/tickets/issues/3624#issuecomment-1060843
Note that with FESCo approval now needed, I dropped the separate step for FPC approval, since having both seems superfluous. If this is not desirable, I can drop this change from this PR.
+1
We should probably have a statement that exceptions need to be documented with the FPC?
+1
@ngompa wrote in #1555 (comment):
Where? A new (for now, empty?) section at the bottom of https://docs.fedoraproject.org/en-US/packaging-guidelines/CryptoPolicies/?
Yes, I think that makes sense.
crypto-policies(7)currently listsas exceptions. Do we want to list those in this new section in the Packaging Guidelines also?
We probably should, since those are currently active exceptions. I didn't even know that was true, especially since Fedora's Go compiler forces the use of OpenSSL-based crypto by default.
AFAIK go uses openssl for FIPS mode on RHEL via a set of downstream patches, but I'm not sure Fedora's version ever does.
37e2c3e9ecto1a52b036d5I added a (currently empty) set of approved exceptions to my PR.
If we want to add any exemptions to that list, I would prefer to verify that they are actually exempt and add them to documentation independently of this PR.
Works for me!