CryptoPolicies: crypto-team -> fesco for exception approvals #1555

Merged
ngompa merged 1 commit from :main into main 2026-07-12 15:07:12 +00:00
Owner

see discussion and decision in
https://forge.fedoraproject.org/fesco/tickets/issues/3624#issuecomment-1060843

Note that with FESCo approval now needed, I dropped the separate step for FPC approval, since having both seems superfluous. If this is not desirable, I can drop this change from this PR.

see discussion and decision in <https://forge.fedoraproject.org/fesco/tickets/issues/3624#issuecomment-1060843> Note that with FESCo approval now needed, I dropped the separate step for FPC approval, since having both seems superfluous. If this is not desirable, I can drop this change from this PR.
Owner

+1

+1
Owner

We should probably have a statement that exceptions need to be documented with the FPC?

We should probably have a statement that exceptions need to be documented with the FPC?
Owner

+1

+1
Author
Owner

@ngompa wrote in #1555 (comment):

We should probably have a statement that exceptions need to be documented with the FPC?

Where? A new (for now, empty?) section at the bottom of https://docs.fedoraproject.org/en-US/packaging-guidelines/CryptoPolicies/?

@ngompa wrote in https://forge.fedoraproject.org/packaging/guidelines/pulls/1555#issuecomment-1060879: > We should probably have a statement that exceptions need to be documented with the FPC? Where? A new (for now, empty?) section at the bottom of <https://docs.fedoraproject.org/en-US/packaging-guidelines/CryptoPolicies/>?
Owner

Yes, I think that makes sense.

Yes, I think that makes sense.
Owner

crypto-policies(7) currently lists

   •   Go-language applications do not yet follow the system-wide policy.

   •   GnuPG-2 application does not follow the system-wide policy.

as exceptions. Do we want to list those in this new section in the Packaging Guidelines also?

`crypto-policies(7)` currently lists • Go-language applications do not yet follow the system-wide policy. • GnuPG-2 application does not follow the system-wide policy. as exceptions. Do we want to list those in this new section in the Packaging Guidelines also?
Owner

We probably should, since those are currently active exceptions. I didn't even know that was true, especially since Fedora's Go compiler forces the use of OpenSSL-based crypto by default.

We probably should, since those are currently active exceptions. I didn't even know that was true, especially since Fedora's Go compiler forces the use of OpenSSL-based crypto by default.
Owner

AFAIK go uses openssl for FIPS mode on RHEL via a set of downstream patches, but I'm not sure Fedora's version ever does.

AFAIK go uses openssl for FIPS mode on RHEL via a set of downstream patches, but I'm not sure Fedora's version ever does.
ngompa approved these changes 2026-07-12 15:06:41 +00:00
ngompa merged commit 1a52b036d5 into main 2026-07-12 15:07:12 +00:00
Author
Owner

I added a (currently empty) set of approved exceptions to my PR.

If we want to add any exemptions to that list, I would prefer to verify that they are actually exempt and add them to documentation independently of this PR.

I added a (currently empty) set of approved exceptions to my PR. If we want to add any exemptions to that list, I would prefer to verify that they are actually exempt and add them to documentation independently of this PR.
Owner

Works for me!

Works for me!
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
4 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
packaging/guidelines!1555
No description provided.