* Fri Sep 05 2025 Alexander Sosedkin <asosedkin@redhat.com> - 20250905-1.git377cc42.inferit.1
- Fix patch
* Fri Sep 05 2025 Alexander Sosedkin <asosedkin@redhat.com> - 20250905-1.git377cc42
- rpm-sequoia: enable MLDSA65-ED25519 and MLDSA87-ED448 in all policies
- rpm-sequoia: enable SHA-1 in all policies
- rpm-sequoia: force enable all PQ algorithms for now
* Mon Aug 04 2025 Alexander Sosedkin <asosedkin@redhat.com> - 20250804-1.git2c74f3d
- nss: enable ML-KEM and ML-DSA
* Mon Jul 21 2025 Alexander Sosedkin <asosedkin@redhat.com> - 20250721-1.git162e4cb
- rpm-sequoia: add back-end
- openssl: send one PQ and one classic key_share; prioritize PQ groups
- policies: alias X25519-MLKEM768 to MLKEM768-X25519
- nss: enable ED25519
* Mon Jun 02 2025 Alexander Sosedkin <asosedkin@redhat.com> - 20250602-1.gita839241
- openssl: fix mistakes in integrity-only cipher definitions
- PQ: add a subpolicy with some post-quantum algorithms
* Tue Jan 28 2025 Alexander Sosedkin <asosedkin@redhat.com> - 20250128-1.git5269e22
- openssl: stricter enabling of Ciphersuites
- openssl: make use of -CBC and -AESGCM keywords
* Tue Sep 17 2024 Alexander Sosedkin <asosedkin@redhat.com> - 20240828-2.git626aa59
- release bump
* Wed Aug 28 2024 Alexander Sosedkin <asosedkin@redhat.com> - 20240828-1.git626aa59
- fips-mode-setup: small Argon2 detection fix
* Thu Aug 22 2024 Alexander Sosedkin <asosedkin@redhat.com> - 20240822-1.gitbaf3e06
- fips-mode-setup: block if LUKS devices using Argon2 are detected
* Thu Aug 15 2024 Alexander Sosedkin <asosedkin@redhat.com> - 20240815-1.gite217f03
- java: start controlling / disable DTLSv1.0
- java: disable anon ciphersuites, tying them to NULL
- java: respect more key size restrictions
- java: specify jdk.tls.namedGroups system property
- java: make hash, mac and sign more orthogonal
- fips-mode-setup: add another scary "unsupported"
- fips-mode-setup: flashy ticking warning upon use
- java: use and include jdk.disabled.namedCurves
- ec_min_size: introduce and use in java, default to 256
- java: stop specifying jdk.tls.namedGroups in javasystem
- fips-setup-helper: add a libexec helper for anaconda
- fips-mode-setup: force --no-bootcfg when UKI is detected