libtomcrypt/libtommath not needed

Bug #1704892 reported by Steven Dake
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
kolla
Fix Released
High
Steven Dake

Bug Description

The dependencies libtomcrypt and libtommath aren't FIPS compliant. They were used in an older version of python-crypto (called python2-crypto in our RDO dependency list), however, this dependency has been superseded by python-crypto, atleast in the RDO world.

Revision history for this message
Steven Dake (sdake) wrote :
Changed in kolla:
status: New → Confirmed
importance: Undecided → High
assignee: nobody → Steven Dake (sdake)
milestone: none → pike-3
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to kolla (master)

Fix proposed to branch: master
Review: https://review.openstack.org/484536

Changed in kolla:
status: Confirmed → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to kolla (master)

Reviewed: https://review.openstack.org/484536
Committed: https://git.openstack.org/cgit/openstack/kolla/commit/?id=7b05e8dbccbff190f85d1d14ff32cef75d78a7ee
Submitter: Jenkins
Branch: master

commit 7b05e8dbccbff190f85d1d14ff32cef75d78a7ee
Author: Steven Dake <email address hidden>
Date: Mon Jul 17 09:24:02 2017 -0700

    Remove libcomcrypt/libtommath (not fips compliant)

    python2-crypto has been superceeded, atleast in RDO, by python-crypto
    which no longer uses the libtomcrypt/libtommath dependencies. As
    these dependencies are not certified by FIPS, they should be removed
    as well.

    Change-Id: I0bfb1631ad0189cf2a7b6ccacebcdf6651c69831
    Closes-Bug: #1704892

Changed in kolla:
status: In Progress → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/kolla 5.0.0.0b3

This issue was fixed in the openstack/kolla 5.0.0.0b3 development milestone.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.