Re: RHEL9+, RSASHA1 and CVE-2025-8677

Ondřej Surý <[email protected]>
Newsgroups gmane.network.dns.bind9.user
Message-ID <97DC7756-2D69-4C38-BC25-CB65A74F535B__26709.4931144797$1762520079$gmane$org@isc.org>
Debian never had that problem, as RSASHA1 is not disabled there in the crypto library, the setting

       disable-algorithms . {
               RSASHA1;
       };

is a different.

You would need something like RSAMD5 + <supported algorithm> to reproduce the issue.

Ondrej
--
Ondřej Surý (He/Him)
[email protected]

My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.

> On 7. 11. 2025, at 7:46, Bjørn Mork via bind-users <[email protected]> wrote:
> 
> But I'm unable to reproduce the original issue with the current 9.20.15
> based package in Debian.  Probably doing something wrong...

-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.