On 3/18/21 4:10 PM, Ben Cotton wrote:
On Thu, Mar 18, 2021 at 10:06 AM Jakub Jelen
<jjelen(a)redhat.com> wrote:
>
> We need to strip these curves from upstream tarballs and it would be
> great to have this resolved (in either way) rather sooner than later.
>
The Brainpool curves are not approved for use in Fedora at this time.
Hi,
I wanted to bring up this topic once more again as it was suggested that
if the curves are build-time disabled we should be able to go around
without hobbling the source tarball. I proposed the following change to
libgcrypt to support build-time disabling brainpool curves and I wanted
to double-check if this approach is legally acceptable:
https://dev.gnupg.org/T5520#149566
Thanks,
--
Jakub Jelen
Crypto Team, Security Engineering
Red Hat, Inc.