Bug 13677

Summary: [fix 21] shadow-utils: Svace fix, enable GOST
Product: [ROSA-based products] ROSA Fresh Reporter: Mikhail Novosyolov <m.novosyolov>
Component: Packages from MainAssignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: normal    
Priority: Normal CC: a.proklov, pastordidi, v.potapov
Version: AllFlags: v.potapov: qa_verified+
a.proklov: published+
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Mikhail Novosyolov 2023-10-16 13:49:47 MSK
********* QA ADVISORY ********

shadow-utils 4.10-4
- fix issues found by Svace static analyzer (hisshadow@)
- enable bcrypt and yescrypt
https://abf.io/build_lists/4754758
https://abf.io/build_lists/4754759
https://abf.io/build_lists/4754761
https://abf.io/build_lists/4754763
https://abf.io/build_lists/4754765

Если в /etc/pam.d/system-auth у pam_unix поменять sha512 на gost_yescrypt, то пароли будут хешироваться по ГОСТ, даже через passwd работает их смена, но passwd не из shadow-utils.
Comment 1 Dmitry Postnikov 2023-10-18 09:45:25 MSK
***************************
The update sent to testings
Comment 2 Vladimir Potapov 2023-10-24 12:48:50 MSK
shadow-utils-4.10-4
https://abf.io/build_lists/4754758
https://abf.io/build_lists/4754759
https://abf.io/build_lists/4754761
https://abf.io/build_lists/4754763
https://abf.io/build_lists/4754765
************************** Advisory ***********************
- fix issues found by Svace static analyzer (hisshadow@)
- enable bcrypt and yescrypt
************************************************************
QA Verified