#9883 Add support for ML-DSA certificates
Opened by abbra. Modified

As and administrator, I want to deploy new FreeIPA environment with post-quantum cryptography algorithms chosen by default.


This will need to include certmonger support currently staged in https://pagure.io/fork/rcritten/certmonger/commits/pq

NSS versions with PQ support: 3.118 for Fedora, 3.112 for RHEL/CentOS.

Metadata Update from @rcritten:
- Custom field rhbz adjusted to https://issues.redhat.com/browse/IDM-4972

master:

  • 3d750c39d28804a8cad1d96b00eabba244b65637 Add minimal support for an ML-DSA CA server installation

master:

  • a5e42d0a3c4c43eb8eab13da756e59c6331b9f73 Allow ML-DSA keys for IPA RA, Apache and 389-ds

master:

  • 8c3ef830f83b7824102d0e3f76ce330f1bb733a6 Add new option, --ca-key-type for flexibility
  • 854212a32a3af4029c202e6495f00e260b71f3fa Handle ML-DSA certificates when installing a replica
  • 442b39a4232e067149ce543e992d354a01f8b330 Test for IPA certificates with ML-DSA keys
  • 4bd530a1748e8784ac7a819cef22fbb38bad2c37 cert profiles: enable ML-DSA subject keys
  • 16bf6545416dbe72fd4601e5de03cce253f53915 Modify the CA subsystem profiles in LDAP to allow ML-DSA
  • 564db10171b198c977480ca694136569e4c05239 Detect the install CA key type for configuring the KRA keys
Metadata