#470 F33 System-Wide Change: Strong crypto settings: phase 2
Closed 6 months ago. Opened a year ago.

This issue tracks the release note for the following Fedora Change:


Fedora 33 due to this change disables TLS protocol versions older than 1.2 version, minimum parameter size for Diffie Hellman key exchanges is set to 2048 bits, and use of signatures with SHA1 hash is disabled in the TLS, SSH, and IKE protocols by default.

For that reason the Fedora 33 might no longer communicate with legacy systems that support only the protocol versions, DH parameter size or SHA1 hash in signatures.

If you need to communicate with such systems, please set the system-wide crypto policy to LEGACY with the following command:

update-crypto-policies --set LEGACY

If we would like to extend on the possible workarounds in SSH, comment https://bugzilla.redhat.com/show_bug.cgi?id=1884920#c1 should contain all important information.

@pbokoc I cannot find this mentioned in the release notes. Wouldn't it make sense to include it so we do not surprise people as below?


this thread can help in defining what users need to know about the change.

The names of algorithms may be confusing, and not telling much for a generic user, but the fact that you may lose the possibility to login into some older systems" will attract attention.

I'm seeing quite a lot of user confusion as a result of this change in various forums like the Reddit post @bookwar mentioned. In retrospect, this change should not have been approved with "Documentation: None / Release Notes: [blank]".

