stable

krb5-1.21.3-5.fc41

FEDORA-2025-42a13f896e created by jrische 10 months ago for Fedora 41
  • Disallowing use of the arcfour-hmac(-md5) encryption type for session keys
  • Add support for the PKINIT paChecksum2 sequence, required for Active Directory interoperability on Windows Server 2025
  • Fix generation of RADIUS Message-Authenticator in FIPS mode

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2025-42a13f896e

This update has been submitted for testing by jrische.

10 months ago

This update's test gating status has been changed to 'waiting'.

10 months ago

This update's test gating status has been changed to 'waiting'.

10 months ago

jrische edited this update.

10 months ago

This update's test gating status has been changed to 'passed'.

10 months ago

This update has been pushed to testing.

10 months ago
karma
User Icon derekenz commented & provided feedback 10 months ago
karma

Works

This update can be pushed to stable now if the maintainer wishes

10 months ago
User Icon filiperosset commented & provided feedback 10 months ago
karma

no regressions noted

This update has been submitted for stable by bodhi.

10 months ago

This update has been pushed to stable.

10 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
10 months ago
in testing
10 months ago
in stable
10 months ago
modified
10 months ago
approved
10 months ago
BZ#2357215 PKINIT: implement paChecksum2 from MS-PKCA v20230920 [fedora]
0
0
BZ#2359673 CVE-2025-3576 krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions [fedora-41]
0
0
BZ#2370259 Do not block HMAC-MD4/5 in FIPS mode [fedora-all]
0
0

Automated Test Results