#28401: Allow hashlib.md5() calls to work with FIPS kernels
-------------------------------------+-------------------------------------
     Reporter:  Andrew DiPrinzio     |                    Owner:  nobody
         Type:                       |                   Status:  new
  Cleanup/optimization               |
    Component:  Core (Other)         |                  Version:  master
     Severity:  Normal               |               Resolution:
     Keywords:  FIPS, md5            |             Triage Stage:
                                     |  Someday/Maybe
    Has patch:  0                    |      Needs documentation:  0
  Needs tests:  0                    |  Patch needs improvement:  0
Easy pickings:  0                    |                    UI/UX:  0
-------------------------------------+-------------------------------------

Comment (by Andrew DiPrinzio):

 Replying to [comment:1 Markus Holtermann]:
 > Thanks for the report.
 >
 > While I like the idea, `useforsecurity` doesn't seem to be part of the
 official Python package but rather something that Red Hat added and thus
 is only available on RHEL, Centos, etc.

 Thanks all for your insights! I continued to do research after opening
 this ticket. You are correct that this flag is only in some fedora
 distributions. Also i think it is fair to say that this not really a bug
 in django but rather a deficiency in python's hashlib. I will try and move
 that ticket forward on the python side.
 [https://bugs.python.org/issue9216]  However since some some distributions
 have this flag would it be acceptable to add support for this flag?
 something like this?


 {{{
 #!div style="font-size: 80%"
 {{{#!python
 try:
   hashlib.md5("blah")
 except ValueError e:
   # the fedora fix throws value errors for issues with FIPS
   hashlib.md5("blah", usedforsecurity=False)
 }}}
 }}}

-- 
Ticket URL: <https://code.djangoproject.com/ticket/28401#comment:4>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/064.323e5e7bec652ec8dc624aa4302b4c94%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to