Skip to content

Commit 77eb16d

Browse files
committed
Revert RL9 crypto policy to DEFAULT
This should resolve SSH issues with some modern key types such as ed25519.
1 parent 840924f commit 77eb16d

File tree

2 files changed

+8
-1
lines changed

2 files changed

+8
-1
lines changed

etc/kayobe/inventory/group_vars/cis-hardening/cis

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,8 @@ rhel9cis_rule_3_4_1_2: false
2727
rhel9cis_selinux_disable: true
2828

2929
# NOTE: FUTURE breaks wazuh agent repo metadata download
30-
rhel9cis_crypto_policy: FIPS
30+
# NOTE: FIPS break ed25519 SSH keys
31+
rhel9cis_crypto_policy: DEFAULT
3132

3233
# Skip package updates
3334
rhel9cis_rule_1_9: false
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
---
2+
security:
3+
- |
4+
Updates the default CIS hardening configuration to set
5+
``rhel9cis_crypto_policy`` to ``DEFAULT`` instead of ``FIPS``. This
6+
resolves SSH issues with some modern key types such as ``ed25519``.

0 commit comments

Comments
 (0)