https://bugzilla.redhat.com/show_bug.cgi?id=2005536 Fabio Valentini <decathorpe@xxxxxxxxx> changed: What |Removed |Added ---------------------------------------------------------------------------- Blocks| |182235 (FE-Legal) Flags|needinfo?(decathorpe@gmail. | |com) | --- Comment #6 from Fabio Valentini <decathorpe@xxxxxxxxx> --- Package looks good to me, with one exception. The fiat-crypto crate ships implementations of many elliptic curves, some of which aren't explicitly listed as "permitted in Fedora" here: https://fedoraproject.org/wiki/Legal:ECC There has been some discussion about whether any elliptic curves are actually still not "good", but we haven't received any definitive resonses from Red Hat legal: https://lists.fedoraproject.org/archives/list/legal@xxxxxxxxxxxxxxxxxxxxxxx/thread/IQELSXUUNQFYYQ2JU3NOWLF2TOI7DEYZ/ Looks like the curves implemented in fiat-crypto are: - Curve 25519: listed as OK - p224 / secp224r1: listed as OK - p256 / secp256r1: listed as OK - p384 / secp384r1: listed as OK - p434: not listed as OK; cannot find any documentation or source for this curve - p448 / Curve 448: listed as OK - p521 / secp521r1: listed as OK - secp256k1: listed as OK Blocking FE-Legal. We need to know whether the p434 curve is OK ... Referenced Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=182235 [Bug 182235] Fedora Legal Tracker -- You are receiving this mail because: You are always notified about changes to this product and component You are on the CC list for the bug. https://bugzilla.redhat.com/show_bug.cgi?id=2005536 _______________________________________________ package-review mailing list -- package-review@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to package-review-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-review@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue