SUSE-CU-2026:9859-1: Recommended update of private-registry/harbor-jobservice

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Sep 10 07:14:53 UTC 2026


SUSE Container Update Advisory: private-registry/harbor-jobservice
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9859-1
Container Tags        : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.110 , private-registry/harbor-jobservice:latest
Container Release     : 2.110
Severity              : important
Type                  : recommended
References            : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025
                        1258311 1259825 1262315 1275660 
-----------------------------------------------------------------

The container private-registry/harbor-jobservice was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4110-1
Released:    Wed Sep  9 17:00:16 2026
Summary:     Recommended update for crypto-policies
Type:        recommended
Severity:    important
References:  1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660
This update for crypto-policies fixes the following issues:

- Update crypto-policies for Post-Quantum Cryptography (PQC) TLS
  support in SLE-15-SP7 (jsc#PED-16072):

  * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660)
  * Add support for python36 (jsc#PED-16072)
  * Add support for sntrup761x25519-sha512 at openssh.com and remove
    it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7
    as it only lists the former (bsc#1258311, bsc#1259825)

- Allow X25519 as required for sntrup761x25519-sha512 at openssh.com
  and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825)

- Add PQC support for OpenSSH (bsc#1258311, bsc#1259825)
  * Enable sntrup761x25519-sha512 for OpenSSH by default

- Modify the output of fips-mode-setup to hint the user when
  setting the FIPS mode in transactional systems to use the
  command 'transactional-update setup-fips'. (bsc#1262315)

- Adapt the manpages to SUSE/openSUSE:
  * Compress all the man pages for update-crypto-policies.8.gz,
    crypto-policies.7.gz, fips-finish-install.8.gz and
    fips-mode-setup.8.gz into man-crypto-policies.tar.xz

- Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696]

  * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert
  * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519
  * FIPS: disable MLKEM768-X25519 for openssh (no-op)
  * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl...
  * TEST-PQ: be more careful with the ordering
  * openssl: send one PQ and one classic key_share; prioritize PQ groups
  * sequoia: Generate AEAD policy
  * Do not include EdDSA in FIPS policy
  * sequoia: Add PQC algorithm
  * sequoia: Run tests against PQC capable policy-config-check
  * Revert 'openssl, policies: implement group_key_share option'
  * openssl, policies: implement group_key_share option
  * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA
  * python/build-crypto-policies: output diffs on --test mismatches
  * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ...
  * policies, alg_lists, openssl: remove KYBER from allowed values
  * openssl: stricter enabling of Ciphersuites
  * openssl: make use of -CBC and -AESGCM keywords
  * openssl: add TLS 1.3 Brainpool identifiers
  * fix warning on using experimental key_exchanges
  * update-crypto-policies: don't output FIPS warning in fips mode
  * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256
  * openssh, libssh: refactor kx maps to use tuples
  * alg_lists: mark MLKEM768/SNTRUP kex experimental
  * nss: revert enabling mlkem768secp256r1
  * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber
  * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768
  * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768
  * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768
  * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256
  * LEGACY: enable 192-bit ciphers for nss pkcs12/smime
  * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384...
  * nss: be stricter with new purposes
  * python/update-crypto-policies: pacify pylint
  * fips-mode-setup: tolerate fips dracut module presence w/o FIPS
  * fips-mode-setup: small Argon2 detection fix
  * SHA1: add __openssl_block_sha1_signatures = 0
  * fips-mode-setup: block if LUKS devices using Argon2 are detected
  * update-crypto-policies: skip warning on --set=FIPS if bootc
  * fips-setup-helper: skip warning, BTW
  * fips-mode-setup: force --no-bootcfg when UKI is detected
  * fips-crypto-policy-overlay: automount FIPS policy
  * nss: rewrite backend for 3.101
  * cryptopolicies: parent scopes for dumping purposes
  * policygenerators: move scoping inside generators
  * openssh: make dss no longer enableble, support is dropped
  * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768
  * TEST-PQ: disable pure Kyber768
  * DEFAULT: switch to rh-allow-sha1-signatures = no...
  * java: drop unused javasystem backend
  * java: stop specifying jdk.tls.namedGroups in javasystem
  * ec_min_size: introduce and use in java, default to 256
  * java: use and include jdk.disabled.namedCurves
  * BSI: Update BSI policy for new 2024 minimum recommendations
  * fips-mode-setup: flashy ticking warning upon use
  * fips-mode-setup: add another scary 'unsupported'
  * BSI: switch to 3072 minimum RSA key size
  * java: make hash, mac and sign more orthogonal
  * java: specify jdk.tls.namedGroups system property
  * java: respect more key size restrictions
  * java: disable anon ciphersuites, tying them to NULL...
  * java: start controlling / disable DTLSv1.0
  * nss: wire KYBER768 to XYBER768D00

- Update to version 20250425.9267dee:

  * openssl: fix mistakes in integrity-only cipher definitions
  * NO-PQ, cryptopolicies: add experimental value suppression
  * nss: add mlkem768x25519 and mlkem768secp256r1
  * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY
  * TEST-PQ, openssh: add support for MLKEM768 key_exchange
  * LEGACY: drop cipher at pkcs12 = SEED-CBC
  * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes
  * nss: TLS-REQUIRE-EMS in FIPS
  * DEFAULT: disable RSA key exchange
  * LEGACY: disable sign = *-SHA1
  * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768

- Add the FIPS scripts fips-finish-install and fips-mode-setup as
  sources in the spec file as they have been removed upstream.
  * We will maintain these scripts downstream.
  * Update the man pages for update-crypto-policies.8.gz
  * Add man pages in text file in compressed form in the file
    man-fips-scripts.tar.xz and add them to the Makefile.

- Update to version 20250324.3714354:

  * NO-PQ: introduce
  * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA
  * _openssl_block_sha1_signatures: flip the default to 1
  * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia
  * sequoia: refactor a bit
  * openssl: specify default key size for req
  * gnutls: support P384-MLKEM1024
  * openssl: stop generating `openssl` in favour of `opensslcnf`
  * gnutls: drop kyber (switching to leancrypto took it away)
  * openssl: use both names for P384-MLKEM1024
  * Detect the presence of nss-policy-check
  * Don't use hardcoded python3 path
  * Make xsltproc settable as XSLTPROC
  * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021
  * Update the info in the README.SUSE file
  * Remove the FEDORA policies and directories

- Allow openssl to load when using the DEFAULT policy, and also
  other policies, in FIPS mode. [bsc#1243830, bsc#1242233]

- Relax the nss version requirement since the mlkem768secp256r1
  enablement has been reverted.

- Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370]

- Enable SHA1 sigver in the DEFAULT policy.

- Remove also sequoia config and generator files
- Remove not needed fips bind mount service

- Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165]

  * openssl: stricter enabling of Ciphersuites
  * openssl: make use of -CBC and -AESGCM keywords
  * openssl: add TLS 1.3 Brainpool identifiers
  * fix warning on using experimental key_exchanges
  * update-crypto-policies: don't output FIPS warning in fips mode
  * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256
  * openssh, libssh: refactor kx maps to use tuples
  * alg_lists: mark MLKEM768/SNTRUP kex experimental
  * nss: revert enabling mlkem768secp256r1
  * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber
  * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768
  * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768
  * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768
  * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256
  * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384...
  * python/update-crypto-policies: pacify pylint
  * fips-mode-setup: tolerate fips dracut module presence w/o FIPS
  * fips-mode-setup: small Argon2 detection fix
  * SHA1: add __openssl_block_sha1_signatures = 0
  * fips-mode-setup: block if LUKS devices using Argon2 are detected
  * update-crypto-policies: skip warning on --set=FIPS if bootc
  * fips-setup-helper: skip warning, BTW
  * fips-mode-setup: force --no-bootcfg when UKI is detected
  * fips-setup-helper: add a libexec helper for anaconda
  * fips-crypto-policy-overlay: automount FIPS policy
  * openssh: make dss no longer enableble, support is dropped
  * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768
  * DEFAULT: switch to rh-allow-sha1-signatures = no...
  * java: drop unused javasystem backend
  * java: stop specifying jdk.tls.namedGroups in javasystem
  * ec_min_size: introduce and use in java, default to 256
  * java: use and include jdk.disabled.namedCurves
  * BSI: Update BSI policy for new 2024 minimum recommendations
  * fips-mode-setup: flashy ticking warning upon use
  * fips-mode-setup: add another scary 'unsupported'
  * CONTRIBUTING.md: add a small section on updating policies
  * CONTRIBUTING.md: remove trailing punctuation from headers
  * BSI: switch to 3072 minimum RSA key size
  * java: make hash, mac and sign more orthogonal
  * java: specify jdk.tls.namedGroups system property
  * java: respect more key size restrictions
  * java: disable anon ciphersuites, tying them to NULL...
  * java: start controlling / disable DTLSv1.0
  * nss: wire KYBER768 to XYBER768D00
  * nss: unconditionally load p11-kit-proxy.so
  * gnutls: make DTLS0.9 controllable again
  * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH
  * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE
  * gnutls: remove extraneous newline
  * sequoia: move away from subprocess.getstatusoutput
  * python/cryptopolicies/cryptopolicies.py: add trailing commas
  * python, tests: rename MalformedLine to MalformedLineError
  * Makefile: introduce SKIP_LINTING flag for packagers to use
  * Makefile: run ruff
  * tests: use pathlib
  * tests: run(check=True) + CalledProcessError where convenient
  * tests: use subprocess.run
  * tests/krb5.py: check all generated policies
  * tests: print to stderr on error paths
  * tests/nss.py: also use encoding='utf-8'
  * tests/nss.py: also use removesuffix
  * tests/nss.py: skip creating tempfiles
  * tests/java.pl -> tests/java.py
  * tests/gnutls.pl -> tests/gnutls.py
  * tests/openssl.pl -> tests/openssl.py
  * tests/verify-output.pl: remove
  * libreswan: do not use up pfs= / ikev2= keywords for default behaviour

- Update to version 20241010.5930b9a:
  * LEGACY: enable 192-bit ciphers for nss pkcs12/smime
  * nss: be stricter with new purposes
  * nss: rewrite backend for 3.101
  * cryptopolicies: parent scopes for dumping purposes
  * policygenerators: move scoping inside generators
  * TEST-PQ: disable pure Kyber768
  * nss: wire XYBER768D00 to X25519-KYBER768
  * TEST-PQ: update
  * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com
  * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values
  * TEST-PQ, python: add more groups, mark experimental
  * openssl: mark liboqsprovider groups optional with ?

- Update to version 20240201.9f501f3:
  * .gitlab-ci.yml: install sequoia-policy-config
  * java: disable ChaCha20-Poly1305 where applicable
  * fips-mode-setup: make sure ostree is detected in chroot
  * fips-finish-install: make sure ostree is detected in chroot
  * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl
  * TEST-PQ: add a no-op subpolicy
  * update-crypto-policies: Keep mid-sentence upper case
  * fips-mode-setup: Write error messages to stderr
  * fips-mode-setup: Fix some shellcheck warnings
  * fips-mode-setup: Fix test for empty /boot
  * fips-mode-setup: Avoid 'boot=UUID=' if /boot == /
  * Update man pages

- Update to version 20231108.adb5572b:
  * Print matches in syntax deprecation warnings
  * Restore support for scoped ssh_etm directives
  * fips-mode-setup: Fix usage with --no-bootcfg
  * turn ssh_etm into an etm at SSH tri-state
  * fips-mode-setup: increase chroot-friendliness
  * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx
  * pylintrc: use-implicit-booleaness-not-comparison-to-*

- avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros:
  we only need python3-base here, we don't need the python
  macros as no module is being built

- Remove dependency on /usr/bin/python3, making scripts to depends on
  the real python3 binary, not the link. bsc#1212476

The following package changes have been done:

- crypto-policies-20250714.cd6043a-150700.6.4.2 updated
- system-user-harbor-2.14.4-150700.1.44 updated
- harbor-jobservice-2.14.4-150700.1.44 updated


More information about the sle-container-updates mailing list