)]}'
{"goals/proposed/pqc-readiness.rst":[{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"e2da7e86c99d65028dce59b976071133afd29ac5","unresolved":true,"context_lines":[{"line_number":154,"context_line":"approach (offering safer options without breaking existing deployments) is the"},{"line_number":155,"context_line":"right direction."},{"line_number":156,"context_line":""},{"line_number":157,"context_line":"Paramiko is the largest cross-project obstacle, shared with the FIPS goal. It"},{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"}],"source_content_type":"text/x-rst","patch_set":1,"id":"3ec278cb_1d31b8d8","line":157,"range":{"start_line":157,"start_character":48,"end_line":157,"end_character":73},"updated":"2026-08-21 14:47:58.000000000","message":"You should probably avoid tying this to the FIPS goal, since that has since been rolled from accepted back to proposed, and it\u0027s unclear whether it will ever regain traction.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"8f3099cc9c0197340364d187c519646d1990256e","unresolved":false,"context_lines":[{"line_number":154,"context_line":"approach (offering safer options without breaking existing deployments) is the"},{"line_number":155,"context_line":"right direction."},{"line_number":156,"context_line":""},{"line_number":157,"context_line":"Paramiko is the largest cross-project obstacle, shared with the FIPS goal. It"},{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"}],"source_content_type":"text/x-rst","patch_set":1,"id":"71639c8b_b8ff6455","line":157,"range":{"start_line":157,"start_character":48,"end_line":157,"end_character":73},"in_reply_to":"3ec278cb_1d31b8d8","updated":"2026-08-21 15:34:07.000000000","message":"Good point. Removed all references to the FIPS goal. The paramiko problem is real regardless of FIPS status, and tying them together adds unnecessary coupling.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"e2da7e86c99d65028dce59b976071133afd29ac5","unresolved":true,"context_lines":[{"line_number":156,"context_line":""},{"line_number":157,"context_line":"Paramiko is the largest cross-project obstacle, shared with the FIPS goal. It"},{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"},{"line_number":161,"context_line":"exchange support to paramiko, but it requires OpenSSL 3.5+ and the project\u0027s"},{"line_number":162,"context_line":"single-maintainer model creates uncertainty about the merge timeline. The"}],"source_content_type":"text/x-rst","patch_set":1,"id":"1089ed7b_83eb9074","line":159,"range":{"start_line":159,"start_character":37,"end_line":159,"end_character":64},"updated":"2026-08-21 14:47:58.000000000","message":"I would recommend not mentioning Nova\u0027s keypair generation since it\u0027s been deprecated for years and is unlikely to accept any \"fixes\" other than removal anyway.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"8f3099cc9c0197340364d187c519646d1990256e","unresolved":false,"context_lines":[{"line_number":156,"context_line":""},{"line_number":157,"context_line":"Paramiko is the largest cross-project obstacle, shared with the FIPS goal. It"},{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"},{"line_number":161,"context_line":"exchange support to paramiko, but it requires OpenSSL 3.5+ and the project\u0027s"},{"line_number":162,"context_line":"single-maintainer model creates uncertainty about the merge timeline. The"}],"source_content_type":"text/x-rst","patch_set":1,"id":"8116ef90_8b5aeba2","line":159,"range":{"start_line":159,"start_character":37,"end_line":159,"end_character":64},"in_reply_to":"1089ed7b_83eb9074","updated":"2026-08-21 15:34:07.000000000","message":"You are right, removed.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"e2da7e86c99d65028dce59b976071133afd29ac5","unresolved":true,"context_lines":[{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"},{"line_number":161,"context_line":"exchange support to paramiko, but it requires OpenSSL 3.5+ and the project\u0027s"},{"line_number":162,"context_line":"single-maintainer model creates uncertainty about the merge timeline. The"},{"line_number":163,"context_line":"Ironic team is independently exploring a libssh-based alternative for"},{"line_number":164,"context_line":"networking-generic-switch. Neither FIPS compliance nor PQC readiness can be"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c75ffd94_cb156f1a","line":161,"range":{"start_line":161,"start_character":30,"end_line":161,"end_character":58},"updated":"2026-08-21 14:47:58.000000000","message":"I\u0027m unsure why you present the OpenSSL 3.5+ requirement as a problem, since your Problem Statement section implies its TLS improvements are important regardless.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"},{"author":{"_account_id":35125,"name":"Mauricio Harley","email":"mharley@redhat.com","username":"mharley-rh"},"change_message_id":"8f3099cc9c0197340364d187c519646d1990256e","unresolved":false,"context_lines":[{"line_number":158,"context_line":"is used in Cinder (SAN storage drivers and SSHPool), Manila (storage driver"},{"line_number":159,"context_line":"SSH), Tempest (instance validation), Nova (keypair operations), and indirectly"},{"line_number":160,"context_line":"in Ironic (netmiko). A recent experimental PR (#2668) adds ML-KEM hybrid key"},{"line_number":161,"context_line":"exchange support to paramiko, but it requires OpenSSL 3.5+ and the project\u0027s"},{"line_number":162,"context_line":"single-maintainer model creates uncertainty about the merge timeline. The"},{"line_number":163,"context_line":"Ironic team is independently exploring a libssh-based alternative for"},{"line_number":164,"context_line":"networking-generic-switch. Neither FIPS compliance nor PQC readiness can be"}],"source_content_type":"text/x-rst","patch_set":1,"id":"d24b7b12_a9f4c33e","line":161,"range":{"start_line":161,"start_character":30,"end_line":161,"end_character":58},"in_reply_to":"c75ffd94_cb156f1a","updated":"2026-08-21 15:34:07.000000000","message":"Fair point, rephrased. OpenSSL 3.5+ is a prerequisite for PQC anyway, not an additional burden.","commit_id":"da7971fde818ed9d26102f5716972afb1ce03c1e"}]}
