Packaging of new cryptography libraries currently requires signoff from the "Fedora crypto team": https://docs.fedoraproject.org/en-US/packaging-guidelines/CryptoPolicies/#_new_crypto_libraries
This "team" is defunct and hasn't existed for the better part of a decade (or longer?), the linked mailing list is private, moderated, and appears to have zero messages in its mailing list archive. Sending mails to it is equivalent to sending something to /dev/null.
The Red Hat Crypto team now ~kind of~ fills the role that the "Fedora crypto team" used to have, except for some tasks (like approvals for new cryptography libraries) that are still referenced in our documentation but that nobody seems to be responsible for now. This means that packaging any such library has basically stalled due to lack of the necessary "OK" (or even a definitive "no") from a group that no longer exists (see RHBZ#2350145 for an example).
I propose that this signoff requirement is dropped from the Packaging Guidelines.
It'd be nice to have a little bit of the backstory on why sign-off is/was required. In case it makes sense to have sign-off and the Red Hat crypto team is willing to take this up as a responsibility I'd instead suggest to change the documentation to refer to them and the ways to reach them.
If not, then getting rid of the signoff requirement is indeed the only option.
Do we want to reach out, or have we already done so? I saw some back-and-forth on devel@ about it but it wasn't particularly clear.
The team is not defunct, but the contact point described there somehow stopped working.
I think carefully curating what cryptography is allowed in Fedora is a vital service to the integrity of the distribution. not all crypto-librraies are equal, and some are really bad, while others simply do not integrate with the rest of the distribution (crypto-policy, system CA store, etc...)
So far the request are always "oh I'd like to put this in", and the only justification is XYZ needs it and does not support a proper library and I do not care for addressing the issues.
I think the policing could be lifted if there was serious respect of the guidelines (ie integration with crypto-policies and system-ca store as a minimum).
That would still leave unanswered a check on the quality of the library. And especially now there are many bad libraries in hip ecosystems ...
Just a simple example of the systemic issues of the cryptographic implementations: https://hexproof.dev/datagrams/bleichenbacher-oracle-survey/