Back to bug 2148269

Who When What Removed Added
Red Hat Bugzilla 2022-11-24 19:56:26 UTC Pool ID sst_security_crypto_rhel_9
Red Hat One Jira (issues.redhat.com) 2022-11-24 19:57:33 UTC Link ID Red Hat Issue Tracker RHELPLAN-140419
Daiki Ueno 2022-11-24 22:50:32 UTC Flags needinfo?(jpazdziora)
Jan Pazdziora 2022-11-25 06:34:44 UTC Flags needinfo?(jpazdziora)
CC jpazdziora
Daiki Ueno 2022-11-28 05:46:58 UTC Keywords Triaged
Priority unspecified high
Red Hat One Jira (issues.redhat.com) 2022-11-28 05:54:53 UTC Link ID Red Hat Issue Tracker CRYPTO-8879
Daiki Ueno 2022-11-30 08:30:04 UTC Link ID Gitlab gnutls/gnutls/-/merge_requests/1674
Daiki Ueno 2022-11-30 08:31:21 UTC Assignee dueno zfridric
Alexander Sosedkin 2022-11-30 11:53:51 UTC Doc Type If docs needed, set a value Bug Fix
Doc Text Cause: HMAC file for gnutls, used for integrity checks in FIPS mode, has been moved to `/usr/lib64/.gnutls.hmac`

Consequence: other software relying on HMAC file location wasn't able to locate it. For example, dracut no longer copied it to initramfs, impacting functionality of NetworkManager during early boot in FIPS mode

Fix: gnutls HMAC file location has been moved back to `/usr/lib64/.libgnutls.so.30.hmac`

Result: gnutls HMAC file is successfully installed into initramfs for machines switched to FIPS mode
CC asosedki
Zoltan Fridrich 2022-11-30 11:59:46 UTC Status NEW ASSIGNED
Doc Text Cause: HMAC file for gnutls, used for integrity checks in FIPS mode, has been moved to `/usr/lib64/.gnutls.hmac`

Consequence: other software relying on HMAC file location wasn't able to locate it. For example, dracut no longer copied it to initramfs, impacting functionality of NetworkManager during early boot in FIPS mode

Fix: gnutls HMAC file location has been moved back to `/usr/lib64/.libgnutls.so.30.hmac`

Result: gnutls HMAC file is successfully installed into initramfs for machines switched to FIPS mode
If this bug requires documentation, please select an appropriate Doc Type value.
Zoltan Fridrich 2022-11-30 12:03:45 UTC Doc Text If this bug requires documentation, please select an appropriate Doc Type value. Cause:
HMAC file for gnutls, used for integrity checks in FIPS mode, has been moved to `/usr/lib64/.gnutls.hmac`

Consequence:
other software relying on HMAC file location wasn't able to locate it. For example, dracut no longer copied it to initramfs, impacting functionality of NetworkManager during early boot in FIPS mode

Fix:
gnutls HMAC file location has been moved back to `/usr/lib64/.libgnutls.so.30.hmac`

Result:
gnutls HMAC file is successfully installed into initramfs for machines switched to FIPS mode
Zoltan Fridrich 2022-11-30 12:07:15 UTC Flags needinfo?(ssorce)
CC ssorce
Simo Sorce 2022-11-30 13:42:16 UTC Flags needinfo?(ssorce)
RHEL Program Management Team 2022-11-30 13:47:27 UTC Blocks 2149640
RHEL Program Management Team 2022-11-30 13:47:32 UTC Blocks 2149641
RHEL Program Management Team 2022-11-30 13:47:34 UTC Keywords ZStream
Alexander Sosedkin 2022-12-12 17:21:42 UTC QA Contact qe-baseos-security asosedki
Zoltan Fridrich 2022-12-16 13:15:16 UTC Fixed In Version gnutls-3.7.6-15.el9
Status ASSIGNED MODIFIED
errata-xmlrpc 2022-12-16 15:31:03 UTC Status MODIFIED ON_QA
Alexander Sosedkin 2022-12-20 13:59:46 UTC Status ON_QA VERIFIED
errata-xmlrpc 2023-05-09 00:31:10 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2023-05-09 08:20:29 UTC Resolution --- ERRATA
Status RELEASE_PENDING CLOSED
Last Closed 2023-05-09 08:20:29 UTC
errata-xmlrpc 2023-05-09 08:20:50 UTC Link ID Red Hat Product Errata RHBA-2023:2522

Back to bug 2148269