Bug 1184142
Summary: | RHEL 6.6 kernel will not boot with fips enabled | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | Allie DeVolder <adevolder> |
Component: | dracut | Assignee: | Harald Hoyer <harald> |
Status: | CLOSED ERRATA | QA Contact: | Release Test Team <release-test-team-automation> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | 6.6 | CC: | adevolder, dracut-maint-list, harald, mganisin, mkolaja, pholica |
Target Milestone: | rc | ||
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
Cause:
nss-softokn-freebl changed files internally.
Consequence:
dracut could not build an initramfs for FIPS mode, because one file was missing.
Fix:
nss-softokn-freebl delivers its own dracut module and dracut requires now nss-softokn-freebl >= 3.14.3-22.el6_6
Result:
dracut can build a FIPS enabled initramfs with all files.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2015-07-22 06:38:10 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Allie DeVolder
2015-01-20 16:34:02 UTC
(In reply to Allan Voss from comment #0) > Description of problem: > When upgrading to RHEL 6.6, dracut failed to create an initrd, and manual > attempts to create an initrd failed with "Failed to install > /usr/lib64/libfreebl3.chk". After following the bugzilla workaround to > create a dummy file, the resulting initrd panics on boot as follows: > ~~~ > Kernel Panic - not syncing: VFS: Unable to mount root fs on > unknown-block(0,0) > Pid: 1, comm: swapper Not tainted 2.6.32-504.3.3.el6.x86_64 #1 > Call Trace: > ~~~ This kernel message says, that no initramfs was loaded by the kernel. Are you sure, you created the initramfs image correctly? Is your bootloader config correct? Please provide the output of: # dracut --debug test.img This bug should be resolved in RHEL 6.6.z within bug #1182725 and will be resolved in RHEL 6.7 within bug #1182297. Am I getting it right Harald? Thanks! Reproduced on RHEL-6.6 with nss-softokn-3.14.3-19.el6_6 and nss-softokn-freebl-3.14.3-19.el6_6 updated from RHN. Verified that dracut from RHEL-6.7-20150506.0 requires nss-softokn-freebl >= 3.14.3-22.el6_6. nss-softokn-freebl-3.14.3-22.el6_6 is available in compose and on RHN already. After nss-softokn-freebl update, dracut was able to successfully buil initramfs and boot in fips mode. Moving to VERIFIED. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-1328.html |