Bug 1645711

Summary: Updated krb5-libs packages in RHEL 7.6 will cause apps to crash when fips mode is on
Product: Red Hat Enterprise Linux 7 Reporter: Scott Spurrier <spurrier>
Component: krb5Assignee: Robbie Harwood <rharwood>
Status: CLOSED CURRENTRELEASE QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: high Docs Contact: Mirek Jahoda <mjahoda>
Priority: high    
Version: 7.6CC: abokovoy, ascheel, bscalio, bwelterl, cgehring, dpal, ekeck, eric.hausgaard, gparente, hkhot, jpazdziora, ksiddiqu, lmanasko, mjahoda, pkis, qe-baseos-security, rharwood, sali, sbose, sean.radigan, spurrier, tmihinto, tscherf, vmishra
Target Milestone: rcKeywords: Regression, ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: krb5-1.15.1-37.el7_6 Doc Type: Bug Fix
Doc Text:
.`krb5` configurations prohibited by FIPS 140-2 can now work again Previously, Red Hat Enterprise Linux 7.6 build of the Kerberos V5 (`krb5`) system increased compliance with FIPS 140-2. As a consequence, certain previously permitted configurations that were prohibited by FIPS 140-2 stopped working. With this update, the changes have been reverted, because `krb5` only requires to work in FIPS mode, not be FIPS-compliant. As a result, configurations prohibited by FIPS 140-2 can now work again. Note that Red Hat Enterprise Linux 8 does not support these configurations at the moment.
Story Points: ---
Clone Of:
: 1659497 (view as bug list) Environment:
Last Closed: 2019-08-06 15:49:17 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1659497    

Comment 24 Sumit Bose 2018-11-16 18:40:12 UTC
*** Bug 1649660 has been marked as a duplicate of this bug. ***

Comment 49 Robbie Harwood 2018-12-06 17:33:22 UTC
*** Bug 1654646 has been marked as a duplicate of this bug. ***