Bug 1670716

Summary: Coredump when starting in FIPS mode
Product: Red Hat Enterprise Linux 8 Reporter: Branislav Náter <bnater>
Component: httpdAssignee: Luboš Uhliarik <luhliari>
Status: CLOSED CURRENTRELEASE QA Contact: Branislav Náter <bnater>
Severity: high Docs Contact:
Priority: unspecified    
Version: 8.0CC: jorton, luhliari, omoris
Target Milestone: rc   
Target Release: 8.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-14 01:58:40 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Core dump none

Description Branislav Náter 2019-01-30 09:01:16 UTC
Created attachment 1524979 [details]
Core dump

Description of problem:
httpd does not start and produce core dumps when running in FIPS mode.

Version-Release number of selected component (if applicable):
httpd-2.4.37-7.module+el8+2443+605475b7.x86_64
mod_ssl-2.4.37-7.module+el8+2443+605475b7.x86_64

How reproducible:
always

Steps to Reproduce:
1. run /CoreOS/httpd/Sanity/mod_ssl-smoke in FIPS mode
In Beaker: bkr workflow-tomorrow --case 554185 --distro rhel-8 --arch x86_64 --fips --reserve

Actual results:
httpd doesn't start

Expected results:
httpd starts

Additional info:
journalctl -xe
systemd-coredump[19428]: Process 19424 (httpd) of user 0 dumped core.
 Stack trace of thread 19424:
#0  0x00007f5059518384 SSL_CTX_set_options (libssl.so.1.1)
#1  0x00007f5059781cad ssl_init_ctx (mod_ssl.so)
#2  0x00007f5059783774 ssl_init_ConfigureServer (mod_ssl.so)
#3  0x00007f5059784af5 ssl_init_Module (mod_ssl.so)
#4  0x0000562c42c17533 ap_run_post_config (httpd)
#5  0x0000562c42bf234f main (httpd)
#6  0x00007f5066963813 __libc_start_main (libc.so.6)
#7  0x0000562c42bf24ae _start (httpd)

Comment 7 Branislav Náter 2019-02-12 08:35:45 UTC
Issue verified on httpd-2.4.37-10.module+el8+2764+7127e69e using automated test (see external trackers)
httpd is able to start in FIPS mode now.

TCMS Test case run: https://tcms.engineering.redhat.com/run/353584/#caserun_20283754