Bug 1962418

Summary: Include a note for ed25519 keys if used with FIPS enabled for installation
Product: OpenShift Container Platform Reporter: Jatan Malde <jmalde>
Component: DocumentationAssignee: Kathryn Alexander <kalexand>
Status: CLOSED CURRENTRELEASE QA Contact: Gaoyun Pei <gpei>
Severity: high Docs Contact: Vikram Goyal <vigoyal>
Priority: unspecified    
Version: 4.7CC: aos-bugs, jokerman, kalexand, mstaeble
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-06-14 18:16:27 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jatan Malde 2021-05-20 02:23:26 UTC
Document URL: 

https://docs.openshift.com/container-platform/4.7/installing/installing_bare_metal/installing-bare-metal.html#ssh-agent-using_installing-bare-metal

Section Number and Name: 

Generating an SSH private key and adding it to the agent

Describe the issue: 

When user uses ed25519 keys with FIPS enabled, the ssh keys are dropped and not used and ssh to the node post booting fails with permission denied message. 

   https://bugzilla.redhat.com/show_bug.cgi?id=1962414

Suggestions for improvement: 

There should be a note in the above section mentioning that user should be aware that if FIPS is enabled ed25519 keys are not supported. 

ref:- https://access.redhat.com/solutions/3643252

Additional information:

Comment 1 Matthew Staebler 2021-06-10 18:17:07 UTC
*** Bug 1969244 has been marked as a duplicate of this bug. ***

Comment 2 Kathryn Alexander 2021-06-10 18:18:22 UTC
The PR is here: https://github.com/openshift/openshift-docs/pull/33336

Comment 3 Kathryn Alexander 2021-06-14 12:09:15 UTC
Gaoyun Pei approved this bug on the PR, I've merged it, and I'm waiting for it to go live.