Bug 1967530

Summary: [RFE] Support enabling FIPS on the engine VM
Product: [oVirt] ovirt-ansible-collection Reporter: Yedidyah Bar David <didi>
Component: hosted-engine-setupAssignee: Asaf Rachmani <arachman>
Status: CLOSED CURRENTRELEASE QA Contact: Qin Yuan <qiyuan>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 1.2.0CC: bugs, mperina, sbonazzo
Target Milestone: ovirt-4.4.8Keywords: FutureFeature, ZStream
Target Release: ---Flags: sbonazzo: ovirt-4.4+
pm-rhel: planning_ack?
pm-rhel: devel_ack+
pm-rhel: testing_ack?
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ovirt-ansible-collection-1.5.4-1.el8ev Doc Type: Enhancement
Doc Text:
Support enabling FIPS on the Self Hosted Engine VM via ansible Previously the ansible code enabled FIPS on the Self Hosted Engine VM only if the user asked to apply an OpenSCAP profile. Starting with ovirt-ansible-collection 1.5.4 is now possible to enable FIPS without requiring an OpenSCAP profile.
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-08-19 06:23:15 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Integration RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Yedidyah Bar David 2021-06-03 10:20:10 UTC
Description of problem:

Right now, the ansible code enables FIPS on the engine VM only if the user asked to apply an OpenSCAP profile - he_apply_openscap_profile var.

We should make this possible independently, using a new var - e.g. he_enable_fips_on_vm.

Comment 1 Qin Yuan 2021-08-18 07:02:54 UTC
Move this bug to VERIFIED according to https://bugzilla.redhat.com/show_bug.cgi?id=1967533#c1

Comment 2 Sandro Bonazzola 2021-08-19 06:23:15 UTC
This bugzilla is included in oVirt 4.4.8 release, published on August 19th 2021.

Since the problem described in this bug report should be resolved in oVirt 4.4.8 release, it has been closed with a resolution of CURRENT RELEASE.

If the solution does not work for you, please open a new bug report.