Bug 2083274

Summary: Specifying the openssl config file explicitly causes provider initialisation to fail in FIPS mode
Product: Red Hat Enterprise Linux 9 Reporter: Alicja Kario <hkario>
Component: opensslAssignee: Dmitry Belyavskiy <dbelyavs>
Status: CLOSED CURRENTRELEASE QA Contact: Alicja Kario <hkario>
Severity: medium Docs Contact:
Priority: high    
Version: 9.0CC: cllang, dbelyavs, kanderso, ssorce
Target Milestone: rcKeywords: Triaged, ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: openssl-3.0.1-29.el9 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of:
: 2085500 (view as bug list) Environment:
Last Closed: 2023-06-05 15:56:12 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2085500    

Description Alicja Kario 2022-05-09 15:21:43 UTC
Description of problem:
When openssl is used with explicitly specified config file in FIPS mode, the provider loading fails

Version-Release number of selected component (if applicable):
openssl-3.0.1-27.el9

How reproducible:
always

Steps to Reproduce:
1. openssl genpkey -algorithm rsa -out cakey.pem
2. openssl req -config /etc/pki/tls/openssl.cnf -passout pass:securepass -new -x509 -days 3650 -extensions v3_ca -keyout cakey.pem -out cacert.pem             -subj "/C=XX/ST=mystate/L=mytown/O=myorganisation/OU=myou/CN=myname/emailAddress=myemail/"

Actual results:
005C9966037F0000:error:0700006D:configuration file routines:module_run:module initialization error:crypto/conf/conf_mod.c:243:module=providers, value=provider_sect retcode=-1

Expected results:
CSR created

Additional info:

Comment 4 Dmitry Belyavskiy 2022-05-13 14:10:10 UTC
*** Bug 2085401 has been marked as a duplicate of this bug. ***

Comment 7 Clemens Lang 2023-06-05 15:56:12 UTC
RHEL 9.1 contains openssl-3.0.1-43.el9_0.