Bug 2085401

Summary: Specifying the openssl config file explicitly causes provider initialisation to fail in FIPS mode
Product: Red Hat Enterprise Linux 9 Reporter: Dmitry Belyavskiy <dbelyavs>
Component: opensslAssignee: Dmitry Belyavskiy <dbelyavs>
Status: CLOSED DUPLICATE QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: medium Docs Contact:
Priority: medium    
Version: 9.0CC: dbelyavs, hkario, ssorce
Target Milestone: rcKeywords: Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-05-13 14:10:10 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dmitry Belyavskiy 2022-05-13 09:13:56 UTC
This bug was initially created as a copy of Bug #2083274

I am copying this bug because: 



Description of problem:
When openssl is used with explicitly specified config file in FIPS mode, the provider loading fails

Version-Release number of selected component (if applicable):
openssl-3.0.1-27.el9

How reproducible:
always

Steps to Reproduce:
1. openssl genpkey -algorithm rsa -out cakey.pem
2. openssl req -config /etc/pki/tls/openssl.cnf -passout pass:securepass -new -x509 -days 3650 -extensions v3_ca -keyout cakey.pem -out cacert.pem             -subj "/C=XX/ST=mystate/L=mytown/O=myorganisation/OU=myou/CN=myname/emailAddress=myemail/"

Actual results:
005C9966037F0000:error:0700006D:configuration file routines:module_run:module initialization error:crypto/conf/conf_mod.c:243:module=providers, value=provider_sect retcode=-1

Expected results:
CSR created

Additional info:

Comment 3 Dmitry Belyavskiy 2022-05-13 14:10:10 UTC

*** This bug has been marked as a duplicate of bug 2083274 ***