Bug 2179891
| Summary: | Unable to run fipsinstall | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Jan Grulich <jgrulich> |
| Component: | openssl | Assignee: | Dmitry Belyavskiy <dbelyavs> |
| Status: | CLOSED WONTFIX | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 38 | CC: | cllang, crypto-team, dbelyavs, mspacek, mturk, sahana, tm |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-03-20 11:08:19 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Jan Grulich
2023-03-20 10:53:50 UTC
It looks this patch https://src.fedoraproject.org/rpms/openssl/blob/f38/f/0034.fipsinstall_disable.patch has been applied in F38 and Rawhide, while it doesn't exist in Fedora 37. I guess it was brought from RHEL (during sync) and it's just missing a condition to avoid using it on Fedora? This is expected, we're shipping the same patches RHEL uses in Fedora. Please switch the entire Fedora system into FIPS mode using `fips-mode-setup --enable`. Note that we do not FIPS-certify Fedora, and it also currently lags behind some of the FIPS compliance patches applied to RHEL (although we will eventually be pushing all FIPS patches into Fedora as well). We do not plan to conditionally apply the FIPS patches to RHEL only. |