Red Hat Bugzilla – Bug 1004102
NSS needs to conform to new FIPS standard. [rhel-7.0.0]
Last modified: 2015-03-05 03:27:29 EST
This bug should also be used to make sure that a -fips subpackage is created along with the fixes to the self-test.
Actually the -fips subpackage will not be created. The FIPS mode initialization should be based on this table: | /etc/system-fips | no /etc/system-fips ---------------------+------------------+---------------------- kernel fips flag | enforce | no test/no fips ---------------------+------------------+------ no kernel fips flag | test | no test test = verify checksums only enforce = verify checksums & abort in case of failure
fixed in nss-softokn-3.16.2-3.el7
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-0364.html