Bug 1349640
| Summary: | virt-who dies when attempting to start with FIPS active due to md5 hashlib | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Craig Donnelly <cdonnell> |
| Component: | virt-who | Assignee: | Chris Snyder <csnyder> |
| Status: | CLOSED ERRATA | QA Contact: | Eko <hsun> |
| Severity: | high | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 6.9 | CC: | ovasik, rbalakri, rjerrido, thozza |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | virt-who-0.18-1.el6 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-03-21 10:30:39 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1269194, 1355878, 1356036 | ||
at a quick glance, patching /usr/lib/python2.7/site-packages/virtwho/virt/virt.py to change each occurrence of hashlib.md5 to hashlib.sha256 should allow virt-who to start without issue. (on my test system after making this change, virt-who starts and reports host/guest mapping with no errors) Note: I haven't tested this on a FIPS system yet. (In reply to Rich Jerrido from comment #2) > at a quick glance, patching > /usr/lib/python2.7/site-packages/virtwho/virt/virt.py to change each > occurrence of hashlib.md5 to hashlib.sha256 should allow virt-who to start > without issue. (on my test system after making this change, virt-who starts > and reports host/guest mapping with no errors) Note: I haven't tested this > on a FIPS system yet. This was tested on virt-who-0.17-1.el7.noarch. Other/different files might need to be patched for older versions of virt-who. I was able to reproduce the customers issue on RHEL 6.8 with FIPS enabled and the version of virt-who he was using: 0.16-8. Running virt-who in place results in the fips error as documented above in the BZ, but using Rich's method, i was able to change 3 lines inside /usr/lib/python2.7/site-packages/virtwho/virt/virt.py and get successful reporting. Lines affected: 140 return hashlib.md5(sortedRepresentation).hexdigest() 196 return hashlib.md5(json.dumps([g.toDict() for g in self.guests], sort_keys=True)).hexdigest() 229 return hashlib.md5(json.dumps(self.serializedAssociation, sort_keys=True)).hexdigest() I modified these to: 140 return hashlib.sha256(sortedRepresentation).hexdigest() 196 return hashlib.sha256(json.dumps([g.toDict() for g in self.guests], sort_keys=True)).hexdigest() 229 return hashlib.sha256(json.dumps(self.serializedAssociation, sort_keys=True)).hexdigest() This resulted in a successful report to my satellite, and worked fine with FIPS enabled on the system. Correction to previous comment, the virt-who-0.16-8 package actually installs these files to /usr/share/virt-who. The file in question is locate at: /usr/share/virt-who/virt/virt.py. Thanks. Using sha256 instead of md5 seems to be reasonable. I've implemented it upstream. https://github.com/virt-who/virt-who/commit/d8159651803f1a2790891366783376c0f9204808 Please let me know if this needs to be also fixed in RHEL-7. Radek, This is not an issue in the current release for RHEL 7 which was 0.14-x as that code did not seem to be in place yet, but we would need to ensure the upcoming release with RHEL 7.3 incorporates this fix. It is fixed for RHEL-7.3 in virt-who-0.17-4.el7. Fixed in virt-who-0.18-1.el6. verified in virt-who-0.18-1.el6 besides hyper-v mode, virt-who can be run with FIPS for other hypervisors modes Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2017-0675.html |
Description of problem: When starting virt-who, we receive a traceback of proccess failing to start due to md5 hashlib in a FIPS enabled environment [rhsm.log]: 2016-06-22 00:05:07,963 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @esx.py:_prepare:58 - Creating ESX event filter 2016-06-22 00:05:18,322 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @virt.py:enqueue:351 - Report for config "env/cmdline" gathered, putting to queue for sending 2016-06-22 00:05:18,329 [virtwho.main ERROR] MainProcess(8927):MainThread @virtwho.py:<module>:822 - Fatal error: Traceback (most recent call last): File "/usr/share/virt-who/virtwho.py", line 814, in <module> res = main() File "/usr/share/virt-who/virtwho.py", line 747, in main return _main(virtWho) File "/usr/share/virt-who/virtwho.py", line 755, in _main result = virtWho.run() File "/usr/share/virt-who/virtwho.py", line 308, in run if self.last_reports_hash.get(report.config.name, None) == report.hash: File "/usr/share/virt-who/virt/virt.py", line 229, in hash return hashlib.md5(json.dumps(self.serializedAssociation, sort_keys=True)).hexdigest() ValueError: error:060800A3:digital envelope routines:EVP_DigestInit_ex:disabled for fips 2016-06-22 00:05:18,329 [virtwho.main DEBUG] MainProcess(8927):MainThread @virtwho.py:terminate:360 - virt-who is shutting down 2016-06-22 00:05:38,650 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @esx.py:_prepare:55 - Log into ESX 2016-06-22 00:05:48,965 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @esx.py:_prepare:58 - Creating ESX event filter 2016-06-22 00:06:09,303 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @virt.py:run:381 - Virt backend 'env/cmdline' terminated Version-Release number of selected component (if applicable): virt-who-0.16-8.el6.noarch How reproducible: I have not yet been able to reproduce in my own environment.. Steps to Reproduce: 1. Build a fips enabled host (Or enable fips on a host) 2. Install virt-who (latest for RHEL 6.8) 3. service virt-who start Actual results: Traceback seen above Expected results: virt-who running and in reporting state.