Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1349640

Summary: virt-who dies when attempting to start with FIPS active due to md5 hashlib
Product: Red Hat Enterprise Linux 6 Reporter: Craig Donnelly <cdonnell>
Component: virt-whoAssignee: Chris Snyder <csnyder>
Status: CLOSED ERRATA QA Contact: Eko <hsun>
Severity: high Docs Contact:
Priority: unspecified    
Version: 6.9CC: ovasik, rbalakri, rjerrido, thozza
Target Milestone: rc   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: virt-who-0.18-1.el6 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-03-21 10:30:39 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1269194, 1355878, 1356036    

Description Craig Donnelly 2016-06-23 20:28:05 UTC
Description of problem:

When starting virt-who, we receive a traceback of proccess failing to start due to md5 hashlib in a FIPS enabled environment [rhsm.log]:

2016-06-22 00:05:07,963 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @esx.py:_prepare:58 - Creating ESX event filter
2016-06-22 00:05:18,322 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @virt.py:enqueue:351 - Report for config "env/cmdline" gathered, putting to queue for sending
2016-06-22 00:05:18,329 [virtwho.main ERROR] MainProcess(8927):MainThread @virtwho.py:<module>:822 - Fatal error:
Traceback (most recent call last):
  File "/usr/share/virt-who/virtwho.py", line 814, in <module>
    res = main()
  File "/usr/share/virt-who/virtwho.py", line 747, in main
    return _main(virtWho)
  File "/usr/share/virt-who/virtwho.py", line 755, in _main
    result = virtWho.run()
  File "/usr/share/virt-who/virtwho.py", line 308, in run
    if self.last_reports_hash.get(report.config.name, None) == report.hash:
  File "/usr/share/virt-who/virt/virt.py", line 229, in hash
    return hashlib.md5(json.dumps(self.serializedAssociation, sort_keys=True)).hexdigest()
ValueError: error:060800A3:digital envelope routines:EVP_DigestInit_ex:disabled for fips
2016-06-22 00:05:18,329 [virtwho.main DEBUG] MainProcess(8927):MainThread @virtwho.py:terminate:360 - virt-who is shutting down
2016-06-22 00:05:38,650 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @esx.py:_prepare:55 - Log into ESX
2016-06-22 00:05:48,965 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @esx.py:_prepare:58 - Creating ESX event filter
2016-06-22 00:06:09,303 [virtwho.env_cmdline DEBUG] Esx-1(8935):MainThread @virt.py:run:381 - Virt backend 'env/cmdline' terminated

Version-Release number of selected component (if applicable):
virt-who-0.16-8.el6.noarch

How reproducible:
I have not yet been able to reproduce in my own environment..

Steps to Reproduce:
1. Build a fips enabled host (Or enable fips on a host)
2. Install virt-who (latest for RHEL 6.8)
3. service virt-who start

Actual results:
Traceback seen above

Expected results:
virt-who running and in reporting state.

Comment 2 Rich Jerrido 2016-06-23 21:04:50 UTC
at a quick glance, patching /usr/lib/python2.7/site-packages/virtwho/virt/virt.py to change each occurrence of hashlib.md5 to hashlib.sha256 should allow virt-who to start without issue. (on my test system after making this change, virt-who starts and reports host/guest mapping with no errors) Note: I haven't tested this on a FIPS system yet.

Comment 4 Rich Jerrido 2016-06-23 21:22:28 UTC
(In reply to Rich Jerrido from comment #2)
> at a quick glance, patching
> /usr/lib/python2.7/site-packages/virtwho/virt/virt.py to change each
> occurrence of hashlib.md5 to hashlib.sha256 should allow virt-who to start
> without issue. (on my test system after making this change, virt-who starts
> and reports host/guest mapping with no errors) Note: I haven't tested this
> on a FIPS system yet.

This was tested on virt-who-0.17-1.el7.noarch. Other/different files might need to be patched for older versions of virt-who.

Comment 5 Craig Donnelly 2016-06-23 22:14:46 UTC
I was able to reproduce the customers issue on RHEL 6.8 with FIPS enabled and the version of virt-who he was using: 0.16-8.

Running virt-who in place results in the fips error as documented above in the BZ, but using Rich's method, i was able to change 3 lines inside /usr/lib/python2.7/site-packages/virtwho/virt/virt.py and get successful reporting.

Lines affected:

140         return hashlib.md5(sortedRepresentation).hexdigest()
196         return hashlib.md5(json.dumps([g.toDict() for g in self.guests], sort_keys=True)).hexdigest()
229         return hashlib.md5(json.dumps(self.serializedAssociation, sort_keys=True)).hexdigest()

I modified these to:

140         return hashlib.sha256(sortedRepresentation).hexdigest()
196         return hashlib.sha256(json.dumps([g.toDict() for g in self.guests], sort_keys=True)).hexdigest()
229         return hashlib.sha256(json.dumps(self.serializedAssociation, sort_keys=True)).hexdigest()

This resulted in a successful report to my satellite, and worked fine with FIPS enabled on the system.

Comment 6 Craig Donnelly 2016-06-23 22:17:34 UTC
Correction to previous comment, the virt-who-0.16-8 package actually installs these files to /usr/share/virt-who.

The file in question is locate at: /usr/share/virt-who/virt/virt.py.

Thanks.

Comment 7 Radek Novacek 2016-06-28 05:48:24 UTC
Using sha256 instead of md5 seems to be reasonable. I've implemented it upstream.

https://github.com/virt-who/virt-who/commit/d8159651803f1a2790891366783376c0f9204808

Please let me know if this needs to be also fixed in RHEL-7.

Comment 8 Craig Donnelly 2016-06-28 23:48:58 UTC
Radek,

This is not an issue in the current release for RHEL 7 which was 0.14-x as that code did not seem to be in place yet, but we would need to ensure the upcoming release with RHEL 7.3 incorporates this fix.

Comment 9 Radek Novacek 2016-06-30 08:24:31 UTC
It is fixed for RHEL-7.3 in virt-who-0.17-4.el7.

Comment 12 Radek Novacek 2016-10-11 14:05:09 UTC
Fixed in virt-who-0.18-1.el6.

Comment 14 Eko 2016-12-08 07:25:50 UTC
verified in virt-who-0.18-1.el6

besides hyper-v mode, virt-who can be run with FIPS for other hypervisors modes

Comment 16 errata-xmlrpc 2017-03-21 10:30:39 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2017-0675.html