Bug 1789609 - gnome-shell crashes when FIPS mode is enabled
Summary: gnome-shell crashes when FIPS mode is enabled
Keywords:
Status: CLOSED DUPLICATE of bug 1813384
Alias: None
Product: Fedora
Classification: Fedora
Component: gdm
Version: 31
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Ray Strode [halfline]
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-01-09 21:55 UTC by Evan McClain
Modified: 2020-03-31 14:49 UTC (History)
12 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2020-03-31 14:49:44 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Evan McClain 2020-01-09 21:55:56 UTC
Description of problem:
When FIPS mode is enabled, GDM fails to start. In jour

Version-Release number of selected component (if applicable):
20191128-2.gitcd267a5.fc31

How reproducible:


Steps to Reproduce:
1. fips-mode-setup --enable

Actual results:
GDM fails to start

Expected results:
GDM should work as expected in FIPS mode

Additional info:
gnome-shell is crashing with:
Process 1555 (gnome-shell) of user 42 dumped core.

Stack trace of thread 1555:
#0  0x00007fcc1370d968 gnutls_x509_trust_list_add_trust_file (libgnutls.so.30)
#1  0x00007fcc13681c41 gnutls_x509_trust_list_add_system_trust (libgnutls.so.30)
#2  0x00007fcbc2f75cbd g_tls_database_gnutls_populate_trust_list (libgiognutls.so)
#3  0x00007fcbc2f75ee1 g_tls_database_gnutls_initable_init (libgiognutls.so)
#4  0x00007fcc17a0edea g_initable_new_valist (libgio-2.0.so.0)
#5  0x00007fcc17a0ee9d g_initable_new (libgio-2.0.so.0)
#6  0x00007fcbc2f70ceb g_tls_backend_gnutls_get_default_database (libgiognutls.so)

Reverting crypto-policies back to 20190816-4.gitbb9bf99.fc31 gets GDM/GNOME Shell to work again under FIPS mode

Comment 1 Evan McClain 2020-03-31 14:49:44 UTC
This appears to be fixed by #1813384

*** This bug has been marked as a duplicate of bug 1813384 ***


Note You need to log in before you can comment on or make changes to this bug.