Bug 1913441 - Candlepin will not install in FIPS mode
Summary: Candlepin will not install in FIPS mode
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Candlepin
Classification: Community
Component: candlepin
Version: 3.1
Hardware: All
OS: Linux
high
medium
Target Milestone: ---
: ---
Assignee: ojanus
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1929681
TreeView+ depends on / blocked
 
Reported: 2021-01-06 18:57 UTC by James Shewey
Modified: 2021-04-12 16:53 UTC (History)
5 users (show)

Fixed In Version: candlepin-4.0.1-1
Clone Of:
: 1929681 (view as bug list)
Environment:
Last Closed: 2021-04-12 16:53:23 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Foreman Issue Tracker 31895 0 Normal New Candlepin package incorrectly signed for FIPS environment 2021-02-16 16:39:04 UTC
Github candlepin candlepin pull 2931 0 None open 1913441: Candlepin will not install in FIPS mode 2021-02-16 15:23:28 UTC
Github candlepin candlepin pull 2932 0 None open [3.1]1913441: Candlepin will not install in FIPS mode 2021-02-16 15:23:28 UTC

Description James Shewey 2021-01-06 18:57:01 UTC
Description of problem:
 
On CentOS 8, if you attempt to install candlepin in FIPS-140-2 mode, the installation will fail

Version-Release number of selected component (if applicable): candlepin-3.1.22-1.el8.noarch

How reproducible: Always


Steps to Reproduce:
1. Before installing the RPM, ensure the system is in FIPS-140-2 mode using the command "fips-mode-setup --enable"
2. Reboot
3. Install the RPM

Actual results:

The installation fails with the error "does not verify: no digest"

Expected results:

The RPM installs successfully

Additional info:

As a workaround, you can temporarily disable FIPS-140-2 mode to install candlepin or install with the --nodigest --nofiledigest switches per https://access.redhat.com/solutions/4460971

Package was downloaded from baseurl=https://fedorapeople.org/groups/katello/releases/yum/3.18/candlepin/el8/

Comment 1 Jonathon Turel 2021-02-16 16:39:04 UTC
Connecting redmine issue https://projects.theforeman.org/issues/31895 from this bug


Note You need to log in before you can comment on or make changes to this bug.