Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 633865 - [FIPS140][RHEL6] kernel module should failed to load if DSA signature check fails when FIPS mode is on [rhel-6.0.z]
[FIPS140][RHEL6] kernel module should failed to load if DSA signature check f...
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: kernel (Show other bugs)
6.1
All Linux
urgent Severity urgent
: rc
: ---
Assigned To: Frantisek Hrbata
yanfu,wang
: ZStream
Depends On: 625914
Blocks:
  Show dependency treegraph
 
Reported: 2010-09-14 10:49 EDT by RHEL Product and Program Management
Modified: 2013-01-10 22:18 EST (History)
16 users (show)

See Also:
Fixed In Version: kernel-2.6.32-71.1.1.el6
Doc Type: Bug Fix
Doc Text:
Previously, a kernel module not shipped by Red Hat was successfully loaded when the FIPS boot option was enabled. With this update, kernel self-integrity is improved by rejecting to load kernel modules which are not shipped by Red Hat when the FIPS boot option is enabled.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2010-11-10 14:09:59 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2010:0842 normal SHIPPED_LIVE Important: kernel security and bug fix update 2010-11-22 14:34:20 EST

  None (edit)
Description RHEL Product and Program Management 2010-09-14 10:49:44 EDT
This bug has been copied from bug #625914 and has been proposed
to be backported to 6.0 z-stream (EUS).
Comment 3 Frantisek Hrbata 2010-09-16 06:53:17 EDT
in 2.6.32-71.1.1.el6
Comment 6 errata-xmlrpc 2010-11-10 14:09:59 EST
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2010-0842.html
Comment 7 Martin Prpič 2010-11-11 06:47:59 EST
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
Previously, a kernel module not shipped by Red Hat was successfully loaded when the FIPS boot option was enabled. With this update, kernel self-integrity is improved by rejecting to load kernel modules which are not shipped by Red Hat when the FIPS boot option is enabled.

Note You need to log in before you can comment on or make changes to this bug.