Red Hat Bugzilla – Bug 851504
Missing *.hmac files in FIPS initramfs
Last modified: 2013-02-28 23:11:34 EST
Created attachment 606836 [details]
Proposed patch for F17
+++ This bug was initially created as a clone of Bug #851185 +++
Description of problem:
Seems that dracut doesn not put FIPS *.hmac filer in initramfs, so fipscheck verification cannot succeed.
Version-Release number of selected component (if applicable):
Easy to test, just install crypt module dracut -f -a crypt and try to run cryptsetup in initramfs "cryptsetup status x" - it will fail with FIPS check failed.
Please note that attached slightly differs from upstream in fips module, this line:
+ inst_libdir_file libssl.so.10
(if using only libssl.so it doesn't install proper symlinks in F17...)
Confirmed fips mode is working again with the latest kernel and these patches. Thanks!
(this is not yet in build, setting to assigned for now)
dracut-018-60.git20120927.fc16 has been submitted as an update for Fedora 16.
dracut-018-105.git20120927.fc17 has been submitted as an update for Fedora 17.
* should fix your issue,
* was pushed to the Fedora 17 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing dracut-018-105.git20120927.fc17'
as soon as you are able to.
Please go to the following url:
then log in and leave karma (feedback).
dracut-018-105.git20120927.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.