Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-21738

VolSync Konflux - Enterprise contract on File based catalog failing some FIPS checks

XMLWordPrintable

    • Security & Compliance
    • False
    • Hide

      None

      Show
      None
    • False
    • Critical
    • None

      Enterprise contract is failing for file based catalog builds for OCP 4.14 and 4.16 (the others 4.15, 4.17-4.19 are ok)

       

      FIPS checks (check-payload on the volsync container image) are failing for:

      • OCP 4.14 - this is because of diskrsync.  We have an exception already for this as this utility doesn't use any network utiltities and will build statically.  However the exception wasn't built into the OCP 4.14 configuration of check-payload because at the time CVP was only running the checks against an OCP 4.15.
      • OCP 4.16 - for some reason the check-payload is failing for only OCP 4.16.

      Getting error:

      ---- Failure Report Operator Name,Executable Name,Status volsync-container,/etc/redhat-release,operating system is not FIPS certified F0619 19:45:41.171824 434 main.go:294] Error: run failed check-payload scan failed for quay.io/redhat-user-workloads/volsync-tenant/volsync-0-13@sha256:4318a1af43e17bfa865594eae08d63e2aae705889ed35c39c9eece14f67d443e

       

              tflower@redhat.com Tesshu Flower
              tflower@redhat.com Tesshu Flower
              Thuy Nguyen Thuy Nguyen
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: