Uploaded image for project: 'CoreOS OCP'
  1. CoreOS OCP
  2. COS-3414

Build ignition with GOEXPERIMENT=strictfipsruntime

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • None
    • 3
    • False
    • Hide

      None

      Show
      None
    • False
    • Ready to Pick, CoreOS West - 276, CoreOS West - Sprint 277, CoreOS West - Sprint 278
    • 0

      It was recommended to build ignition with GOEXPERIMENT=strictfipsruntime

       

      Context slack thread:

      https://redhat-internal.slack.com/archives/C04668B0XK2/p1751425524378039

       

      TLDR; while debugging an issue with a fips.enable test failure, we discovered that golang 1.22 requires openssl fips shared object to be present in the initrd. openssl-fips-provider-so was changed to a subpackage at a later version and it was missing in the rhcos initrd.  David Benoit from the go toolset team recommended we bulid with GOEXPERIMENT=strictfipsruntime for ignition.

              rh-ee-spresti Steven Presti
              mnguyen@redhat.com Michael Nguyen
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: