-
Bug
-
Resolution: Done-Errata
-
Critical
-
4.13, 4.12, 4.11, 4.10
-
No
-
Rejected
-
False
-
-
-
Bug Fix
-
Done
Because the installer generates some of the keys that will remain present in the cluster (e.g. the signing key for the admin kubeconfig), it should also run in an environment where FIPS is enabled.
Because it is very easy to fail to notice that the keys were generated in a non-FIPS-certified environment, we should enforce this by checking that fips_enabled is true if the target cluster is to have FIPS enabled.
walters@redhat.com has a patch for this.
- causes
-
OCMUI-1878 Provide FIPS-capable installer download links
- Closed
- is related to
-
OCPBUGS-15861 openshift-baremetal-installer should not link against libvirt
- Closed
- relates to
-
CORS-3418 Ship static build of openshift-installer
- Closed
- links to
-
RHEA-2024:0041 OpenShift Container Platform 4.16.z bug fix update