• Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • None
    • 4.18
    • RHCOS
    • None
    • False
    • Hide

      None

      Show
      None
    • Hide
      * Previously, explicitly disabling FIPS mode with `fips=0` caused some systemd services, that assume FIPS mode was requested, to run and consequently fail. This issue resulted in {op-system} failing to boot. With this release, the relevant systemd services now only run if FIPS mode is enabled by specifying `fips=1`. As a result, {op-system} now correctly boots without FIPS mode enabled when `fips=0` is specified. (link:https://issues.redhat.com/browse/OCPBUGS-39536[*OCPBUGS-39536*])
      Show
      * Previously, explicitly disabling FIPS mode with `fips=0` caused some systemd services, that assume FIPS mode was requested, to run and consequently fail. This issue resulted in {op-system} failing to boot. With this release, the relevant systemd services now only run if FIPS mode is enabled by specifying `fips=1`. As a result, {op-system} now correctly boots without FIPS mode enabled when `fips=0` is specified. (link: https://issues.redhat.com/browse/OCPBUGS-39536 [* OCPBUGS-39536 *])
    • Bug Fix
    • Done

      Adding fips=0 to the kernel params in RHOS results in rhcos-fips-finish failing and dracut dropping the the emergency shell

       

      Sep 04 09:12:15 localhost.localdomain systemd[1]: Starting Finish FIPS mode setup...
      Sep 04 09:12:15 localhost.localdomain systemd[1]: rhcos-fips-finish.service: Main process exited, code=exited, status=1/FAILURE
      Sep 04 09:12:15 localhost.localdomain rhcos-fips[1000]: FIPS mode is not enabled.
      Sep 04 09:12:15 localhost.localdomain systemd[1]: rhcos-fips-finish.service: Failed with result 'exit-code'.
      Sep 04 09:12:15 localhost.localdomain systemd[1]: Failed to start Finish FIPS mode setup.
      Sep 04 09:12:15 localhost.localdomain systemd[1]: rhcos-fips-finish.service: Triggering OnFailure= dependencies.

      From what I can see rhcos-fips-finish shouldn't be getting triggered at all?

              dhiggins@redhat.com Derek Higgins
              dhiggins@redhat.com Derek Higgins
              Michael Nguyen Michael Nguyen
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: