-
Bug
-
Resolution: Duplicate
-
Undefined
-
None
-
4.16
-
Critical
-
None
-
False
-
Description of problem:
Upgrade from OCP 4.15 to 4.16 will fail when fips enabled
Version-Release number of selected component (if applicable):
4.16.0-0.nightly-multi-2024-10-15-034912
How reproducible:
Always
Steps to Reproduce:
1. Setup a OCP 4.15 cluster with fips enabled 2. Upgrade to latest 4.16 nightly version 3.
Actual results:
[jianl@jianl-thinkpadt14gen4 must-gather]$ omg get pod -n openshift-cluster-version NAME READY STATUS RESTARTS AGE cluster-version-operator-fc546cfc9-5d4pr 0/1 Running 22 2h22m version--sjfwc-krw4p 0/1 Succeeded 0 2h22m [jianl@jianl-thinkpadt14gen4 must-gather]$ omg logs pod/cluster-version-operator-fc546cfc9-5d4pr -n openshift-cluster-version | grep -E "Failed" 2024-10-15T14:13:25.809409494Z I1015 14:13:25.809332 1 start.go:256] Failed to initialize from payload; shutting down: the config map openshift-config-managed/release-verification has an invalid key "verifier-public-key-redhat" that must be a GPG public key: openpgp: invalid data: tag byte does not have MSB set: openpgp: invalid data: tag byte does not have MSB set [jianl@jianl-thinkpadt14gen4 must-gather]$
Expected results:
Can upgrade to OCP 4.16
Additional info:
Some Failed Prow Jobs: https://qe-private-deck-ci.apps.ci.l2s4.p1.openshiftapps.com/view/gs/qe-private-deck/logs/periodic-ci-openshift-openshift-tests-private-release-4.16-multi-nightly-4.16-upgrade-from-stable-4.15-gcp-ipi-xpn-fips-amd-f28/1846114020063449088 https://qe-private-deck-ci.apps.ci.l2s4.p1.openshiftapps.com/view/gs/qe-private-deck/logs/periodic-ci-openshift-openshift-tests-private-release-4.16-multi-nightly-4.16-upgrade-from-stable-4.15-aws-ipi-byo-kms-etcd-encryption-fips-amd-f28/1845231798867464192 https://gcsweb-qe-private-deck-ci.apps.ci.l2s4.p1.openshiftapps.com/gcs/qe-private-deck/logs/periodic-ci-openshift-openshift-tests-private-release-4.16-multi-nightly-4.16-upgrade-from-stable-4.15-aws-ipi-imdsv2-fips-amd-f28/1845449737008844800/
- is related to
-
OCPBUGS-43467 Load Red Hat keys in FIPS mode with Go 1.22
- Closed