Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-3562

Fips check - node scan failed with warning for 4.19 nightly payload

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Minor Minor
    • None
    • None
    • Compliance Operator
    • None
    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • False
    • Low

      Description of problem:
      Fips check - node scan failed with warning for 4.19 nightly payload:

      ---- Warning Report +----------+------------------+---------------------------------------------------------------+ | RPM NAME | EXECUTABLE NAME | STATUS | +----------+------------------+---------------------------------------------------------------+ | toolbox | /usr/bin/toolbox | go binary does not contain required tag(s): strictfipsruntime | +----------+------------------+---------------------------------------------------------------+

       

      Version-Release number of selected component (if applicable):

      4.19.0-0.nightly-2025-01-19-132507
      + registry.ci.openshift.org/ci/check-payload:latest    

      How reproducible:

      Always    

      Steps to Reproduce:

          1.Run below script against the cluster installed with above payload: https://github.com/openshift/release/blob/master/ci-operator/step-registry/fips-check/node-scan/fips-check-node-scan-commands.sh 
      Or you can also run below command on the node:
      $ podman run --privileged -ti -v /:/myroot registry.ci.openshift.org/ci/check-payload:latest scan node --root /myroot     

      Actual results:

      Fips check - node scan failed with warning for 4.19 nightly payload:

      ---- Warning Report +----------+------------------+---------------------------------------------------------------+ | RPM NAME | EXECUTABLE NAME | STATUS | +----------+------------------+---------------------------------------------------------------+ | toolbox | /usr/bin/toolbox | go binary does not contain required tag(s): strictfipsruntime | +----------+------------------+---------------------------------------------------------------+

      Expected results:

      Fips check - node scan should succeeded without errors and warnings        

      Additional info:

          

              lbragsta@redhat.com Lance Bragstad
              xiyuan@redhat.com Xiaojie Yuan
              Xiaojie Yuan Xiaojie Yuan
              Maria Simon Marcos Maria Simon Marcos
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: