-
Epic
-
Resolution: Done
-
Critical
-
None
-
None
Make the edpm-hardened-uefi FIPS by default and also add an ansible role to optionally enforce the FIPS state on initial deployment.
There are 3 parts that need to be supported by the operators and the ansible roles:
- Deploy the right image (FIPS or non-FIPS) base don the OCP FIPS mode for greenfield deployments were the openstack baremetal operator is used.
- Configuring FIPS state on nodes. This is needed for for greenfield pre-provisioned hosts and adopted clouds that were fips enabled in 17.1 to enable scaling out or node replacement as required.
- Configure iscsid to not use MD5 when FIPS is enabled.
1.
|
FIPS by default on EDPM compute nodes | Closed | Unassigned |