-
Epic
-
Resolution: Done
-
Critical
-
None
-
None
-
FIPS by default on EDPM compute nodes
-
False
-
False
-
Committed
-
No Docs Impact
-
To Do
-
RHOSSTRAT-224 - FIPS Support in OSO 18.0
-
Committed
-
Committed
-
0% To Do, 0% In Progress, 100% Done
-
Release Note Not Required
-
Rejected
-
-
-
2024Q2
-
Approved
Make the edpm-hardened-uefi FIPS by default and also add an ansible role to optionally enforce the FIPS state on initial deployment.
There are 3 parts that need to be supported by the operators and the ansible roles:
- Deploy the right image (FIPS or non-FIPS) base don the OCP FIPS mode for greenfield deployments were the openstack baremetal operator is used.
- Configuring FIPS state on nodes. This is needed for for greenfield pre-provisioned hosts and adopted clouds that were fips enabled in 17.1 to enable scaling out or node replacement as required.
- Configure iscsid to not use MD5 when FIPS is enabled.
There are no Sub-Tasks for this issue.