Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-103374

Run rhc connect panic when FIPS enabled

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • rhel-9.7
    • rhel-9.7
    • rhc
    • None
    • No
    • Critical
    • subs-client-tools
    • 5
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Run `rhc connect --activation-key abc --organization xyz` failed when FIPS enabled.
      ```
      panic: tls: HKDF-Extract invocation failed unexpectedly

      goroutine 13 [running]:
      crypto/tls.(*cipherSuiteTLS13).extract(0x55b471f8e2c0,

      {0x0?, 0x0?, 0x0?}

      ,

      {0x0, 0x0, 0x0}

      )
      /usr/lib/golang/src/crypto/tls/key_schedule.go:99 +0x187
      crypto/tls.(*clientHandshakeStateTLS13).establishHandshakeKeys(0xc000243c50)
      /usr/lib/golang/src/crypto/tls/handshake_client_tls13.go:518 +0x2ce
      crypto/tls.(*clientHandshakeStateTLS13).handshake(0xc000243c50)
      /usr/lib/golang/src/crypto/tls/handshake_client_tls13.go:136 +0x785
      crypto/tls.(*Conn).clientHandshake(0xc000005888,

      {0x55b471cb6300, 0xc0000c0c30}

      )
      /usr/lib/golang/src/crypto/tls/handshake_client.go:372 +0x845
      crypto/tls.(*Conn).handshakeContext(0xc000005888,

      {0x55b471cb6300, 0xc00018c460}

      )
      /usr/lib/golang/src/crypto/tls/conn.go:1568 +0x3a6
      crypto/tls.(*Conn).HandshakeContext(...)
      /usr/lib/golang/src/crypto/tls/conn.go:1508
      net/http.(*persistConn).addTLS.func2()
      /usr/lib/golang/src/net/http/transport.go:1651 +0x6e
      created by net/http.(*persistConn).addTLS in goroutine 29
      /usr/lib/golang/src/net/http/transport.go:1647 +0x309
      ```
      Do not have this issue when FIPS disalbed.

      openssl-3.5.1-1.el9.x86_64
      rhc-0.2.7-1.el9.x86_64

              rh-ee-jlocash Joshua Locash
              xiaofwan@redhat.com Xiaofeng Wang
              CSI Client Tools Bugs Bot CSI Client Tools Bugs Bot
              Archana Pandey Archana Pandey
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: