Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-104075

[RHEL-10] Add a menu entry to the boot.iso to boot with fips=1

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • rhel-10.1
    • rhel-10.0
    • osbuild
    • No
    • Low
    • image-builder-1
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • None
    • Enhancement
    • Hide
      .`image-installer` provides a new boot menu entry for `fips=1`

      In this update, the `image-installer` ISO image type provides a new boot menu entry for setting the `fips=1` kernel boot option during installation. This simplifies the process, as in RHEL 10, you cannot switch an installed system to FIPS mode, and you must add `fips=1` to the kernel command line when starting the installation. By setting `fips=1` for the installation, you can target the system's compliance with Federal Information Processing Standards (FIPS) 140 requirements.
      Show
      .`image-installer` provides a new boot menu entry for `fips=1` In this update, the `image-installer` ISO image type provides a new boot menu entry for setting the `fips=1` kernel boot option during installation. This simplifies the process, as in RHEL 10, you cannot switch an installed system to FIPS mode, and you must add `fips=1` to the kernel command line when starting the installation. By setting `fips=1` for the installation, you can target the system's compliance with Federal Information Processing Standards (FIPS) 140 requirements.
    • Done
    • Done
    • Done
    • Unspecified
    • None

      In RHEL10 it is no longer possible to switch an installed system to FIPS, it needs to be done during install with fips=1 set on the kernel cmdline when booting the installer from the boot.iso – this is documented, but to make it easier and more visible to users we should add a new boot menu entry to the boot.iso menu.

      This menu entry should also be added for osbuild-composer produced installer isos.

              brlane@redhat.com Brian Lane
              brlane@redhat.com Brian Lane
              Osbuilders Bot Account Osbuilders Bot Account
              Release Test Team Release Test Team
              Mirek Jahoda Mirek Jahoda
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: