-
Bug
-
Resolution: Done-Errata
-
Normal
-
rhel-9.4
-
crypto-policies-20231109-1.git0ceff7f.el9
-
None
-
None
-
1
-
rhel-sst-security-crypto
-
ssg_security
-
11
-
13
-
2
-
QE ack, Dev ack
-
False
-
-
No
-
Crypto23Q4
-
-
Pass
-
Not Needed
-
Automated
-
Release Note Not Required
-
None
https://gitlab.com/redhat-crypto/fedora-crypto-policies/-/issues/44
Takeaways:
- If /boot is empty, fips-mode-setup should abort and ask to mount it first
- In a chroot with /boot mounted as different partition from /, fips-mode-setup should add boot=UUID=... to kernel parameters
- In a chroot with /boot sharing the partition with /, fips-mode-setup should not add boot= to kernel parameters
- /boot checks should mind autofs / automount.boot / systemd-gpt-auto-generator(8)
- links to
-
RHEA-2023:120978 crypto-policies enhancement update
- mentioned on