Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-131901

"basic hdkf test(hmac(sha256-ni)): hkdf_extract failed with -22" with fips=1 in RHEL-9.7

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Critical Critical
    • None
    • rhel-9.7.z
    • kernel / Crypto
    • None
    • Moderate
    • FutureFeature
    • Customer Facing, Customer Reported
    • rhel-kernel-security
    • 0
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • x86_64
    • None

      What were you trying to do that didn't work?

      FIPS mode is enabled.

      What is the impact of this issue to you?

      Here is customer statement in the Customer Case.

      After 9.7 upgrade, "kernel: basic hdkf test(hmac(sha256-ni)): hkdf_extract failed with -22" is logged on boot.
      
      Describe the impact to you or the business
      All updates, including security updates, are on hold pending a resolution. Will not search for additional complications that may be caused by failure of this basic cryto function to work, since it is used for TLS 1.3
      
      In what environment are you experiencing this behavior?
      Running RHEL 9.7 and using TLS 1.3.
      
      How frequently does this behavior occur? Does it occur repeatedly or at certain times?
      Initial error logged on every boot.

      Please provide the package NVR for which the bug is seen:

      kernel-5.14.0-611.8.1.el9_7

      How reproducible is this bug?:

      Seen during a boot

      Steps to reproduce

      1.  
      2.  
      3.  

      Expected results

      hkdf_extract failed with -22

      Actual results

      No failed on hkdf_extract
       
       
       

       

              zhiren.xu Herbert Xu
              rhn-support-jaeshin Jay Shin
              Herbert Xu Herbert Xu
              Security Kernel Security Kernel
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated: