Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-15384

Post installation of RHEL 8.8 UEFI Minimal Install with ANSSI high level profile system fails to boot

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Critical Critical
    • rhel-8.10
    • rhel-8.8.0
    • selinux-policy
    • None
    • None
    • Critical
    • rhel-security-selinux
    • ssg_security
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • Red Hat Enterprise Linux
    • None
    • None
    • None
    • Unspecified Release Note Type - Unknown
    • x86_64
    • None

      What were you trying to do that didn't work?

      Post installation of Minimal UEFI RHEL 8.8 with ANSSI-BP-028 (high) profile, system fails to boot in emergency mode

      How reproducible:

      1. Install VM using RHEL8.8 DVD ISO in UEFI mode
      2. Select DISK and configure custom layout as required by ANSSI-BP-028 (high) security profile.
      3. Select minimal software install.
      4. Select ANSSI-BP-028 (high) security profile
      5. Setup network configuration.
      6. Change root password and begin install.
      7. Reboot VM.

      Expected results

      System should boot normally without any issue

      Actual results

      System fails in emergency mode unable to mount /boot/efi

      Additional Information

      • The only reason system failed to boot as /boot/efi failed to mount.
      • System boots fine when selinux is disabled. (Booting with parameter selinux=0)
      • Same issue is observed even in old version RHEL 8.7
      • When tried manually loading vfat module shows below error:

       

       

      # modprobe -vvv vfat
      modprobe: INFO: custom logging function 0x55c3d23bff70 registered
      modprobe: INFO: Failed to insert module '/lib/modules/4.18.0-425.3.1.el8.x86_64/kernel/fs/fat/fat.ko.xz': Operation not permitted
      modprobe: ERROR: could not insert 'vfat': Operation not permitted
      modprobe: INFO: context 0x55c3d36a74a0 released
      insmod /lib/modules/4.18.0-425.3.1.el8.x86_64/kernel/fs/fat/fat.ko.xz 
      

       

       

              rhn-support-zpytela Zdenek Pytela
              rhn-support-prjagtap Pradeep Jagtap
              Zdenek Pytela Zdenek Pytela
              SSG Security QE SSG Security QE
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: