-
Bug
-
Resolution: Won't Do
-
Undefined
-
None
-
rhel-8.3.0, rhel-8.8.0
-
None
-
None
-
rhel-sst-java
-
None
-
False
-
False
-
-
None
-
None
-
None
-
None
-
If docs needed, set a value
-
-
Unspecified
-
None
-
57,005
When OpenJDK is configured in FIPS mode, the XML Signature provider is currently disabled, and the keystore type must be PKCS11 (/etc/pki/nssdb is used, in read-only mode).
This is not compatible with some 3rd party applications.
For example, it leads to the following error running Jenkins on RHEL in FIPs mode:
java.security.KeyStoreException: FIPS mode: KeyStore must be from provider SunPKCS11-NSS-FIPS