Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-3417

Enable XML Signature provider in FIPS mode [rhel-8, openjdk-11]

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • rhel-sst-java
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None
    • 57,005

      When OpenJDK is configured in FIPS mode, the XML Signature provider is currently disabled, and the keystore type must be PKCS11 (/etc/pki/nssdb is used, in read-only mode).

      This is not compatible with some 3rd party applications.

      For example, it leads to the following error running Jenkins on RHEL in FIPs mode:

      java.security.KeyStoreException: FIPS mode: KeyStore must be from provider SunPKCS11-NSS-FIPS

              fferrari@redhat.com Francisco Ferrari Bihurriet
              rhn-support-mmillson Michael Millson
              Francisco Ferrari Bihurriet Francisco Ferrari Bihurriet
              David Kutalek David Kutalek
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: