Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-36133

Enable XML Signature provider in FIPS mode [rhel-8, openjdk-17]

    • java-17-openjdk-17.0.7.0.7-3.el8
    • None
    • None
    • sst_java
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None

      This bug was initially created as a copy of Bug #1940064

      I am copying this bug because: we need to fix this in OpenJDK 17 too.

      When OpenJDK is configured in FIPS mode, the XML Signature provider is currently disabled, and the keystore type must be PKCS11 (/etc/pki/nssdb is used, in read-only mode).

      This is not compatible with some 3rd party applications.

      For example, it leads to the following error running Jenkins on RHEL in FIPs mode:

      java.security.KeyStoreException: FIPS mode: KeyStore must be from provider SunPKCS11-NSS-FIPS

            fferrari@redhat.com Francisco Ferrari Bihurriet
            fferrari@redhat.com Francisco Ferrari Bihurriet
            Francisco Ferrari Bihurriet Francisco Ferrari Bihurriet
            David Kutalek David Kutalek
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: