Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-36133

Enable XML Signature provider in FIPS mode [rhel-8, openjdk-17]

    • java-17-openjdk-17.0.7.0.7-3.el8
    • None
    • None
    • rhel-sst-java
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None

      This bug was initially created as a copy of Bug #1940064

      I am copying this bug because: we need to fix this in OpenJDK 17 too.

      When OpenJDK is configured in FIPS mode, the XML Signature provider is currently disabled, and the keystore type must be PKCS11 (/etc/pki/nssdb is used, in read-only mode).

      This is not compatible with some 3rd party applications.

      For example, it leads to the following error running Jenkins on RHEL in FIPs mode:

      java.security.KeyStoreException: FIPS mode: KeyStore must be from provider SunPKCS11-NSS-FIPS

              fferrari@redhat.com Francisco Ferrari Bihurriet
              fferrari@redhat.com Francisco Ferrari Bihurriet
              Francisco Ferrari Bihurriet Francisco Ferrari Bihurriet
              David Kutalek David Kutalek
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: