Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-45618

make fips-mode-setup scarier [rhel-9]

    • crypto-policies-20240815-1.gite217f03.el9
    • None
    • None
    • 1
    • rhel-sst-security-crypto
    • ssg_security
    • 26
    • 0.5
    • False
    • Hide

      None

      Show
      None
    • No
    • Crypto24Q3
    • Hide

      AC1) fips-mode-setup --enable displays a 15 seconds countdown and an extra warning, stating that this operation cannot be undone and reinstalling with fips=1 is the recommended way to enable fips mode, it is possible to cancel within 15 seconds (then no changes are made), after that FIPS is enabled correctly.

      AC2) fips-mode-setup --disable displays a 15 seconds countdown and an extra warning, stating that this operation cannot be undone and is not supported, it is possible to cancel within 15 second (then no changes are made), after that FIPS is disabled correctly.

      AC3) Installation in FIPS mode still works flawlessly.

       

      Show
      AC1) fips-mode-setup --enable displays a 15 seconds countdown and an extra warning, stating that this operation cannot be undone and reinstalling with fips=1 is the recommended way to enable fips mode, it is possible to cancel within 15 seconds (then no changes are made), after that FIPS is enabled correctly. AC2) fips-mode-setup --disable displays a 15 seconds countdown and an extra warning, stating that this operation cannot be undone and is not supported, it is possible to cancel within 15 second (then no changes are made), after that FIPS is disabled correctly. AC3) Installation in FIPS mode still works flawlessly.  
    • Pass
    • Enabled
    • Automated
    • Unspecified Release Note Type - Unknown
    • None

      As described in RHEL-28848, fips-mode-setup should warn the user that neither enabling and disabling FIPS mode are reversible operations, and reinstalling is the recommended way. Might as well throw in a scary warning and a countdown.

              asosedki@redhat.com Alexander Sosedkin
              asosedki@redhat.com Alexander Sosedkin
              Alexander Sosedkin Alexander Sosedkin
              Ondrej Moris Ondrej Moris
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: