-
Bug
-
Resolution: Unresolved
-
Major
-
rhel-9.0.0
-
None
-
Important
-
4
-
rhel-sst-idm-ipa
-
ssg_idm
-
None
-
False
-
-
Yes
-
2024-Q1-Bravo-S1, 2024-Q1-Bravo-S3, 2024-Q1-Bravo-S4, 2024-Q1-Bravo-S5
-
None
-
None
-
Known Issue
-
-
Done
-
-
All
-
None
Description of problem:
The RHEL 9 client configured for FIPS fails to join an IPA realm if the IPA server was created in FIPS.
The RHEL 9 client NOT configured for FIPS will successfully join an IPA realm if the IPA server was created in FIPS.
The RHEL 9 client configured for FIPS will successfully an IPA realm of the IPA server was not created it FIPS.
Version-Release number of selected component (if applicable):
ipa-client-4.9.8-7.el9_0.x86_64
How reproducible:
To replicate the problem, follow the following instructions. I have replicated this issue many times. We have hundreds of nodes set with FIPS enabled. Only the RHEL 9.0 systems will not join the IPA realm.
1. Create a RHEL 9.0 system
2. Enable FIPS: fips-mode-setup --enable
3. Reboot
4. login
5. ipa-client-setup -N (enter username, password, etc.)
6. The node fails to join the IPA realm
7. Disable FIPS: fips-mode-setup --disable
6. Reboot
7. Login
8. ipa-client-setup -N (enter username, password, etc.)
9. Node joins the IPA realm with no error.
Steps to Reproduce:
1.
2.
3.
Actual results:
Expected results:
Additional info:
- external trackers