Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-5301

gpg commands in FIPS mode show message "gpg: out of core handler ignored in FIPS mode"

    • Icon: Bug Bug
    • Resolution: Won't Do
    • Icon: Minor Minor
    • None
    • rhel-8.8.0
    • libgcrypt
    • None
    • Moderate
    • rhel-sst-security-crypto
    • ssg_security
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None

      Description of problem:
      In RHEL 8/ RHEL 9 when you have FIPS enabled and attempt to run any gpg commands, you see a message -

      RHEL 8
      ~~~
      [root@rhel8 ~]# gpg --help
      gpg: out of core handler ignored in FIPS mode
      gpg (GnuPG) 2.2.20
      libgcrypt 1.8.5
      <snip>
      [root@rhel8 ~]# echo $?
      0
      ~~~
      RHEL 9
      ~~~
      $ gpg --help | head
      gpg: out of core handler ignored in FIPS mode
      gpg (GnuPG) 2.3.3
      libgcrypt 1.10.0-unknown
      $ echo $?
      0
      ~~~

      Based on BZ 2094013 https://bugzilla.redhat.com/show_bug.cgi?id=2094013 I think this is just an informational message, but would like some clarity if this message is needed or if it's not useful - can it be hidden?

      Version-Release number of selected component (if applicable):
      gnupg2-2.2.20-3.el8_6.x86_64
      libgcrypt-1.8.5-7.el8_6.x86_64

      gnupg2-2.3.3-2.el9_0.x86_64
      libgcrypt-1.10.0-10.el9_2.x86_64

      How reproducible:

      Steps to Reproduce:
      1. Enable FIPS mode (preferably install system and press `tab` to add the kernel command option fips=1 alternatively can use `fips-mode-setup --enable` and then reboot).
      2. Run any gpg command including `gpg --help`

      Actual results:
      The first line after running a gpg command shows `gpg: out of core handler ignored in FIPS mode`

      Expected results:
      gpg command runs without this message

              jjelen@redhat.com Jakub Jelen
              rhn-support-ckrell Charlie Krell
              Jakub Jelen Jakub Jelen
              SSG Security QE SSG Security QE
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: