Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-91930

[RHEL-9] Add a menu entry to the boot.iso to boot with fips=1

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • lorax-templates-rhel-9.7-1.el9
    • No
    • Low
    • image-builder-1
    • 14
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • None
    • Enhancement
    • Hide
      .New boot menu entry for `fips=1` added to ISO installations

      With this update, the DVD and Boot ISO image installations provide a new boot menu entry for setting the `fips=1` kernel boot option. This simplifies the process, as enabling FIPS mode during the RHEL installation ensures that the system generates all keys with FIPS-approved algorithms and continuous monitoring tests in place. By using this boot option, you start the installation with the `fips=1` kernel parameter and you can target the system's compliance with Federal Information Processing Standards (FIPS) 140 requirements.
      Show
      .New boot menu entry for `fips=1` added to ISO installations With this update, the DVD and Boot ISO image installations provide a new boot menu entry for setting the `fips=1` kernel boot option. This simplifies the process, as enabling FIPS mode during the RHEL installation ensures that the system generates all keys with FIPS-approved algorithms and continuous monitoring tests in place. By using this boot option, you start the installation with the `fips=1` kernel parameter and you can target the system's compliance with Federal Information Processing Standards (FIPS) 140 requirements.
    • Done
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      In RHEL10 we are adding a menu to the boot.iso that sets fips=1 on the kernel cmdline when booting the anaconda installer. We should also add this to RHEL 9.8 for consistency.

              brlane@redhat.com Brian Lane
              brlane@redhat.com Brian Lane
              Brian Lane Brian Lane
              Release Test Team Release Test Team
              Mirek Jahoda Mirek Jahoda
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: