Uploaded image for project: 'RHEL Documentation'
  1. RHEL Documentation
  2. RHELDOCS-20588

RHEL 9.6 DISA STIG security profile not adding "fips=1" to kernel

XMLWordPrintable

    • Moderate
    • rhel-sst-ccs
    • ssg_front_door
    • 2
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Red Hat Enterprise Linux
    • CCS 2025-13, CCS 2025-14, CCS 2025-15, CCS 2025-16, CCS 2025-17
    • None
    • Done
    • Done
    • Not Required

      Document link:

       

      Section number and name

      • Release Notes: Chapter 4: Important changes to external kernel parameters
      • Installation: Part II. Manually installing Red Hat Enterprise Linux
        • Chapter 7. Booting the installation media 

      Describe the issue:

      Due to changes in how the DISA STIG Security Profile handles FIPS, it is no longer enabled at first boot. To be FIPS compliant, it must be enabled before installation starts. There is no mention in either the release notes for RHEL 9.6 or in the installation documentation. If a customer required hardening they will usual pick a security profile and use that to harden the system. Now that FIPS is not added to the kernel with the security profile, customers will be out of compliance without knowing it.

       

      Impact of this issue:

      This affects anyone using a Security Profile that enables FIPS, not just the DISA STIG. This will cause customers to be out of compliance, causing them to have to rebuild any system they have built with RHEL 9.6, expecting the Security Profile to have enabled it.

      Suggestions for improvement:

      Add a part in both the RHEL Release Notes and the Installation documentation stating to be FIPS compliant you must enable FIPS in the kernel before the installation GUI startts.

              jafiala@redhat.com Jan Fiala
              rhn-support-mralph Mike Ralph
              Gabriela Fialova, Mayur Patil
              Gabriela Fialova Gabriela Fialova
              Votes:
              2 Vote for this issue
              Watchers:
              14 Start watching this issue

                Created:
                Updated:
                Resolved: