Uploaded image for project: 'MicroShift'
  1. MicroShift
  2. USHIFT-1977

build microshift binary with GOEXPERIMENT=strictfipsruntime tags

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Undefined Undefined
    • openshift-4.14
    • None
    • None
    • None
    • Strategic Product Work
    • False
    • Hide

      None

      Show
      None
    • False
    • OCPSTRAT-327 - MicroShift FIPS compliance
    • uShift Sprint 246

      this experimental flag that  works only when binary build with redhat go-toolchain that was released after August 1st, 2023 [0]

      When a binary is compiled with "FIPS or Die", if the binary runs on an Operating System in FIPS mode and runs in a manner in which it does not use OpenSSL, it will exit with an error.

       

       [0] https://docs.google.com/presentation/d/1o3IowxHX6BsnxGkIInaQ0lBgnn_K5Ex8jxwCYCeNsqs/edit#slide=id.g2679cb578c3_0_17

              eslutsky Evgeny Slutsky
              eslutsky Evgeny Slutsky
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: