#5695 [RFE] FreeIPA on FIPS enabled systems
Closed: fixed Opened by pvoborni.

FreeIPA doesn't work in FIPS mode.

Currently ipactl start prints: Cannot start IPA server in FIPS mode".

This ticket should track a progress in enabling it.


Applies only to RHEL based OSes.

master:

  • 8db5b277a079fdfe5efbd7d49311f14489cee0e8 Unify password generation across FreeIPA
  • fb7c111ac13510609e2cba14ecf88cd2ed291a4b ipa_generate_password algorithm change

master:

  • 721105c53de6fbc0abc7799ec7f48920e02089bd Generate sha256 ssh pubkey fingerprints for hosts

master:

  • 08c71703a44d8aec308781351c3a9dd4a4ba94a7 Remove is_fips_enabled checks in installers and ipactl

master:

  • 0b9b6b52d7f2e64a52ef8fd570839711311fa254 Add FIPS-token password of HTTPD NSS database

master:

  • ca457eb5ce12291f555f1bf771114d6d7d191987 Add password to certutil calls in NSSDatabase
  • b20b0489ea06931bfa7d46bdbd6623bc3f09219b custodiainstance: don't use IPA-specific CertDB

master:

  • 3372ad2766c0d182fa88c8bc28cf43477dc4cb3b Add fips_mode variable to env
  • 7292890042677ae40faa44753ebf570db6c19e7c test_config: fix tests for env.fips_mode
  • 62e884ff7f037a28a15d61cc9fa9c46e5c40cda5 check_remote_version: update exception and docstring
  • 397ca71e897b42a23ed4ef294fca367c1542a2aa replicainstall: add context manager for rpc client
  • cf25ea7e300cdada57bd964acb4393cc11ad333e FIPS: perform replica installation check

master:

  • 728a6bd4229ba170b2e94f216127b19d5d94e2ba Remove ra_db argument from CAInstance init
  • a39effed7603d66acd238e3142f4df8081ff7bc8 Remove DM password files after successfull pkispawn run

master:

  • e2d1b21c5049f68d0336dcaf3f8657b214a34e2b Remove md5_fingerprints from IPA

Please write all changes (like removal of MD5 fingerprints, etc) that affects UI or users into releases notes filed in ticket.

And also design page.

Metadata Update from @pvoborni:
- Issue assigned to tkrizek
- Issue set to the milestone: FreeIPA 4.5

master:

  • dfd560a190cb2ab13f34ed9e21c5fb5c6e793f18 Remove NSSConnection from the Python RPC module
  • 2a1494c9aef2e2b5c06e427e689787e5a2c4dc7f Move RA agent certificate file export to a different location
  • 1e89d28aaf3a0a4b48fc09a5d98262f1000c52a3 Don't run kra.configure_instance if not necessary
  • 6b074ad833a12acbd4643795b2150fa7f019d6b2 Move publishing of CA cert to cainstance creation on master
  • 0a54fac02cecad3b9e3bf8ad0c8a44df3b701857 Remove NSSConnection from Dogtag
  • afea026a5c45ce24f3bf6da499b4d334eea3ca78 Remove pkcs12 handling functions from CertDB
  • 2a9d1fb7d9dda0299c6f7cd75a715182d15e04df Remove NSSConnection from otptoken plugin
  • 76e8d7b35d110e5cf5494898950ab3607799c031 Remove ipapython.nsslib as it is not used anymore
  • 595f9b64e31dc9e4f035119e834db7e6cb152dce Workaround for certmonger's "Subject" representations
  • 51a2b1372936106ff95d5a45afc813f146653ae4 Refactor certmonger for OpenSSL certificates
  • 24b134c633390343ba76e4091fa612650976280a Added a PEMFileHandler for Custodia store
  • 5ab85b365ae886558b1f077b0d039a0d24bebfa7 Moving ipaCert from HTTPD_ALIAS_DIR

Metadata Update from @jcholast:
- Custom field affects_doc reset
- Custom field component reset
- Custom field design reset
- Custom field on_review reset
- Custom field rhbz reset
- Custom field type reset
- Issue close_status updated to: None
- Issue set to the milestone: None (was: FreeIPA 4.5)

master:

  • 770d4cda430803f8e020c57971c4dd8e802dc417 Env setitem: replace assert with exception
  • 5055b34cefd6e3f9b707aed076a49ae97b38aa3c test_config: fix fips_mode key in Env

Metadata Update from @mbasti:
- Custom field affects_doc reset
- Custom field tester adjusted to wanted

master:

  • 052de4308c64b126bee440e970be4cf8449c5ebc Fix replica with --setup-ca issues

Metadata Update from @jcholast:
- Custom field affects_doc reset

master:

  • 88fd936a761dfce099c4b03529d679256c9860d6 Remove NSPRError exception from platform tasks

Metadata Update from @mbasti:
- Custom field affects_doc reset

Metadata Update from @mbasti:
- Custom field affects_doc reset
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1125174

Metadata Update from @mbasti:
- Custom field affects_doc reset

Metadata Update from @mbasti:
- Custom field affects_doc reset
- Custom field keywords adjusted to test

master:

  • a7c8077ce8f72eee26e8f5d4362239313ffdae3d Fix CA-less upgrade

Metadata Update from @jcholast:
- Custom field affects_doc reset

Metadata Update from @mbasti:
- Custom field affects_doc reset
- Issue set to the milestone: FreeIPA 4.5

Metadata Update from @mbasti:
- Custom field affects_doc reset
- Custom field keywords reset

Metadata Update from @tkrizek:
- Custom field changelog adjusted to FreeIPA can be installed on FIPS enabled systems, Replaced MD5 fingerprints with SHA256, Added fips_mode variable to env that indicates whether FIPS is turned on the server
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata