Project

General

Profile

Actions

action #166304

closed

Review FIPS host settings

Added by mloviska 4 months ago. Updated 3 months ago.

Status:
Resolved
Priority:
High
Assignee:
Target version:
-
Start date:
2024-09-04
Due date:
% Done:

100%

Estimated time:

Description

FIPS_ENABLE is set in a couple of jobs, but the host does not configure kernel in order to run in FIPS mode. This seems to be a partial misconfiguration as slem aggregates seem to be configured well.

For instance:

https://openqa.suse.de/tests/15296613#
https://openqa.suse.de/tests/overview?distri=sle&version=15-SP5&build=20240903-1&groupid=417 -> no fips testing at all

We need to review our FIPS hosts in container testing in order to prepare our team for possible involvement in Vendor Affirmation testing

Actions #1

Updated by pherranz 4 months ago

  • Assignee set to pherranz
Actions #2

Updated by pherranz 4 months ago

  • Status changed from Workable to In Progress
Actions #4

Updated by pherranz 4 months ago

Also added fips tests in the Maint. Updates:
https://gitlab.suse.de/qac/qac-openqa-yaml/-/merge_requests/1812

Actions #5

Updated by pherranz 4 months ago

  • % Done changed from 0 to 100

Added FIPS tests in Maint. Updates for all archs, 15-SP4 or greater and both Podman and Docker.
https://gitlab.suse.de/qac/qac-openqa-yaml/-/merge_requests/1814

Actions #6

Updated by pherranz 4 months ago

  • Status changed from In Progress to Feedback

Seems like there's a bug in 12-SP5 containers that prevents the tests to pass. Already opened a bug:
https://bugzilla.suse.com/show_bug.cgi?id=1230531

Actions #7

Updated by pherranz 4 months ago

  • Status changed from Feedback to Resolved
Actions #8

Updated by ph03nix 3 months ago

  • Tags set to containers
Actions

Also available in: Atom PDF