MD5 is a blacklisted crypto in FIPS enabled Kernels
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tripleo |
Incomplete
|
Medium
|
Unassigned |
Bug Description
When enabling a FIPS Kernel, MD5 hashing operations are blocked:
os-collect-config: Traceback (most recent call last):
os-collect-config: File "/usr/bin/
os-collect-config: sys.exit(
os-collect-config: File "/usr/lib/
os-collect-config: config_hash = getfilehash(
os-collect-config: File "/usr/lib/
os-collect-config: m = hashlib.md5()
os-collect-config: ValueError: error:060800A3:
MD5 is blocked, as it is susceptible to collision attacks.
Changed in tripleo: | |
importance: | Undecided → Medium |
status: | New → Triaged |
Changed in tripleo: | |
milestone: | none → ocata-3 |
Changed in tripleo: | |
milestone: | ocata-3 → none |
Changed in tripleo: | |
milestone: | none → pike-1 |
no longer affects: | puppet-tripleo |
Changed in tripleo: | |
milestone: | pike-1 → pike-2 |
Changed in tripleo: | |
milestone: | pike-2 → pike-3 |
Changed in tripleo: | |
milestone: | pike-3 → pike-rc1 |
Changed in tripleo: | |
milestone: | pike-rc1 → queens-1 |
Changed in tripleo: | |
milestone: | queens-1 → queens-2 |
Changed in tripleo: | |
milestone: | queens-2 → queens-3 |
Changed in tripleo: | |
milestone: | queens-3 → queens-rc1 |
Changed in tripleo: | |
milestone: | queens-rc1 → rocky-1 |
Changed in tripleo: | |
milestone: | rocky-1 → rocky-2 |
Changed in tripleo: | |
milestone: | rocky-2 → rocky-3 |
Changed in tripleo: | |
milestone: | rocky-3 → rocky-rc1 |
Changed in tripleo: | |
milestone: | rocky-rc1 → stein-1 |
Changed in tripleo: | |
milestone: | stein-1 → stein-2 |
Changed in tripleo: | |
milestone: | stein-2 → stein-3 |
Changed in tripleo: | |
milestone: | stein-3 → train-1 |
Changed in tripleo: | |
milestone: | train-1 → train-2 |
Changed in tripleo: | |
milestone: | train-2 → train-3 |
Changed in tripleo: | |
milestone: | train-3 → ussuri-1 |
Changed in tripleo: | |
milestone: | ussuri-1 → ussuri-2 |
Changed in tripleo: | |
milestone: | ussuri-2 → ussuri-3 |
Changed in tripleo: | |
milestone: | ussuri-3 → ussuri-rc3 |
Changed in tripleo: | |
milestone: | ussuri-rc3 → victoria-1 |
Changed in tripleo: | |
milestone: | victoria-1 → victoria-3 |
Note this bug has a wider impact, as it means any use of MD5 throughout OpenStack will be blocked.