Project

Profile

Help

Task #6983

closed

Story #3778: [Epic] As a user, I can run Pulp 3 in a FIPS-enabled environment

As a developer using pulplift I have a FIPS enabled CentOS 8 environment

Added by bmbouter almost 4 years ago. Updated over 3 years ago.

Status:
CLOSED - COMPLETE
Priority:
Normal
Assignee:
-
Category:
-
Sprint/Milestone:
Start date:
Due date:
% Done:

0%

Estimated time:
Platform Release:
Groomed:
Yes
Sprint Candidate:
Yes
Tags:
Dev Environment
Sprint:
Sprint 80
Quarter:

Description

Background

We need a development environment for testing FIPS compatibility.

Solution

Add a new CentOS 8 box to pulplift that is FIPS enabled.

Actions #1

Updated by bmbouter almost 4 years ago

  • Parent issue set to #3778
Actions #2

Updated by daviddavis almost 4 years ago

  • Groomed changed from No to Yes
  • Sprint Candidate changed from No to Yes
Actions #3

Updated by daviddavis over 3 years ago

My suggestion here would be to create a centos 8 fips box and push it up to https://app.vagrantup.com/. We did this for centos 7:

https://app.vagrantup.com/pulp/boxes/centos7-fips

Here is an ansible playbook task from Foreman that will set FIPS:

https://github.com/theforeman/forklift/blob/master/roles/fips/tasks/main.yml

Note that we tried to use this ^ for pulplift but the reboot step took a while and caused later provisioning steps to sometimes fail so it's better to create a fips-enabled base box.

Actions #4

Updated by mdellweg over 3 years ago

As per CI-Meeting, it was stated that this can be established by providing a kernel parameter.

There is a cmd_line option for the libvirt vagrant provider [0] that claims to append to the kernel command line.

[0] https://github.com/vagrant-libvirt/vagrant-libvirt#domain-specific-options

Actions #5

Updated by daviddavis over 3 years ago

  • Sprint set to Sprint 78
Actions #6

Updated by rchan over 3 years ago

  • Sprint changed from Sprint 78 to Sprint 79
Actions #7

Updated by rchan over 3 years ago

  • Sprint changed from Sprint 79 to Sprint 80
Actions #8

Updated by mdepaulo@redhat.com over 3 years ago

  • Status changed from NEW to CLOSED - COMPLETE
Actions #9

Updated by bmbouter over 3 years ago

  • Sprint/Milestone set to 3.7.0

Also available in: Atom PDF