Project

General

Profile

Bug #23130

unable to install theforeman-foreman_scap_client in FIPS-enabled environment

Added by Peter Ondrejka over 3 years ago. Updated about 3 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Target version:
-
Difficulty:
Triaged:
No
Bugzilla link:
Pull request:
Fixed in Releases:
Found in Releases:

Description

Following the installation steps from https://www.theforeman.org/plugins/foreman_openscap/0.8/index.html#2.Installation, installation of puppet-foreman_scap_client in step 2.3 fails as follows:

]# puppet module install theforeman-foreman_scap_client -d
Debug: Runtime environment: puppet_version=5.5.0, ruby_version=2.4.3, run_mode=user, default_encoding=UTF-8
Notice: Preparing to install into /etc/puppetlabs/code/environments/production/modules ...
Debug: Facter: searching for custom fact "fips_enabled".
Debug: Facter: searching for fips_enabled.rb in /opt/puppetlabs/puppet/cache/lib/facter.
Debug: Facter: searching for fips_enabled.rb in /opt/puppetlabs/puppet/cache/facts.
Debug: Facter: fact "facterversion" has resolved to "3.11.0".
Debug: Facter: fact "aio_agent_version" has resolved to "5.5.0".
Debug: Facter: searching "/opt/puppetlabs/facter/facts.d" for external facts.
Debug: Facter: skipping external facts for "/etc/facter/facts.d": No such file or directory
Debug: Facter: skipping external facts for "/etc/puppetlabs/facter/facts.d": No such file or directory
Debug: Facter: no external facts were found.
Debug: Facter: resolving fips facts.
Debug: Facter: fact "fips_enabled" has resolved to true.
Error: Module install is prohibited in FIPS mode.
Error: Try 'puppet help module install' for usage

The installation with foreman-installer --enable-foreman-plugin-openscap proceeds as expected


Related issues

Blocks Foreman - Feature #3511: As a security person, I would like Foreman to run in FIPS modeResolved

History

#1 Updated by Peter Ondrejka over 3 years ago

  • Blocks Feature #3511: As a security person, I would like Foreman to run in FIPS mode added

#2 Updated by Ivan Necas over 3 years ago

  • Triaged set to No
  • Project changed from Foreman to OpenSCAP

#3 Updated by Marek Hulán over 3 years ago

We should update the docs, could you please try installing the module using package from our repos?

http://yum.theforeman.org/plugins/nightly/el7/x86_64/puppet-foreman_scap_client-0.3.16-1.el7.noarch.rpm

#4 Updated by Peter Ondrejka over 3 years ago

Marek Hulán wrote:

We should update the docs, could you please try installing the module using package from our repos?

http://yum.theforeman.org/plugins/nightly/el7/x86_64/puppet-foreman_scap_client-0.3.16-1.el7.noarch.rpm

rpm installation worked as expected

#5 Updated by Ivan Necas over 3 years ago

Should we close this one then?

#6 Updated by Marek Hulán about 3 years ago

  • Status changed from New to Rejected

yes, thanks, the rpm is mentioned in the manual too

Also available in: Atom PDF