From 42449db708139a7e6dd1b2a3f3466f5153cf4537 Mon Sep 17 00:00:00 2001 From: Matthew Burket Date: Fri, 20 Sep 2024 14:32:59 -0500 Subject: [PATCH 1/3] The /etc/system-fips file was depcreated in RHEL 9. Also allow the source of truth /proc/sys/crypto/fips_enabled to pass this file check. --- .../fips/enable_fips_mode/oval/shared.xml | 20 +++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml b/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml index 3b50e07060e..729bec3953e 100644 --- a/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml +++ b/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml @@ -2,8 +2,12 @@ {{{ oval_metadata("Check if FIPS mode is enabled on the system") }}} - + + + + {{% endif %}} + + + + + + /proc/sys/crypto/fips_enabled + ^1$ + 1 + + From 7d9e0c8073361638883738d86409edfed67e2a81 Mon Sep 17 00:00:00 2001 From: Matthew Burket Date: Tue, 24 Sep 2024 11:43:25 -0500 Subject: [PATCH 2/3] Disable enable_dracut_fips_module check for FIPS No longer used on RHEL10. --- .../software/integrity/fips/enable_fips_mode/oval/shared.xml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml b/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml index 729bec3953e..8cbef376fe5 100644 --- a/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml +++ b/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml @@ -10,8 +10,10 @@ + {{%- if product not in ["rhel10"] -%}} + {{%- endif -%}} Date: Wed, 25 Sep 2024 12:12:56 -0500 Subject: [PATCH 3/3] Use /proc/sys/crypto/fips_enabled everywhere in enable_fips_modes --- .../integrity/fips/enable_fips_mode/oval/shared.xml | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml b/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml index 8cbef376fe5..267fc6b0df7 100644 --- a/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml +++ b/linux_os/guide/system/software/integrity/fips/enable_fips_mode/oval/shared.xml @@ -2,12 +2,8 @@ {{{ oval_metadata("Check if FIPS mode is enabled on the system") }}} - - - - {{%- if product not in ["rhel10"] -%}}