-
Notifications
You must be signed in to change notification settings - Fork 33
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ntpd refuses to start with FIPS mode enabled #1534
Comments
Hello, I think that's to be expected: One should patch
EDIT: Thanks for the detailed report. |
I think we're okay with the workaround for now - if we get complaints from our FIPS required users, we can look at alternative methods of addressing this. |
Description
When FIPS mode is enabled on openssl, ntpd refuses to start due to md5 being disabled as a security hash.
Impact
We can not use ntpd to synchronize time on Flatcar OS images when running in FIPS mode. This creates a security and compliance risk for customers that require FIPS 140-2 cryptography to be enabled.
Environment and steps to reproduce
a. Enabled fips mode
b.Reboot host to trigger all FIPS mode items to be properly enabled.
Expected behavior
ntpd.service
should execute normally.Additional information
None.
The text was updated successfully, but these errors were encountered: