You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
After the CENTOS 7 installation on a physical server where DISA STIG profile is selected, I got the following error message and can not boot into OS: "dracut-pre-trigger[646]: modprobe: FATAL: Module sha1 not found" and "FIPS integrity test failed".
Actually, I repeated the installation already a couple of times and got the same error message and think it is because of the security profile selected which is DISA STIG RHEL7.
SCAP Security Guide Version:
Built-in CentOS
Operating System Version:
CentOS 7
Steps to Reproduce:
Start OS installation on a server with UEFI boot
Select DISA STIG RHEL7 profile
Reboot the server
Actual Results:
FIPS verification failed
Expected Results:
FIPS verification successful
Addition Information/Debugging Steps:
The text was updated successfully, but these errors were encountered:
It turned out that UUID of the boot partition was not specified in the in the GRUB_CMDLINE_LINUX key in /etc/default/grub file. After adding it manually and rebuilding the grub.conf, the problem has been resolved.
The remediation seems to add the UUID, check out linux_os/guide/system/software/integrity/fips/grub2_enable_fips_mode/bash/shared.sh, could @ykorkmaz please recheck whether it is still valid?
Description of problem:
After the CENTOS 7 installation on a physical server where DISA STIG profile is selected, I got the following error message and can not boot into OS: "dracut-pre-trigger[646]: modprobe: FATAL: Module sha1 not found" and "FIPS integrity test failed".
Actually, I repeated the installation already a couple of times and got the same error message and think it is because of the security profile selected which is DISA STIG RHEL7.
SCAP Security Guide Version:
Built-in CentOS
Operating System Version:
CentOS 7
Steps to Reproduce:
Actual Results:
FIPS verification failed
Expected Results:
FIPS verification successful
Addition Information/Debugging Steps:
The text was updated successfully, but these errors were encountered: