-
Notifications
You must be signed in to change notification settings - Fork 684
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix grub2 enable fips mode rule #4986
Fix grub2 enable fips mode rule #4986
Conversation
|
Since this piece of code is not a bash function anymore, it is not possible to use the return statement, so inverting the logic of the test did the trick.
bf1ea50
to
6c71820
Compare
I understand. But is it harmful to install the package even if the processor doesn't support the hardware acceleration? Otherwise we won't have this rule green during installation on a machine which is not subscribed during installation phase. |
Even if installing the package |
I've consulted quoting:
I've tested on other architectures such as ppc64,s390x,etc and the package is present on those archs as well and can be installed without any problem.
|
I am merging this PR, as it makes the OSPP/STIG profile one rule greener. |
Description:
The problem was that it may happen that bash remediation phase when doing a fresh installation, some functions may require installing package, but it can happen that the machine is not registered to any repository yet, so the package installation should happen during the package installation phase via anaconda.
dracut-fips-aesni
to anaconda remediation for grub2_enable_fips_mode rule.return
statement norexit
, now it skips correctly when the package is not installed.Rationale:
grub2_enable_fips_mode passes during fresh installation when using oscap-anaconda-addon profiles.
Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1754532