Loading...
Loading...
What were you trying to do that didn't work? When executing pkcs11-tool with a configuration specified via KRYOPTIC_CONF on a system in FIPS mode, C_Initialize crashes. This occurs because pkcs11-tool links to OpenSSL (which loads the provider) and then explicitly loads /usr/lib64/pkcs11/fipstokn.so. Because fipstokn.so is a symlink to the module in ossl-modules, OpenSSL forbids the second initialization. What is the impact of this issue to you? High Please provide the package NVR for which the bug is seen: fips-provider-next-1.5.2-5.el10_2 How reproducible is this bug?: Always Steps to reproduce Enable FIPS mode Define KRYOPTIC_CONF path (e.g., export KRYOPTIC_CONF="/root/fipstokn.tmp/tokens/fipstokn.conf"). Execute pkcs11-tool: KRYOPTIC_CONF="/root/fipstokn.tmp/tokens/fipstokn.conf" pkcs11-tool --module /usr/lib64/pkcs11/fipstokn.so -I Expected results pkcs11-tool successfully initializes the PKCS#11 module using the provided configuration and displays token information. Actual results pkcs11-tool and, more specifically, fips-provider-next crashes
Unresolved
Click on a version to see all relevant bugs
Red Hat Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.