Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.
Bug 1195850 - libgcrypt drops suid root rights on library load when fips is enabled
Summary: libgcrypt drops suid root rights on library load when fips is enabled
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: libgcrypt
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Tomas Mraz
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: F22BetaBlocker
TreeView+ depends on / blocked
 
Reported: 2015-02-24 17:21 UTC by Hans de Goede
Modified: 2015-03-09 15:10 UTC (History)
4 users (show)

Fixed In Version: libgcrypt-1.6.3-1.fc22
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-03-09 15:09:41 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Hans de Goede 2015-02-24 17:21:02 UTC
On Út, 2015-02-24 at 10:42 +0100, Hans de Goede wrote:
> Hi all,
>
> Debugging this took me ages, so I thought I would share this with you,
> with the new gdm on wayland landed in F-22 recently Xorg gets started
> as a regular user.
>
> This is a good thing as we want to move to Xorg running as a regular user,
> but we're not 100% there yet, so currently Xorg is still suid-root, and
> needs those root rights to function properly.
>
> But when fips is enabled either on the kernel commandline or a /etc/system-fips
> file exists one of the libraries X is using is dropping the root rights at
> early library init and things fail.
>
> So if X is not working for you all of a sudden, make sure you do not have
> fips enabled on the kernel commandline, and remove any /etc/system-fips
> file you may have.

This is unintended side-effect of running the FIPS selftest in the
libgcrypt constructor, we need to fix that. Please open a new bug
against libgcrypt so the bug fix is tracked.

Comment 1 Fedora Blocker Bugs Application 2015-03-09 09:08:18 UTC
Proposed as a Blocker for 22-beta by Fedora user pbrobinson using the blocker tracking app because:

 Stops core desktop working when FIPS is enabled

Comment 2 Rex Dieter 2015-03-09 13:13:39 UTC
Is FIPS mode a blocker ?  (if so, under what criteria?)

Comment 3 Tomas Mraz 2015-03-09 15:09:41 UTC
This should be fixed in rawhide and recent F22 update in testing.

Comment 4 Tomas Mraz 2015-03-09 15:10:31 UTC
Also I do not think FIPS mode regression should be a release blocker.


Note You need to log in before you can comment on or make changes to this bug.