<html><body>
<p><font size="2" face="sans-serif">Yep, did so right away. and yes, this is for the future state of IPA.</font><br>
<font size="2" face="sans-serif"><br>
</font><br>
<font size="2" face="Trebuchet MS"><b>Michael Sean Conley</b></font><br>
<font size="2" face="Trebuchet MS">Hardware/Infrastructure</font><br>
<font size="2" face="Trebuchet MS">Intelligence, Information and Services</font><br>
<font size="2" face="Trebuchet MS"><b>Raytheon Company</b></font><br>
<font size="2" face="Trebuchet MS">972-643-9887 (office)</font><br>
<br>
<font size="2" face="Trebuchet MS">Michael.Sean.Conley@raytheon.com</font><br>
<br>
<img width="16" height="16" src="cid:1__=09BB0A9ADFDC8ABD8f9e8a93df9@raytheon.com" border="0" alt="Inactive hide details for Martin Kosek ---08/05/2016 06:33:27 AM---Are you now asking about when upstream version is FIPS compl"><font size="2" color="#424282" face="sans-serif">Martin Kosek ---08/05/2016 06:33:27 AM---Are you now asking about when upstream version is FIPS compliant or some downstream distribution? If</font><br>
<br>
<font size="1" color="#5F5F5F" face="sans-serif">From: </font><font size="1" face="sans-serif">Martin Kosek <mkosek@redhat.com></font><br>
<font size="1" color="#5F5F5F" face="sans-serif">To: </font><font size="1" face="sans-serif">Michael Sean Conley <Michael.Sean.Conley@raytheon.com>, Rob Crittenden <rcritten@redhat.com></font><br>
<font size="1" color="#5F5F5F" face="sans-serif">Cc: </font><font size="1" face="sans-serif">freeipa-users@redhat.com</font><br>
<font size="1" color="#5F5F5F" face="sans-serif">Date: </font><font size="1" face="sans-serif">08/05/2016 06:33 AM</font><br>
<font size="1" color="#5F5F5F" face="sans-serif">Subject: </font><font size="1" face="sans-serif">Re: [Freeipa-users] IPA and FIPS 140-2</font><br>
<hr width="100%" size="2" align="left" noshade style="color:#8091A5; "><br>
<br>
<br>
<tt><font size="2">Are you now asking about when upstream version is FIPS compliant or some<br>
downstream distribution? If you are asking about RHEL, as indicated by<br>
</font></tt><tt><font size="2"><a href="https://bugzilla.redhat.com/show_bug.cgi?id=1125174">https://bugzilla.redhat.com/show_bug.cgi?id=1125174</a></font></tt><tt><font size="2"><br>
the bug is still in a NEW state. Given the state of RHEL-7.3 life cycle, it is<br>
too late to add it there.<br>
<br>
However, as Rob mentioned, it would really great if you file a support case (if<br>
we are talking about RHEL) and get it linked to that bug. Due to the interest,<br>
it is already high in the RHEL-7.4 considerations, but adding +1 won't hurt and<br>
you may also receive updates on development status.<br>
<br>
Martin<br>
<br>
On 08/04/2016 06:40 PM, Michael Sean Conley wrote:<br>
> Is there any indication of a timeframe for it to become FIPS compliant? If we<br>
> are talking weeks, rather than years...<br>
> <br>
> *Michael Sean Conley*<br>
> <br>
> <br>
> Inactive hide details for Rob Crittenden ---08/04/2016 11:37:23 AM---Michael<br>
> Sean Conley wrote: > Does ANYONE have any experienRob Crittenden ---08/04/2016<br>
> 11:37:23 AM---Michael Sean Conley wrote: > Does ANYONE have any experience<br>
> getting IPA to work with FIPS?<br>
> <br>
> From: Rob Crittenden <rcritten@redhat.com><br>
> To: Michael Sean Conley <Michael.Sean.Conley@raytheon.com>,<br>
> freeipa-users@redhat.com<br>
> Date: 08/04/2016 11:37 AM<br>
> Subject: Re: [Freeipa-users] IPA and FIPS 140-2<br>
> <br>
> -------------------------------------------------------------------------------<br>
> <br>
> <br>
> <br>
> Michael Sean Conley wrote:<br>
>> Does ANYONE have any experience getting IPA to work with FIPS?<br>
>><br>
>> We're trying desperately to get this going, as we have some requirements<br>
>> that the Identity Management Tool we choose must be FIPS 140-2 compliant.<br>
> <br>
> No, it doesn't work in FIPS mode yet. If you open a support case with<br>
> Red Hat your case can be added to<br>
> </font></tt><tt><font size="2"><a href="https://bugzilla.redhat.com/show_bug.cgi?id=1125174">https://bugzilla.redhat.com/show_bug.cgi?id=1125174</a></font></tt><tt><font size="2"><br>
> <br>
> While most, if not all, of the individual components can run in FIPS<br>
> mode there are a lot of moving parts to coordinate to ensure they comply<br>
> with the FIPS Security Policy and to handle some corner cases in the<br>
> management framework.<br>
> <br>
> rob<br>
> <br>
> <br>
> <br>
<br>
</font></tt><br>
</body></html>