openssl pkcs12 key generation, export, and conversion fail in RHEL 7 with FIPS mode enabled

Solution Verified - Updated -

Issue

  • When running openssl pkcs12 key pair generation, exports, and creating bundles with FIPS (Federal Information Processing Standards) mode enabled results in failures related to incompatible/unknown ciphers.

  • When running openssl pkcs12 certificate/key conversions and unpacking bundles with FIPS mode enabled results in the same failures.

Environment

  • Red Hat Enterprise Linux 7
  • Red Hat Enterprise Linux 8 with OpenSSL versions earlier than openssl-1.1.1c-2.el8

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content