Unable to start ipsec service when FIPS mode is enabled.
Issue
- When FIPS mode is on, IPsec failed to start with the following errors.
Sep 27 17:01:39 localhost pluto[5211]: Opening NSS database "sql:/etc/ipsec.d" read-only
Sep 27 17:01:39 localhost pluto[5211]: NSS Password file "/etc/ipsec.d/nsspassword" for token "NSS FIPS 140-2 Certificate DB" could not be opened for reading
Sep 27 17:01:39 localhost pluto[5211]: authentication of "NSS FIPS 140-2 Certificate DB" failed
Sep 27 17:01:39 localhost pluto[5211]: FATAL: NSS initialization failure
Environment
- Red Hat Enterprise Linux 7
- FIPS mode on
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.