Chrony server does not start with NTS and FIPS mode enabled
Issue
-
I am trying to enable Network Time Security (NTS) on a Chrony server with FIPS mode enabled. However when attempting to start chronyd with NTS configured in FIPS mode, getting error as 'nts_ke_server.c:486:(generate_key) Fatal error : Could not set SIV key'.
# /usr/sbin/chronyd -d -d 2024-01-23T20:41:39Z nks#1:siv_gnutls.c:172:(SIV_SetKey) Could not initialise cipher : An algorithm that is not enabled was negotiated. 2024-01-23T20:41:39Z nks#1:nts_ke_server.c:486:(generate_key) Fatal error : Could not set SIV key
-
The more "security" we have the better, so would prefer to have both NTS and FIPS mode. Is it possible to allow NTS with FIPS mode.
Environment
- Red Hat Enteprise Linux 8
- Red Hat Enteprise Linux 9
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.