Fail To Install Gateway RPM On RedHat 8 With FIPS Mode Enabled At The OS Level
search cancel

Fail To Install Gateway RPM On RedHat 8 With FIPS Mode Enabled At The OS Level

book

Article ID: 273799

calendar_today

Updated On:

Products

CA API Gateway

Issue/Introduction

We are looking to install a software gateway on RedHat 8 which has FIPS mode enabled at the OS level.

When installing the gateway rpm we receive the following error:

# rpm -ivh ssg-10.1.00-11620.noarch

package ssg-10.1.00-11620.noarch does not verify: no digest

Environment

CA API Gateway 10.x, 11.0

Cause

RedHat 8 requires more strict packaging signing with SHA256 when FIPS is enabled.

Resolution

The current work around prior to 11.0 CR02 is to first install and configure your software gateway.  Once that is complete you can then enable FIPS mode at the OS level.

Starting with 11.0 CR02 they enhanced the signing digest used to create the verification that would be FIPS compliant.

https://techdocs.broadcom.com/us/en/ca-enterprise-software/layer7-api-management/api-gateway/11-0/release-notes/new-features-and-enhancements.html#concept.dita_newfeatures_refresh_gw10cr2_11cr2

 

Additional Information

F135656