<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MCTB tiebreaker fails to start on RHEL with FIPS enabled in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/MCTB-tiebreaker-fails-to-start-on-RHEL-with-FIPS-enabled/m-p/152328#M33913</link>
    <description>&lt;P&gt;MCTB tiebreaker 1.21P2 fails to start on RHEL 7 with FIPS enabled&lt;/P&gt;
&lt;P&gt;When tiebreaker starts:&lt;/P&gt;
&lt;P&gt;bad decrypt&lt;BR /&gt;139962014652304:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:evp_enc.c:592:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This seems to indicate an openssl error.&amp;nbsp; Looking at&amp;nbsp;/etc/init.d/netapp-metrocluster-tiebreaker-software&lt;/P&gt;
&lt;P&gt;DECR_PASS=$(echo $ENCR_PASS | openssl enc -aes-128-cbc -a -d -salt -pass pass:$KEY)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RHEL docs seem to indicate we need to add -md sha256 to the openssl encrypt and decrypt for it to work in FIPS mode.&amp;nbsp; Where is the decrypt line specified?&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 12:08:34 GMT</pubDate>
    <dc:creator>jhubert</dc:creator>
    <dc:date>2025-06-04T12:08:34Z</dc:date>
    <item>
      <title>MCTB tiebreaker fails to start on RHEL with FIPS enabled</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/MCTB-tiebreaker-fails-to-start-on-RHEL-with-FIPS-enabled/m-p/152328#M33913</link>
      <description>&lt;P&gt;MCTB tiebreaker 1.21P2 fails to start on RHEL 7 with FIPS enabled&lt;/P&gt;
&lt;P&gt;When tiebreaker starts:&lt;/P&gt;
&lt;P&gt;bad decrypt&lt;BR /&gt;139962014652304:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:evp_enc.c:592:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This seems to indicate an openssl error.&amp;nbsp; Looking at&amp;nbsp;/etc/init.d/netapp-metrocluster-tiebreaker-software&lt;/P&gt;
&lt;P&gt;DECR_PASS=$(echo $ENCR_PASS | openssl enc -aes-128-cbc -a -d -salt -pass pass:$KEY)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RHEL docs seem to indicate we need to add -md sha256 to the openssl encrypt and decrypt for it to work in FIPS mode.&amp;nbsp; Where is the decrypt line specified?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:08:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/MCTB-tiebreaker-fails-to-start-on-RHEL-with-FIPS-enabled/m-p/152328#M33913</guid>
      <dc:creator>jhubert</dc:creator>
      <dc:date>2025-06-04T12:08:34Z</dc:date>
    </item>
  </channel>
</rss>

