fips-initramfs-generic 0.0.15+generic1 incompatible with mdadm

Bug #2007057 reported by Troy Frew
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu
New
Undecided
Unassigned

Bug Description

uname -a
Linux 5.4.0-1072-fips #81-Ubuntu SMP Wed Jan 25 11:07:24 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux

dpkg -l | grep fips-initramfs-generic
ii fips-initramfs-generic 0.0.15+generic1 amd64 FIPS 140-2 kernel tests

secure boot enabled
/boot/efi and backup esp on /dev/sda1 and /dev/sdb1
/boot as unencrypted mdadm raid 1 on /dev/sda2 and /dev/sdb2
/ as encrypted lvm mdadm raid 1 on /dev/sda3 and /dev/sdb3
keyscript to auto unlock / from tpm2.0 key data

kernel settings fips=0, host will boot fine

kernel setting fips=1, host panics cannot find /boot

temporary fix i've had to put in to make the host boot with fips=1:

echo "GRUB_CMDLINE_LINUX_DEFAULT=\"\$GRUB_CMDLINE_LINUX_DEFAULT fips=1 bootdev=/dev/md0\"" | sudo tee /etc/default/grub.d/99-fips.cfg

sudo sed -i 's/"udev"/"udev mdadm"/g' /usr/share/initramfs-tools/scripts/init-top/fips

sudo update-initramfs -u

sudo update-grub

Tags: bot-comment
Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. It seems that your bug report is not filed about a specific source package though, rather it is just filed against Ubuntu in general. It is important that bug reports be filed about source packages so that people interested in the package can find the bugs about it. You can find some hints about determining what package your bug might be about at https://wiki.ubuntu.com/Bugs/FindRightPackage. You might also ask for help in the #ubuntu-bugs irc channel on Libera.chat.

To change the source package that this bug is filed about visit https://bugs.launchpad.net/ubuntu/+bug/2007057/+editstatus and add the package name in the text box next to the word Package.

[This is an automated message. I apologize if it reached you inappropriately; please just reply to this message indicating so.]

tags: added: bot-comment
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.