Comment 19 for bug 1461834

Revision history for this message
Jake Lepere (jrlepere) wrote :

Enabling FIPS on Ubuntu Pro 22.04+ machines [1] drops rsa1024 as an available encryption key because rsa1024 isn't FIPS compliant. Therefore, adding rsa1024 signed apt keys here isn't possible.

Does anyone have suggestions to work around this? I've asked if maintainers could resign apt keys for relevant repos but haven't heard back. Additionally, adding apt keys before enabling FIPS works, but future apt updates unfortunately fail afterwards.

[1] https://ubuntu.com/security/certifications/docs/fips-enablement