Closed Bug 143071 Opened 24 years ago Closed 24 years ago

Disable immediate FIPS switching

Categories

(Core Graveyard :: Security: UI, defect, P2)

Other Branch
defect

Tracking

(Not tracked)

VERIFIED WONTFIX
psm2.3

People

(Reporter: KaiE, Assigned: KaiE)

Details

Because of the arguments stated in bug 142659, I recommend that switching FIPS mode during runtime should no longer be supported. I suggest we remember the switch somewhere internally, and do the switch the next time we start up. We should inform the user that a complete application exit is required to do the switch.
I suggest this should block bug 133584.
We should implement this for RTM.
Keywords: nsbeta1+
Priority: -- → P2
Whiteboard: [adt2 RTM]
Target Milestone: --- → 2.3
Situation has changed since my last comments. Bob provided patches in bug 142659, that allowed me to produce a fix in bug 143532. With those patches, we might be safe already. However, Bob said, we are not sure. Even with those patches, after having toggled FIPS mode, we have still objects in memory, and their presence could cause side effects we are not yet aware about. Bob suggested, if we want to be really safe, we should implement this bug and ask the user to restart.
Because we are now avoiding immediate crashes, and the approach suggested in this bug is a bit more work to implement, I had a chat with Stephane, and he suggested that a release note might be sufficient. Thinking more about it, I'd say instead of a release note, we also could just display a restart recommendation message to the user. I'm marking this bug as WONTFIX and have filed bug 148305 for adding the message.
Status: NEW → RESOLVED
Closed: 24 years ago
Keywords: nsbeta1+
Resolution: --- → WONTFIX
Whiteboard: [adt2 RTM]
Verified
Status: RESOLVED → VERIFIED
Product: PSM → Core
Product: Core → Core Graveyard
You need to log in before you can comment on or make changes to this bug.