SunPKCS11's Secmod and external modules in FIPS mode

Martin Balao mbalao at
Sat Dec 21 01:03:29 UTC 2019


SunPKCS11's Secmod in OpenJDK does not allow modules other than the NSS
Software Token to be configured in FIPS mode [1]. To give some context,
NSS represents modules internally with a structure called "struct
SECMODModuleStr" and the "fips" variable you see in [1] is the "isFIPS"
member of the module structure [2]. isFIPS is initialized by NSS to
false for all modules [3] but if the module spec string has a "FIPS"
flag, it may be turned to true [4]. Newer NSS versions (since bug
1531267 [5] [6]) may set isFIPS to true for all modules when
/proc/sys/crypto/fips_enabled is 1 in Linux systems. As a result, as
soon as the system is in FIPS mode and the NSSDB has more than the NSS
Software Token module in it, OpenJDK refuses to initialize the SunPKCS11
provider. You can see a real case with pk11-kit-trust as the external
module in RH1780335 [7].

This behavior has been the same since the very beginning of OpenJDK
(revision 2), and I couldn't find much information about it. There might
be a commit message previous to that.

I'm trying to understand the rationale behind it and see what would be
the implications of removing the check (note: couldn't notice anything
in my quick test by removing it).

Can someone give me a hint?


[1] -
[2] -
[3] -
[4] -
[5] -
[6] -
[7] -

More information about the security-dev mailing list