elastic / elastic/apm-agent-python

apm agent fails in a FIPS enabled host

Offen
#2,115 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
agent-python community triage
Vorherrschende Sprache
Python
Sterne
431
Forks
239
Ø Merge
5 T. 10 Std.
Gemergte PRs (30 T.)
7

Beschreibung

``We are running a webapp on Azure, which uses Elastic APM (elastic-apm==6.23.0). Since 08/29/2024, without changing anything our app is failing to run, with:

```
crypto/fips/fips.c:154: OpenSSL internal error: FATAL FIPS SELFTEST FAILURE
Aborted (core dumped)
```

We noticed the Azure webapp environment (linux) now has the following kernel parameter:

```
# sysctl crypto.fips_enabled
crypto.fips_enabled = 1
```

**To Reproduce**

```
# python
Python 3.12.2 (main, Feb 22 2024, 11:15:41) [GCC 10.2.1 20210110] on linux
Type "help", "copyright", "credits" or "license" for more information.
>>> import elasticapm
>>> apm=elasticapm.Client()
>>> elasticapm.instrument()
crypto/fips/fips.c:154: OpenSSL internal error: FATAL FIPS SELFTEST FAILURE
Aborted (core dumped)
#
```

**Environment (please complete the following information)**
- OS: Linux hostname 5.15.164.1-1.cm2 #1 SMP Sun Aug 18 19:16:21 UTC 2024 x86_64 GNU/Linux
- Python version: 3.12
- APM Server version: unrelevant, it fail before even connecting (no need to have an APM server to test it)
- Agent version: 6.23.0

**Additional context**

```
(antenv) root@aiops-dev_0ac897ce81:/tmp/8dccb366a943910# python
Python 3.12.2 (main, Feb 22 2024, 11:15:41) [GCC 10.2.1 20210110] on linux
Type "help", "copyright", "credits" or "license" for more information.
>>> import elasticapm
>>> apm=elasticapm.Client()
>>> elasticapm.instrument()
crypto/fips/fips.c:154: OpenSSL internal error: FATAL FIPS SELFTEST FAILURE
Aborted (core dumped)
(antenv) root@aiops-dev_0ac897ce81:/tmp/8dccb366a943910#

Linux aiops-dev_0ac897ce81 5.15.164.1-1.cm2 #1 SMP Sun Aug 18 19:16:21 UTC 2024 x86_64 GNU/Linux

(antenv) root@aiops-dev_0ac897ce81:/tmp/8dccb366a943910# sysctl crypto.fips_enabled
crypto.fips_enabled = 1

elastic-apm==6.23.0

(antenv) root@aiops-dev_0ac897ce81:/tmp/8dccb366a943910# python -V
Python 3.12.2
```

See attached file for detail about installed packages in the OS and version, as well as a detailled dump of the system calls.

[issue.txt](https://github.com/user-attachments/files/16836808/issue.txt)

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Reproduziere den Fehler unter Python 3.12/Linux mit crypto.fips_enabled=1 unter Verwendung der gemeldeten Einstiegspunkte import elasticapm, Client() und instrument(). Der Payload nennt keine Quelldateien oder Tests. Ermittle daher zunächst den Initialisierungspfad, der durch diese Aufrufe erreicht wird, und erstelle einen Regressionstest für den FIPS-enabled-Fall. Erledigt ist dies, wenn die Instrumentierung nicht mehr mit dem gemeldeten OpenSSL self-test failure abbricht.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
azure, linux, python
Bereich
backend, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.