elastic / elastic/apm-agent-python
apm agent fails in a FIPS enabled host
- 主要语言
- Python
- 星标
- 431
- 派生
- 239
- 平均合并
- 5 天 10 小时
- 30 天内合并 PR
- 7
描述
``We are running a webapp on Azure, which uses Elastic APM (elastic-apm==6.23.0). Since 08/29/2024, without changing anything our app is failing to run, with:
```
crypto/fips/fips.c:154: OpenSSL internal error: FATAL FIPS SELFTEST FAILURE
Aborted (core dumped)
```
We noticed the Azure webapp environment (linux) now has the following kernel parameter:
```
# sysctl crypto.fips_enabled
crypto.fips_enabled = 1
```
**To Reproduce**
```
# python
Python 3.12.2 (main, Feb 22 2024, 11:15:41) [GCC 10.2.1 20210110] on linux
Type "help", "copyright", "credits" or "license" for more information.
>>> import elasticapm
>>> apm=elasticapm.Client()
>>> elasticapm.instrument()
crypto/fips/fips.c:154: OpenSSL internal error: FATAL FIPS SELFTEST FAILURE
Aborted (core dumped)
#
```
**Environment (please complete the following information)**
- OS: Linux hostname 5.15.164.1-1.cm2 #1 SMP Sun Aug 18 19:16:21 UTC 2024 x86_64 GNU/Linux
- Python version: 3.12
- APM Server version: unrelevant, it fail before even connecting (no need to have an APM server to test it)
- Agent version: 6.23.0
**Additional context**
```
(antenv) root@aiops-dev_0ac897ce81:/tmp/8dccb366a943910# python
Python 3.12.2 (main, Feb 22 2024, 11:15:41) [GCC 10.2.1 20210110] on linux
Type "help", "copyright", "credits" or "license" for more information.
>>> import elasticapm
>>> apm=elasticapm.Client()
>>> elasticapm.instrument()
crypto/fips/fips.c:154: OpenSSL internal error: FATAL FIPS SELFTEST FAILURE
Aborted (core dumped)
(antenv) root@aiops-dev_0ac897ce81:/tmp/8dccb366a943910#
Linux aiops-dev_0ac897ce81 5.15.164.1-1.cm2 #1 SMP Sun Aug 18 19:16:21 UTC 2024 x86_64 GNU/Linux
(antenv) root@aiops-dev_0ac897ce81:/tmp/8dccb366a943910# sysctl crypto.fips_enabled
crypto.fips_enabled = 1
elastic-apm==6.23.0
(antenv) root@aiops-dev_0ac897ce81:/tmp/8dccb366a943910# python -V
Python 3.12.2
```
See attached file for detail about installed packages in the OS and version, as well as a detailled dump of the system calls.
[issue.txt](https://github.com/user-attachments/files/16836808/issue.txt)
贡献指南
调研方向
在 Python 3.12/Linux 上使用 crypto.fips_enabled=1,并通过报告中的 import elasticapm、Client() 和 instrument() 入口点复现该故障。该 payload 未指明源文件或测试,因此首先定位这些调用所到达的初始化路径,并为 FIPS-enabled 情况建立回归测试。完成的标准是 instrumentation 不再因报告的 OpenSSL self-test failure 而中止。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- azure, linux, python
- 领域
- backend, security
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100