Skip to content

Commit f861719

Browse files
authored
Merge pull request #64917 from mjpytlak/osdocs-7806
Revert "Temporarily remove Support for FIPS cryptography topic"
2 parents da6e527 + 67c5695 commit f861719

File tree

9 files changed

+7
-22
lines changed

9 files changed

+7
-22
lines changed

_topic_maps/_topic_map.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -510,6 +510,9 @@ Topics:
510510
- Name: Troubleshooting installation issues
511511
File: installing-troubleshooting
512512
Distros: openshift-origin,openshift-enterprise
513+
- Name: Support for FIPS cryptography
514+
File: installing-fips
515+
Distros: openshift-enterprise,openshift-online
513516
---
514517
Name: Post-installation configuration
515518
Dir: post_installation_configuration

installing/install_config/installing-customizing.adoc

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -52,9 +52,6 @@ include::modules/installation-special-config-chrony.adoc[leveloffset=+1]
5252

5353
* For information on Butane, see xref:../../installing/install_config/installing-customizing.adoc#installation-special-config-butane_installing-customizing[Creating machine configs with Butane].
5454

55-
////
5655
ifndef::openshift-origin[]
5756
* For information on FIPS support, see xref:../../installing/installing-fips.adoc#installing-fips[Support for FIPS cryptography].
5857
endif::[]
59-
60-
////

installing/installing-preparing.adoc

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -25,8 +25,8 @@ endif::openshift-origin[]
2525
* Microsoft Azure on 64-bit x86 instances
2626
* Microsoft Azure on 64-bit ARM instances
2727
* Microsoft Azure Stack Hub
28-
* Google Cloud Platform (GCP) on 64-bit x86 instances
29-
* Google Cloud Platform (GCP) on 64-bit ARM instances
28+
* Google Cloud Platform (GCP) on 64-bit x86 instances
29+
* Google Cloud Platform (GCP) on 64-bit ARM instances
3030
* {rh-openstack-first}
3131
* IBM Cloud VPC
3232
* {ibmzProductName} or {linuxoneProductName}
@@ -77,12 +77,11 @@ If you use a user-provisioned installation method, you can configure a proxy for
7777

7878
If you want to prevent your cluster on a public cloud from exposing endpoints externally, you can deploy a private cluster with installer-provisioned infrastructure on xref:../installing/installing_aws/installing-aws-private.adoc#installing-aws-private[AWS], xref:../installing/installing_azure/installing-azure-private.adoc#installing-azure-private[Azure], or xref:../installing/installing_gcp/installing-gcp-private.adoc#installing-gcp-private[GCP].
7979

80-
If you need to install your cluster that has limited access to the internet, such as a disconnected or restricted network cluster, you can xref:../installing/disconnected_install/installing-mirroring-installation-images.adoc#installing-mirroring-installation-images[mirror the installation packages] and install the cluster from them. Follow detailed instructions for user provisioned infrastructure installations into restricted networks for xref:../installing/installing_aws/installing-restricted-networks-aws.adoc#installing-restricted-networks-aws[AWS], xref:../installing/installing_gcp/installing-restricted-networks-gcp.adoc#installing-restricted-networks-gcp[GCP], xref:../installing/installing_ibm_z/installing-restricted-networks-ibm-z.adoc#installing-restricted-networks-ibm-z[{ibmzProductName} or {linuxoneProductName}], xref:../installing/installing_ibm_z/installing-restricted-networks-ibm-z-kvm.adoc#installing-restricted-networks-ibm-z-kvm[{ibmzProductName} or {linuxoneProductName} with {op-system-base} KVM], xref:../installing/installing_ibm_power/installing-restricted-networks-ibm-power.adoc#installing-restricted-networks-ibm-power[IBM Power], xref:../installing/installing_vsphere/installing-restricted-networks-vsphere.adoc#installing-restricted-networks-vsphere[vSphere], or xref:../installing/installing_bare_metal/installing-restricted-networks-bare-metal.adoc#installing-restricted-networks-bare-metal[bare metal]. You can also install a cluster into a restricted network using installer-provisioned infrastructure by following detailed instructions for xref:../installing/installing_aws/installing-restricted-networks-aws-installer-provisioned.adoc#installing-restricted-networks-aws-installer-provisioned[AWS], xref:../installing/installing_gcp/installing-restricted-networks-gcp-installer-provisioned.adoc#installing-restricted-networks-gcp-installer-provisioned[GCP], xref:../installing/installing_nutanix/installing-restricted-networks-nutanix-installer-provisioned.adoc#installing-restricted-networks-nutanix-installer-provisioned[Nutanix, xref:../installing/installing_openstack/installing-openstack-installer-restricted.adoc#installing-openstack-installer-restricted[{rh-openstack}], and xref:../installing/installing_vsphere/installing-restricted-networks-installer-provisioned-vsphere.adoc#installing-restricted-networks-installer-provisioned-vsphere[vSphere].
80+
If you need to install your cluster that has limited access to the internet, such as a disconnected or restricted network cluster, you can xref:../installing/disconnected_install/installing-mirroring-installation-images.adoc#installing-mirroring-installation-images[mirror the installation packages] and install the cluster from them. Follow detailed instructions for user provisioned infrastructure installations into restricted networks for xref:../installing/installing_aws/installing-restricted-networks-aws.adoc#installing-restricted-networks-aws[AWS], xref:../installing/installing_gcp/installing-restricted-networks-gcp.adoc#installing-restricted-networks-gcp[GCP], xref:../installing/installing_ibm_z/installing-restricted-networks-ibm-z.adoc#installing-restricted-networks-ibm-z[{ibmzProductName} or {linuxoneProductName}], xref:../installing/installing_ibm_z/installing-restricted-networks-ibm-z-kvm.adoc#installing-restricted-networks-ibm-z-kvm[{ibmzProductName} or {linuxoneProductName} with {op-system-base} KVM], xref:../installing/installing_ibm_power/installing-restricted-networks-ibm-power.adoc#installing-restricted-networks-ibm-power[IBM Power], xref:../installing/installing_vsphere/installing-restricted-networks-vsphere.adoc#installing-restricted-networks-vsphere[vSphere], or xref:../installing/installing_bare_metal/installing-restricted-networks-bare-metal.adoc#installing-restricted-networks-bare-metal[bare metal]. You can also install a cluster into a restricted network using installer-provisioned infrastructure by following detailed instructions for xref:../installing/installing_aws/installing-restricted-networks-aws-installer-provisioned.adoc#installing-restricted-networks-aws-installer-provisioned[AWS], xref:../installing/installing_gcp/installing-restricted-networks-gcp-installer-provisioned.adoc#installing-restricted-networks-gcp-installer-provisioned[GCP], xref:../installing/installing_nutanix/installing-restricted-networks-nutanix-installer-provisioned.adoc#installing-restricted-networks-nutanix-installer-provisioned[Nutanix], xref:../installing/installing_openstack/installing-openstack-installer-restricted.adoc#installing-openstack-installer-restricted[{rh-openstack}], and xref:../installing/installing_vsphere/installing-restricted-networks-installer-provisioned-vsphere.adoc#installing-restricted-networks-installer-provisioned-vsphere[vSphere].
8181

8282

8383
If you need to deploy your cluster to an xref:../installing/installing_aws/installing-aws-government-region.adoc#installing-aws-government-region[AWS GovCloud region], xref:../installing/installing_aws/installing-aws-china.adoc#installing-aws-china-region[AWS China region], or xref:../installing/installing_azure/installing-azure-government-region.adoc#installing-azure-government-region[Azure government region], you can configure those custom regions during an installer-provisioned infrastructure installation.
8484

85-
////
8685
ifndef::openshift-origin[]
8786
You can also configure the cluster machines to use xref:../installing/installing-fips.adoc#installing-fips[FIPS Validated / Modules in Process cryptographic libraries] during installation.
8887

@@ -92,7 +91,6 @@ The use of FIPS Validated / Modules in Process cryptographic libraries is only s
9291
====
9392

9493
endif::[]
95-
////
9694

9795
////
9896
[id="installing-preparing-single-node"]

installing/installing_with_agent_based_installer/preparing-to-install-with-agent-based-installer.adoc

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,9 +33,7 @@ include::modules/agent-installer-configuring-fips-compliance.adoc[leveloffset=+1
3333

3434
* link:https://access.redhat.com/articles/5059881[OpenShift Security Guide Book]
3535

36-
////
3736
* xref:../../installing/installing-fips.adoc#installing-fips[Support for FIPS cryptography]
38-
////
3937

4038
include::modules/agent-install-networking.adoc[leveloffset=+1]
4139

operators/operator_sdk/osdk-generating-csvs.adoc

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -41,9 +41,7 @@ include::modules/osdk-csv-manual-annotations.adoc[leveloffset=+2]
4141
* xref:../../operators/operator_sdk/osdk-generating-csvs.adoc#osdk-suggested-namespace-default-node_osdk-generating-csvs[Setting a suggested namespace with default node selector]
4242
* xref:../../operators/operator_sdk/osdk-generating-csvs.adoc#olm-enabling-operator-for-restricted-network_osdk-generating-csvs[Enabling your Operator for restricted network environments] (disconnected mode)
4343
* xref:../../operators/operator_sdk/osdk-generating-csvs.adoc#osdk-hiding-internal-objects_osdk-generating-csvs[Hiding internal objects]
44-
////
4544
* xref:../../installing/installing-fips.adoc#installing-fips[Support for FIPS crytography]
46-
////
4745
4846
include::modules/olm-enabling-operator-restricted-network.adoc[leveloffset=+1]
4947
include::modules/olm-enabling-operator-for-multi-arch.adoc[leveloffset=+1]

security/container_security/security-compliance.adoc

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -13,12 +13,9 @@ standards or the organization's corporate governance framework.
1313

1414
// Compliance and the NIST risk management model
1515
include::modules/security-compliance-nist.adoc[leveloffset=+1]
16-
17-
////
1816
ifndef::openshift-origin[]
1917

2018
[role="_additional-resources"]
2119
.Additional resources
2220
* xref:../../installing/installing-fips.adoc#installing-fips-mode_installing-fips[Installing a cluster in FIPS mode]
2321
endif::[]
24-
////

security/container_security/security-hardening.adoc

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -44,8 +44,6 @@ include::modules/security-hardening-how.adoc[leveloffset=+1]
4444
* xref:../../nodes/nodes/nodes-nodes-managing.adoc#nodes-nodes-kernel-arguments_nodes-nodes-managing[Adding kernel arguments to Nodes]
4545
ifndef::openshift-origin[]
4646
* xref:../../installing/installing_aws/installing-aws-customizations.adoc#installation-configuration-parameters_installing-aws-customizations[Installation configuration parameters] - see `fips`
47+
* xref:../../installing/installing-fips.adoc#installing-fips[Support for FIPS cryptography]
4748
* link:https://access.redhat.com/articles/3359851[{op-system-base} core crypto components]
48-
////
49-
* xref:../../installing/installing-fips.adoc#installing-fips[Support for FIPS cryptography]
50-
////
5149
endif::[]

security/container_security/security-hosts-vms.adoc

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,11 +29,9 @@ include::modules/security-hosts-vms-rhcos.adoc[leveloffset=+1]
2929
* xref:../../installing/install_config/installing-customizing.adoc#installation-special-config-encrypt-disk_installing-customizing[Disk encryption]
3030
* xref:../../installing/install_config/installing-customizing.adoc#installation-special-config-chrony_installing-customizing[Chrony time service]
3131
* xref:../../updating/understanding_updates/intro-to-updates.adoc#update-service-about_understanding-openshift-updates[About the OpenShift Update Service]
32-
////
3332
ifndef::openshift-origin[]
3433
* xref:../../installing/installing-fips.adoc#installing-fips[FIPS cryptography]
3534
endif::[]
36-
////
3735
3836
// Virtualization versus containers
3937
include::modules/security-hosts-vms-vs-containers.adoc[leveloffset=+1]

virt/install/preparing-cluster-for-virt.adoc

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,11 +21,9 @@ IPv6::
2121
You cannot run {VirtProductName} on a single-stack IPv6 cluster.
2222
====
2323

24-
////
2524
.FIPS mode
2625

2726
If you install your cluster in xref:../../installing/installing-fips.adoc#installing-fips-mode_installing-fips[FIPS mode], no additional setup is required for {VirtProductName}.
28-
////
2927

3028
// Section is in assembly so that we can use xrefs
3129
[id="virt-hardware-os-requirements_preparing-cluster-for-virt"]

0 commit comments

Comments
 (0)