@@ -133,15 +133,14 @@ RUN cd /usr/src/openbfdd && \
133133 ./configure --enable-silent-rules && \
134134 make
135135
136- ENV OPENSSL_FIPS_LIBDIR=/usr/local/openssl-fips/lib
137- ENV LD_LIBRARY_PATH=$OPENSSL_FIPS_LIBDIR:$LD_LIBRARY_PATH
136+ ENV LD_LIBRARY_PATH=/usr/local/openssl-fips/lib64:$LD_LIBRARY_PATH
138137RUN wget https://www.openssl.org/source/openssl-3.0.13.tar.gz && \
139138 tar -xzf openssl-3.0.13.tar.gz && \
140139 cd openssl-3.0.13 && \
141140 ./config --prefix=/usr/local/openssl-fips enable-fips && \
142141 make -j8 && \
143142 make install && \
144- /usr/local/openssl-fips/bin/openssl fipsinstall -module $OPENSSL_FIPS_LIBDIR /ossl-modules/fips.so -out /usr/local/openssl-fips/ssl/fipsmodule.cnf
143+ /usr/local/openssl-fips/bin/openssl fipsinstall -module /usr/local/openssl-fips/lib64 /ossl-modules/fips.so -out /usr/local/openssl-fips/ssl/fipsmodule.cnf
145144
146145RUN mkdir /packages/ && \
147146 mv /usr/src/openbfdd/bfdd-beacon /usr/src/openbfdd/bfdd-control /packages/ && \
@@ -234,8 +233,8 @@ RUN --mount=type=bind,target=/packages,from=ovs-builder,source=/packages \
234233COPY --from=ovs-builder /usr/local/openssl-fips /usr/local/openssl-fips
235234# env OPENSSL_CONF is only work when user is root, not effect when user is nobody, maybe openssl bug, so we copy openssl binary and libraries to /usr/bin and /usr/lib/x86_64-linux-gnu
236235RUN cp /usr/local/openssl-fips/bin/openssl /usr/bin/openssl && \
237- cp $OPENSSL_FIPS_LIBDIR /libssl.so.3 /usr/lib/x86_64-linux-gnu/libssl.so.3 && \
238- cp $OPENSSL_FIPS_LIBDIR /libcrypto.so.3 /usr/lib/x86_64-linux-gnu/libcrypto.so.3 && \
239- cp $OPENSSL_FIPS_LIBDIR /ossl-modules/fips.so /usr/lib/x86_64-linux-gnu/ossl-modules/
236+ cp /usr/local/openssl-fips/lib64 /libssl.so.3 /usr/lib/x86_64-linux-gnu/libssl.so.3 && \
237+ cp /usr/local/openssl-fips/lib64 /libcrypto.so.3 /usr/lib/x86_64-linux-gnu/libcrypto.so.3 && \
238+ cp /usr/local/openssl-fips/lib64 /ossl-modules/fips.so /usr/lib/x86_64-linux-gnu/ossl-modules/
240239
241240ENTRYPOINT ["/usr/bin/dumb-init", "--"]
0 commit comments