JiriOndrusek opened a new issue, #9251:
URL: https://github.com/apache/camel-quarkus/issues/9251

   ### Bug description
   
   On a FIPS enabled host, MS SQL Server based tests (e.g. 
`CamelMssqlJdbcTest`) fail because the SQL Server 2025 container image 
(`mcr.microsoft.com/mssql/server:2025-latest`, Ubuntu 24.04 based) crashes 
during its own startup while initializing TLS. The container never becomes 
ready, so Testcontainers/dev services report it as unreachable. This is not a 
Camel Quarkus or JDBC driver problem; the JDBC "connection refused" is only the 
aftermath.
   
   Container log:
   ```
   Server      Error: 49946, Severity: 16, State: 1.
   Server      Internal error occurred initializing the TLS configuration. 
Error code [4].
   Server      Error: 49947, Severity: 16, State: 1.
   Server      Unable to initialize the TLS configuration. The server is being 
shut down.
   ```
   The process exits with code 151.
   
   ### Root cause
   
   `sqlservr` in the 2025 image reads the host kernel flag 
`/proc/sys/crypto/fips_enabled` (shared with the container). When it is `1`, it 
initializes TLS in FIPS mode, but the Ubuntu 24.04 base ships no OpenSSL FIPS 
provider, so initialization fails and the server shuts down. Upstream: 
https://github.com/microsoft/mssql-docker/issues/958 (open, no maintainer 
response). The 2022 image (Ubuntu 22.04) is unaffected and starts on FIPS.
   
   Verified locally by bind-mounting a file containing `1` over 
`/proc/sys/crypto/fips_enabled`:
   - `mssql/server:2025-latest`, flag 1: exit 151, errors 49946/49947
   - `mssql/server:2025-latest`, flag 0: ready for connections
   - `mssql/server:2022-latest`, flag 1: ready for connections
   
   ### Environment
   
   RHEL 8.9 in FIPS mode, OpenJDK 17 (FIPS), Testcontainers 2.0.5, image 
`mcr.microsoft.com/mssql/server:2025-latest`.
   
   ### Affected tests
   
   - `integration-test-groups/jdbc/mssql` (`CamelMssqlJdbcTest`)
   - `integration-tests/jdbc-grouped`
   - `integration-test-groups/debezium/mssql`
   
   ### Proposed fix
   
   Use the SQL Server 2022 image on FIPS only, via the existing `fips` Maven 
profile pattern:
   - root pom `fips` profile overrides `sql-server.container.image` with 
`mcr.microsoft.com/mssql/server:2022-latest`
   - `jdbc/mssql` honours `sql-server.container.image` through the dev service 
`image-name` (as the mysql/oracle/postgresql modules already do)
   
   Regular (non-FIPS) runs keep using 2025-latest. The other two modules read 
the same property, so they are covered automatically


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to