RADIUS, which is being used internally by ipa-otpd daemon for OTP authentication, uses MD5 checksums during the authentication process.
A possible solution to this would be to implement EAP for RADIUS so that MD5 does not have to be used.
Metadata Update from @stlaz: - Issue tagged with: rfe
Metadata Update from @pvoborni: - Issue priority set to: normal - Issue set to the milestone: Future Releases
This BZ could be linked with https://bugzilla.redhat.com/show_bug.cgi?id=1544679 which has further context. Note that thanks to https://github.com/freeipa/freeipa/pull/1621 it seems that we can make OTP&Radius "work in FIPS mode", though not being necessarily FIPS compliant - see https://github.com/freeipa/freeipa/pull/1621 for details.
master:
Metadata Update from @rcritten: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
ipa-4-6:
ipa-4-5: