Could you please clarify: a) whether this would disallow running BIND compiled with native-pkcs11 option on FIPS mode system with disabled MD5 and SHA1 functions? b) if the answer for a) is yes, whether there's a way how to compile BIND to be operational on such system c) whether there's a way how to compile BIND to adhere to FIPS mode on such system d) why is the startup check better solution than correctly checking for exit codes from the respective functions. There might be temporary errors from HSMs (f.e. network split when using Networked HSM) and that MUST not make BIND to crash.