FIPS Mode
FIPS mode restricts the system to cryptographic modules that have been validated against the FIPS 140-3 standard (OpenSSL, GnuTLS, NSS, the kernel crypto API, and so on). It is a hard requirement for US federal systems and many finance and healthcare compliance regimes. EL ships complete FIPS support, and once enabled, crypto-policies governs the policy for every crypto component.
What FIPS Mode Changes
Section titled “What FIPS Mode Changes”After enabling:
- crypto-policies switches to the
FIPSsubpolicy; OpenSSL, GnuTLS, and other libraries automatically disable unvalidated algorithms (MD5, DES, RC4, and more) - The kernel crypto API enters FIPS mode and runs self-tests at boot
- Calls to non-compliant algorithms fail loudly instead of silently degrading
RHEL 8/9: Enable with fips-mode-setup
Section titled “RHEL 8/9: Enable with fips-mode-setup”$ sudo fips-mode-setup --enable$ sudo systemctl reboot$ fips-mode-setup --checkFIPS mode is enabled.$ update-crypto-policies --showFIPSTo turn it off:
$ sudo fips-mode-setup --disable$ sudo systemctl rebootRHEL 10: Use the Kernel Parameter
Section titled “RHEL 10: Use the Kernel Parameter”From RHEL 10 onward fips-mode-setup is deprecated. The standard method sets the fips=1 kernel boot parameter:
$ sudo grubby --update-kernel=ALL --args="fips=1"$ sudo systemctl reboot$ cat /proc/sys/crypto/fips_enabled1$ update-crypto-policies --showFIPSOn AlmaLinux / Rocky Linux
Section titled “On AlmaLinux / Rocky Linux”The rebuilds include the same crypto-policies and kernel FIPS support, and enabling works the same way. One caveat: whether modules count as “validated” depends on each distribution’s own FIPS validation status. For strict compliance, confirm the validation list and scope of the distribution you use — when in doubt, use RHEL (whose validation carries Red Hat’s official backing).
Cloud and Image Workflows
Section titled “Cloud and Image Workflows”- Major clouds offer official images with FIPS pre-enabled — search for “FIPS” images and new instances start compliant
- With Image Mode / bootc, declare it in the Containerfile:
FROM registry.redhat.io/rhel10/rhel-bootc:latest
RUN mkdir -p /etc/kernel/cmdline.d && \ echo "fips=1" > /etc/kernel/cmdline.d/fips.conf && \ update-crypto-policies --set FIPSApplications fail under FIPS — now what?
Section titled “Applications fail under FIPS — now what?”Errors like digital envelope routines::unsupported mean the application called an unvalidated algorithm (MD5, old TLS versions). In order: upgrade to a FIPS-capable application version, reconfigure the app to use compliant algorithms, then report the gap to the vendor or Red Hat. Do not switch back to the DEFAULT policy to silence errors — that forfeits compliance for the whole system.
How do FIPS and OpenSCAP relate?
Section titled “How do FIPS and OpenSCAP relate?”They complement each other: OpenSCAP scans configuration against CIS/PCI baselines, while FIPS is the system-level implementation of the cryptography items within those baselines. Audit scripts commonly check fips-mode-setup --check. OpenSCAP compliance scanning can automate this check.
What should I check before enabling?
Section titled “What should I check before enabling?”- Enable on a fresh system or during a reboot window — the switch involves kernel arguments and self-tests, so earlier is easier
- Inventory your crypto library dependencies first; old applications (early JDK 8, legacy OpenSSL bindings) are the most likely to break
- Switch cluster members (controller/worker) in one pass — never mix states
Further Reading
Section titled “Further Reading”- OpenSCAP Compliance — Automate compliance checks with baseline scanning
- Server Baseline — General hardening beyond FIPS
- Image Mode (bootc) — Declare FIPS inside your OS image