Skip to content

FIPS Mode

FIPS mode restricts the system to cryptographic modules that have been validated against the FIPS 140-3 standard (OpenSSL, GnuTLS, NSS, the kernel crypto API, and so on). It is a hard requirement for US federal systems and many finance and healthcare compliance regimes. EL ships complete FIPS support, and once enabled, crypto-policies governs the policy for every crypto component.

After enabling:

  • crypto-policies switches to the FIPS subpolicy; OpenSSL, GnuTLS, and other libraries automatically disable unvalidated algorithms (MD5, DES, RC4, and more)
  • The kernel crypto API enters FIPS mode and runs self-tests at boot
  • Calls to non-compliant algorithms fail loudly instead of silently degrading
Enable FIPS mode and reboot to take effect
$ sudo fips-mode-setup --enable
$ sudo systemctl reboot
Verify after reboot
$ fips-mode-setup --check
FIPS mode is enabled.
$ update-crypto-policies --show
FIPS

To turn it off:

Disable FIPS mode
$ sudo fips-mode-setup --disable
$ sudo systemctl reboot

From RHEL 10 onward fips-mode-setup is deprecated. The standard method sets the fips=1 kernel boot parameter:

Enable FIPS on RHEL 10: add the kernel argument and reboot
$ sudo grubby --update-kernel=ALL --args="fips=1"
$ sudo systemctl reboot
Verify FIPS status on RHEL 10
$ cat /proc/sys/crypto/fips_enabled
1
$ update-crypto-policies --show
FIPS

The rebuilds include the same crypto-policies and kernel FIPS support, and enabling works the same way. One caveat: whether modules count as “validated” depends on each distribution’s own FIPS validation status. For strict compliance, confirm the validation list and scope of the distribution you use — when in doubt, use RHEL (whose validation carries Red Hat’s official backing).

  • Major clouds offer official images with FIPS pre-enabled — search for “FIPS” images and new instances start compliant
  • With Image Mode / bootc, declare it in the Containerfile:
Enable FIPS inside a bootc image
FROM registry.redhat.io/rhel10/rhel-bootc:latest
RUN mkdir -p /etc/kernel/cmdline.d && \
echo "fips=1" > /etc/kernel/cmdline.d/fips.conf && \
update-crypto-policies --set FIPS

Applications fail under FIPS — now what?

Section titled “Applications fail under FIPS — now what?”

Errors like digital envelope routines::unsupported mean the application called an unvalidated algorithm (MD5, old TLS versions). In order: upgrade to a FIPS-capable application version, reconfigure the app to use compliant algorithms, then report the gap to the vendor or Red Hat. Do not switch back to the DEFAULT policy to silence errors — that forfeits compliance for the whole system.

They complement each other: OpenSCAP scans configuration against CIS/PCI baselines, while FIPS is the system-level implementation of the cryptography items within those baselines. Audit scripts commonly check fips-mode-setup --check. OpenSCAP compliance scanning can automate this check.

  • Enable on a fresh system or during a reboot window — the switch involves kernel arguments and self-tests, so earlier is easier
  • Inventory your crypto library dependencies first; old applications (early JDK 8, legacy OpenSSL bindings) are the most likely to break
  • Switch cluster members (controller/worker) in one pass — never mix states