Fips Module Config

Robert A Wooldridge <[email protected]> Tue, 28 Oct 2025 16:40:34 -0500
Newsgroups gmane.linux.debian.devel.security
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------9i0jFl7FLgPlPvKP0IPxU60c
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Hello,

My company has been using Debian servers since 2002.  We have US Gov 
contracts and in the near future would like to make some of our servers 
fips 140-2 compliant.  I have a test server set up using Trixie but I'm 
having trouble understanding how to configure openssl with the fips module.

I have installed openssl-provider-fips packagewhich I see 
provides/usr/lib/x86_64-linux-gnu/ossl-modules/fips.so and I've 
generated a fips.cnf file as well as updated /etc/ssl/openssl.cnf but 
I'm not sure what to do after this.  Can you someone give me some tips 
or point me in the right direction?



-- 
*Bob Wooldridge*
[email protected] <mailto:[email protected]>
/EDM Incorporated/
--------------9i0jFl7FLgPlPvKP0IPxU60c
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Hello,</p>
    <p>My company has been using Debian servers since 2002.  We have US
      Gov contracts and in the near future would like to make some of
      our servers fips 140-2 compliant.  I have a test server set up
      using Trixie but I'm having trouble understanding how to configure
      openssl with the fips module.  </p>
    <p>I have installed <span
        style="color:#000000;background-color:#ffffff;">openssl-provider-fips</span> package<span
        style="font-family:monospace"> </span>which I see provides<span
        style="font-family:monospace"> </span><span
        style="color:#000000;background-color:#ffffff;">/usr/lib/x86_64-linux-gnu/ossl-modules/fips.so</span> and
      I've generated a fips.cnf file as well as updated
      /etc/ssl/openssl.cnf but I'm not sure what to do after this.  Can
      you someone give me some tips or point me in the right direction?</p>
    <p><br>
    </p>
    <p><br>
    </p>
    <div class="moz-signature">-- <br>
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <title></title>
      <font color="#000000"> </font></div>
    <div class="moz-signature"
      signature-switch-id="41e02136-7a13-42be-8270-16e6f2a4e6e9"><b>Bob
        Wooldridge</b><br>
      <a href="mailto:[email protected]">[email protected]</a><br>
      <i>EDM Incorporated</i></div>
  </body>
</html>

--------------9i0jFl7FLgPlPvKP0IPxU60c--