Re: Fips Module Config

[email protected] Wed, 29 Oct 2025 02:55:17 -0400
Newsgroups gmane.linux.debian.devel.security
Message-ID <[email protected]>
--=_KT8t5MQeKsW9rND2DEe0lU_=
Content-Type: text/plain;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Debian=E2=80=99s OpenSSL 3.x (as in Trixie and Bookworm) uses the new
provider-based architecture, and openssl-provider-fips is exactly what
enables FIPS 140-2 mode. However, OpenSSL itself doesn=E2=80=99t =
automatically go
into =E2=80=9CFIPS mode=E2=80=9D just because you installed the module; it =
needs to be
explicitly configured and validated.

On Wed, Oct 29, 2025 at 3:17=E2=80=AFAM Robert A Wooldridge <
[email protected]> wrote:

> Hello, My company has been using Debian servers since 2002. We have US =
Gov
> contracts and in the near future would like to make some of our servers
> fips 140-2 compliant. I have a test server set up usi
> *DuckDuckGo* did not detect any trackers. More
> <https://duckduckgo.com/-s1GamK2LlA9I-PlJqZd7ZSQHrB-OEMwY3NWx3FImUcOP5iiq=
ScsTWfYFZfdXCMPjKzywpBzQCAEqcYQ4sRZa_0ILKAdKMVnBwvTzxuecRwnyBMj4oWs55w9Ha3b=
nbnfHdYLlIMFTTmr7eqwP64pyBPqg2ktacFLA0Po5cVf4IXBl8w8E5ueIaYE8JSo-HiS0uJ15ju=
r9VoK2tRNFoBYKCQpoLuNs6-wsjbJCr7LYgQ>
> Unable to verify sender identity
> Report Spam
> <https://duckduckgo.com/-s1GamK2LlA9I-PlJqZd7ZSQHrB-OEMwY3NWx3FImUcOP5iiq=
ScsTWfYFZfdXCMPjKzywpBzQCAEqcYQ4sRZa_0ILKAdKMVnBwvTzxuecRwnyBMj4oWs55w9Ha3b=
nbnfHdYLlIMFTTmr7eqwP64pyBPqg2ktacFLA0Po5cVf4IXBl8w8E5ueIaYE8JSo-HiS0uJ15ju=
r9VoK2tRNFoBYKCQpoLuNs6-wsjbJCr7LYgQ>
>
> Hello,
>
> My company has been using Debian servers since 2002.  We have US Gov
> contracts and in the near future would like to make some of our servers
> fips 140-2 compliant.  I have a test server set up using Trixie but I'm
> having trouble understanding how to configure openssl with the fips
> module.
>
> I have installed openssl-provider-fips package which I see provides
> /usr/lib/x86_64-linux-gnu/ossl-modules/fips.so and I've generated a
> fips.cnf file as well as updated /etc/ssl/openssl.cnf but I'm not sure =
what
> to do after this.  Can you someone give me some tips or point me in the
> right direction?
>
>
>
> --
> *Bob Wooldridge*
> [email protected] <[email protected]>
> *EDM Incorporated*
>


--=_KT8t5MQeKsW9rND2DEe0lU_=
Content-Type: text/html;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<html><head></head><body><div dir=3D"auto"><span style=3D"font-family:-appl=
e-system,sans-serif"><div>
<div>
<p>Debian&#x2019;s OpenSSL 3.x (as in =
Trixie and Bookworm) uses the new provider-based architecture, and =
openssl-provider-fips is exactly what enables FIPS 140-2 mode. However, =
OpenSSL itself doesn&#x2019;t automatically go into &#x201C;FIPS =
mode&#x201D; just because you installed the module; it needs to be =
explicitly configured and validated.</p>
</div>
</div><br></span></div><div=
 dir=3D"auto"><span style=3D"font-family:-apple-system,sans-serif">On Wed, =
Oct 29, 2025 at 3:17&#x202F;AM Robert A Wooldridge &lt;<a =
href=3D"mailto:[email protected]">bob.=
[email protected]</a>&gt; =
wrote:</span><br></div><div><div class=3D"gmail_quote =
gmail_quote_container"><blockquote class=3D"gmail_quote" style=3D"margin:0 =
0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><u></u>

   =20
 =20
  <div><div>
</div>
    <p>Hello,</p>
    <p>My company has been using =
Debian servers since 2002.&nbsp; We have US
      Gov contracts and in the =
near future would like to make some of
      our servers fips 140-2 =
compliant.&nbsp; I have a test server set up
      using Trixie but I'm =
having trouble understanding how to configure
      openssl with the fips =
module.&nbsp;&nbsp;</p>
    <p>I have installed&nbsp;<span =
style=3D"color:#000000;background-color:#ffffff">openssl-provider-fips</spa=
n>&nbsp;package<span style=3D"font-family:monospace">&nbsp;</span>which I =
see provides<span style=3D"font-family:monospace">&nbsp;</span><span =
style=3D"color:#000000;background-color:#ffffff">/usr/lib/x86_64-linux-gnu/=
ossl-modules/fips.so</span>&nbsp;and
      I've generated a fips.cnf file =
as well as updated
      /etc/ssl/openssl.cnf but I'm not sure what to do =
after this.&nbsp; Can
      you someone give me some tips or point me in =
the right direction?</p></div><div>
    <p><br>
    </p>
    <p><br>
    </p>
    <div>-- <br>
     =20
     =20
      <font color=3D"#000000"> =
</font></div>
    <div><b>Bob
        Wooldridge</b><br>
      <a href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a><br>
      <i>EDM =
Incorporated</i></div>
 =20


</div></blockquote></div></div>
</body></html>

--=_KT8t5MQeKsW9rND2DEe0lU_=--