Re: Fips Module Config
[email protected] Wed, 29 Oct 2025 02:55:17 -0400
| Newsgroups | gmane.linux.debian.devel.security |
|---|---|
| Message-ID | <[email protected]> |
--=_KT8t5MQeKsW9rND2DEe0lU_= Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Debian=E2=80=99s OpenSSL 3.x (as in Trixie and Bookworm) uses the new provider-based architecture, and openssl-provider-fips is exactly what enables FIPS 140-2 mode. However, OpenSSL itself doesn=E2=80=99t = automatically go into =E2=80=9CFIPS mode=E2=80=9D just because you installed the module; it = needs to be explicitly configured and validated. On Wed, Oct 29, 2025 at 3:17=E2=80=AFAM Robert A Wooldridge < [email protected]> wrote: > Hello, My company has been using Debian servers since 2002. We have US = Gov > contracts and in the near future would like to make some of our servers > fips 140-2 compliant. I have a test server set up usi > *DuckDuckGo* did not detect any trackers. More > <https://duckduckgo.com/-s1GamK2LlA9I-PlJqZd7ZSQHrB-OEMwY3NWx3FImUcOP5iiq= ScsTWfYFZfdXCMPjKzywpBzQCAEqcYQ4sRZa_0ILKAdKMVnBwvTzxuecRwnyBMj4oWs55w9Ha3b= nbnfHdYLlIMFTTmr7eqwP64pyBPqg2ktacFLA0Po5cVf4IXBl8w8E5ueIaYE8JSo-HiS0uJ15ju= r9VoK2tRNFoBYKCQpoLuNs6-wsjbJCr7LYgQ> > Unable to verify sender identity > Report Spam > <https://duckduckgo.com/-s1GamK2LlA9I-PlJqZd7ZSQHrB-OEMwY3NWx3FImUcOP5iiq= ScsTWfYFZfdXCMPjKzywpBzQCAEqcYQ4sRZa_0ILKAdKMVnBwvTzxuecRwnyBMj4oWs55w9Ha3b= nbnfHdYLlIMFTTmr7eqwP64pyBPqg2ktacFLA0Po5cVf4IXBl8w8E5ueIaYE8JSo-HiS0uJ15ju= r9VoK2tRNFoBYKCQpoLuNs6-wsjbJCr7LYgQ> > > Hello, > > My company has been using Debian servers since 2002. We have US Gov > contracts and in the near future would like to make some of our servers > fips 140-2 compliant. I have a test server set up using Trixie but I'm > having trouble understanding how to configure openssl with the fips > module. > > I have installed openssl-provider-fips package which I see provides > /usr/lib/x86_64-linux-gnu/ossl-modules/fips.so and I've generated a > fips.cnf file as well as updated /etc/ssl/openssl.cnf but I'm not sure = what > to do after this. Can you someone give me some tips or point me in the > right direction? > > > > -- > *Bob Wooldridge* > [email protected] <[email protected]> > *EDM Incorporated* > --=_KT8t5MQeKsW9rND2DEe0lU_= Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <html><head></head><body><div dir=3D"auto"><span style=3D"font-family:-appl= e-system,sans-serif"><div> <div> <p>Debian’s OpenSSL 3.x (as in = Trixie and Bookworm) uses the new provider-based architecture, and = openssl-provider-fips is exactly what enables FIPS 140-2 mode. However, = OpenSSL itself doesn’t automatically go into “FIPS = mode” just because you installed the module; it needs to be = explicitly configured and validated.</p> </div> </div><br></span></div><div= dir=3D"auto"><span style=3D"font-family:-apple-system,sans-serif">On Wed, = Oct 29, 2025 at 3:17 AM Robert A Wooldridge <<a = href=3D"mailto:[email protected]">bob.= [email protected]</a>> = wrote:</span><br></div><div><div class=3D"gmail_quote = gmail_quote_container"><blockquote class=3D"gmail_quote" style=3D"margin:0 = 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><u></u> =20 =20 <div><div> </div> <p>Hello,</p> <p>My company has been using = Debian servers since 2002. We have US Gov contracts and in the = near future would like to make some of our servers fips 140-2 = compliant. I have a test server set up using Trixie but I'm = having trouble understanding how to configure openssl with the fips = module. </p> <p>I have installed <span = style=3D"color:#000000;background-color:#ffffff">openssl-provider-fips</spa= n> package<span style=3D"font-family:monospace"> </span>which I = see provides<span style=3D"font-family:monospace"> </span><span = style=3D"color:#000000;background-color:#ffffff">/usr/lib/x86_64-linux-gnu/= ossl-modules/fips.so</span> and I've generated a fips.cnf file = as well as updated /etc/ssl/openssl.cnf but I'm not sure what to do = after this. Can you someone give me some tips or point me in = the right direction?</p></div><div> <p><br> </p> <p><br> </p> <div>-- <br> =20 =20 <font color=3D"#000000"> = </font></div> <div><b>Bob Wooldridge</b><br> <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a><br> <i>EDM = Incorporated</i></div> =20 </div></blockquote></div></div> </body></html> --=_KT8t5MQeKsW9rND2DEe0lU_=--