- Description
- Setup
- > FIPS mode disables md5 hashing at a library level. Enabling it may have unintended consequences.
- > method to consistently configure all SIMP modules with your intended FIPS mode.
- Reference
- Limitations
- Development
This module enables Federal Information Processing Standard(FIPS) mode at the kernel level. FIPS Publication 140-2, is a computer security standard, developed by a U.S. Government and industry working group to validate the quality of cryptographic modules. FIPS publications (including 140-2) can be found at the following URL: http://csrc.nist.gov/publications/PubsFIPS.html. Enabling FIPS mode installs an integrity checking package and modifies ciphers available for applications to use.
This module manages the kernel parameters and packages required for enabling FIPS mode in supported operating systems.
This module is a component of the System Integrity Management Platform, a compliance-management framework built on Puppet.
If you find any issues, they may be submitted to our bug tracker.
WARNING
FIPS mode disables md5 hashing at a library level. Enabling it may have unintended consequences.
- Kernel parameters and Grub
- Dracut and initrd
- Packages:
- nss
- dracut-fips
- fipscheck
Include the fips
class.
- By default, this will enable FIPS mode.
- To ensure that FIPS mode is disabled, set
simp_options::fips
tofalse
.- Do not set
fips::enabled
directly tofalse
―it defaults to the value ofsimp_options::fips
(as do the FIPS-related parameters of all other SIMP modules).
- Do not set
IMPORTANT
Setting
simp_options::fips
to eithertrue
orfalse
is by far the best method to consistently configure all SIMP modules with your intended FIPS mode.
See REFERENCE.md for details.
SIMP Puppet modules are generally intended for use on Red Hat Enterprise Linux
and compatible distributions, such as CentOS. Please see the metadata.json
file
for the most up-to-date list of supported operating systems, Puppet versions,
and module dependencies.
Please read our Contribution Guide.
This module includes Beaker acceptance tests using the SIMP Beaker Helpers.
By default the tests use Vagrant with VirtualBox as a back-end; Vagrant and VirtualBox must both be installed to run these tests without modification. To execute the tests run the following:
bundle install
bundle exec rake beaker:suites
Please refer to the SIMP Beaker Helpers documentation for more information.