---
title: Monitor Ubuntu Advantage FIPS configurations
description: There are multiple ways to enable, manage, and monitor FIPS on Ubuntu.
  You can use the UA Client to enable FIPS, and configure Landscape to audit FIPS
  configurations in your entire Ubuntu estate.
url: https://canonical.com/blog/monitor-ubuntu-advantage-fips-configurations?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Rajan Patel](https://canonical.com/blog/author/rajanpatel927 "More about Rajan Patel")

21 February 2022

# Monitor Ubuntu Advantage FIPS configurations

[FIPS](https://canonical.com/blog/tag/fips)
[Landscape](https://canonical.com/blog/tag/landscape)
[Security certifications and compliance](https://canonical.com/blog/tag/security-certifications-and-compliance)

---

Share the article

In regulated environments, some machines must adhere to strict cryptography requirements designed to protect systems from being cracked, altered, or tampered with. Using cryptographic modules that are FIPS certified or compliant ensure a systems’ encryption solutions adequately protect its digital assets. FIPS validated operating systems are a prerequisite for government agencies, their partners, and those wanting to conduct business with the federal government.

There are multiple ways to enable, manage, and monitor FIPS on Ubuntu.

## Network access control influences the mode for FIPS enablement

FIPS validated operating systems are deployed across two network types:

1. **Connected**: machines have the ability to contact subdomains on canonical.com to stay current with an evolving security baseline
2. **Airgapped**: machines can not reach beyond their local network

You may have some machines which require strict adherence to FIPS validation. There may be other machines that require FIPS compliance and critical vulnerability updates right away, before a formal FIPS certification process can be completed. In that case, network accessibility and the nature of the workload will influence which flavour of FIPS is required.

## FIPS in connected environments

Ubuntu Pro entitlements, associated with your free or paid subscription, can be managed in the Ubuntu Pro dashboard at [ubuntu.com/pro](https://ubuntu.com/pro). FIPS configurations, or access to FIPS Updates, can be associated with a unique token within the Ubuntu Pro dashboard. Running a single `ua attach <token>` command with the appropriate token will enable the entitlements according to your selections on the Ubuntu Pro dashboard, on the target Ubuntu machine. The free tier grants you access to one token, which serves as a default configuration profile for a set of machines. If you do not wish to automatically enable any entitlements, or if you are using Ubuntu Pro and your UA Client is already attached, this tutorial provides a walkthrough of [using the UA Client to enable FIPS](https://ubuntu.com/tutorials/using-the-ua-client-to-enable-fips#1-overview).

### Monitoring FIPS configurations with Landscape

[Landscape](https://ubuntu.com/landscape) is Canonical’s monitoring and management tool for Ubuntu. Organisations incorporate Landscape into their compliance strategies, because of its highly configurable auditing and logging capabilities. In less than 15 minutes, you can configure Landscape to [audit UA Client FIPS configurations](https://ubuntu.com/tutorials/audit-ua-client-fips-configurations-at-scale-with-landscape#1-overview)in your entire Ubuntu estate.

## FIPS in air-gapped environments

Massimiliano Gori, Cybersecurity Compliance Product Manager at Canonical, will discuss [how to enable FIPS on Ubuntu in air-gapped environments](https://ubuntu.com/engage/FIPS-on-Ubuntu-in-air-gapped-environments) in a live webinar which you can attend from the comfort of your own desk. Please mark February 23th at 9 AM PST, 12:00 PM EST on your calendar. We look forward to answering all of your questions about FIPS and Landscape.

#### If you want to learn more

Talk to us about Landscape and our professional services options.

[Contact Us](https://ubuntu.com/landscape#get-in-touch)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Managing Ubuntu on bare metal at scale](https://canonical.com/blog/managing-ubuntu-on-bare-metal-at-scale)

Modern infrastructure teams are expected to deliver cloud-like speed, consistency, and reliability, even when their workloads run on physical servers. Bare metal remains...

[David Beamonte](https://canonical.com/blog/author/dbeamonte)

9 July 2026

[### A year of documentation-driven development](https://canonical.com/blog/a-year-of-documentation-driven-development)

For many software teams, documentation is written after features are built and design decisions have already been made. When that happens, questions about how a feature is...

[Yanisa Haley Scherber](https://canonical.com/blog/author/yanisa-hs)

17 February 2026

[### Announcing FIPS 140-3 for Ubuntu Core22](https://canonical.com/blog/announcing-fips-140-3-for-ubuntu-core22)

FIPS compliance for IoT use cases in Federal space. In this article, we’ll explore what Ubuntu Core is, and how to use it with FIPS.

[Henry Coggill](https://canonical.com/blog/author/henrycoggill)

17 February 2026

[### When an upstream change broke smartcard FIPS authentication – and how we fixed it](https://canonical.com/blog/when-an-upstream-change-broke-smartcard-fips-authentication-and-how-we-fixed-it)

This is the story of how Canonical’s Support team provided bug-fix support: we tracked down an upstream change in OpenSC that inadvertently broke FIPS compatibility,...

[Lidia Luna Puerta](https://canonical.com/blog/author/lidia-luna)

12 February 2026
