Deploy a FIPS kernel¶
This guide shows you how to deploy an Ubuntu machine with the FIPS-certified kernel. The kernel is available with an Ubuntu Pro subscription.
This guide covers machines that MAAS deploys. To put a MAAS controller into FIPS mode, see Enable FIPS mode on a MAAS controller.
How it works¶
MAAS does not install the FIPS kernel directly. Instead, MAAS deploys Ubuntu with a generic kernel and passes cloud-init user data to the machine. Cloud-init then attaches Ubuntu Pro, installs the FIPS kernel, and reboots the machine.
The sequence is:
MAAS deploys Ubuntu 22.04 LTS with a generic kernel.
The machine reboots and boots from its disk.
The machine requests its configuration from MAAS, and MAAS returns the cloud-init user data.
Cloud-init attaches Ubuntu Pro and enables the FIPS-updates service.
The machine reboots into the FIPS kernel.
MAAS marks the machine as Deployed before cloud-init finishes. Expect a further delay while cloud-init completes and the machine reboots.
Before you begin¶
You need:
An Ubuntu Pro token. Find yours on the Ubuntu Pro dashboard.
Ubuntu 22.04 LTS images synchronized in MAAS.
A machine whose hardware is compatible with the Ubuntu FIPS kernel.
Internet access from the machine. Offline installation of the FIPS kernel is not supported.
Deploy the machine¶
Commission the machine as usual.
Select the machine and choose Deploy.
Select Ubuntu and Ubuntu 22.04 LTS “Jammy Jellyfish”.
Select Cloud-init user-data and paste the template that matches the cloud-init version in your image. Replace
<ubuntu_pro_token>with your token.For cloud-init 24.1 or later:
#cloud-config ubuntu_pro: token: <ubuntu_pro_token> enable: - fips-updates
For cloud-init earlier than 24.1:
#cloud-config package_update: true package_upgrade: true runcmd: - pro attach <ubuntu_pro_token> - yes | pro enable fips-updates
Select Start deployment for machine.
Verify the deployment¶
After the final reboot, log in to the machine and run these checks:
Confirm that the kernel is in FIPS mode:
cat /proc/sys/crypto/fips_enabledThe output is
1when FIPS mode is active.Confirm that the FIPS-updates service is enabled:
sudo pro status
The
fips-updatesrow showsenabled.