Enable FIPS mode on a MAAS controller¶
This guide shows you how to put a MAAS controller host into FIPS mode and confirm that MAAS has detected it. When MAAS detects FIPS mode, it activates security hardening and the FIPS-only controls on that controller.
To deploy a FIPS kernel to a machine that MAAS manages, see Deploy a FIPS kernel instead.
Note
MAAS is distributed as a snap on the core26 base. core26 is not yet FIPS-certified, so the cryptographic libraries inside the snap are not FIPS-validated. The host kernel can still run in FIPS mode, and MAAS applies every FIPS-conditional control. See FIPS-validated cryptography in the snap.
Before you begin¶
You need:
An Ubuntu Pro token. Find yours on the Ubuntu Pro dashboard.
Administrator (
sudo) access to the controller host.A maintenance window. The host must reboot.
Plan to enable FIPS mode on every controller in the deployment. Once one region controller starts in FIPS mode, every region controller that is not in FIPS mode reports a FIPS_CONFIG_STATUS_MISMATCH violation.
Enable FIPS mode¶
Attach the host to Ubuntu Pro:
sudo pro attach <ubuntu_pro_token>
Enable the FIPS-updates service:
sudo pro enable fips-updates
Reboot the host:
sudo reboot
Confirm FIPS mode on the host¶
After the reboot, check the kernel state:
cat /proc/sys/crypto/fips_enabled
The output is 1 when FIPS mode is active.
Confirm that MAAS detected FIPS mode¶
On a region controller, try to turn hardening off:
sudo maas config-hardening disable
On a FIPS host, MAAS refuses with the following message:
Cannot disable hardening on a FIPS-enabled host. Hardening is mandatory when FIPS mode is active.
You can also check the startup log:
journalctl -t maas-regiond | grep -E 'fips_mode_detected|hardening_mode_determined'
Look for fips_mode=True and hardening_active=True.
Confirm the state through the API¶
Any authenticated user can read the FIPS and hardening state of a controller.
Get an access token:
read -rsp "MAAS password: " MAAS_PASSWORD; echo TOKEN=$(curl -s --cacert ca.pem -X POST "https://<maas-host>:5443/MAAS/a/v3/auth/login" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "username=<your-username>" \ --data-urlencode "password=${MAAS_PASSWORD}" | jq -r '.access_token')
Read the system information:
curl -s --cacert ca.pem "https://<maas-host>:5443/MAAS/a/v3/system/info" \ -H "Authorization: Bearer $TOKEN"
On a FIPS host, the response is:
{"fips_active": true, "hardening_active": true, "version": "3.7.0"}
The response describes the controller that answered the request. See Reported state.
Complete the hardening configuration¶
Hardening is now active on the controller. Any missing prerequisite appears as an error notification for administrators. Run validation to list them:
sudo maas config-hardening validate
To resolve each item, see Activate MAAS hardening.
FIPS mode adds controls that may require further action:
Replace any public API TLS certificate that uses a weak key or signature. See Replace a weak TLS certificate.
Add trusted host keys for machines that use SSH-based power drivers. See Manage trusted SSH host keys.
Move machines off power drivers that are rejected in FIPS mode. See Power drivers.
Set the default IPMI cipher suite to
17before you commission machines. Commissioning writes this setting into each machine’s power configuration, and its default is3, which FIPS mode rejects:maas $PROFILE maas set-config name=maas_auto_ipmi_cipher_suite_id value=17
If MAAS already manages machines, users, and keys, read Adopt FIPS mode on an existing deployment before you enable FIPS mode. MAAS does not validate material that is already stored.