FIPS mode reference¶
This page lists the controls that MAAS applies only when the host kernel is in FIPS mode. For background, see FIPS mode and security hardening. To enable FIPS mode on a controller, see Enable FIPS mode on a MAAS controller.
FIPS mode always activates security hardening. The controls in the Security hardening reference therefore also apply on a FIPS host.
Detection¶
Item |
Value |
|---|---|
Source |
|
FIPS mode active |
File content is |
File missing |
Not in FIPS mode |
File unreadable |
Not in FIPS mode, and a |
When read |
Once per process, at startup |
Reported state¶
MAAS reports its FIPS and hardening state through the v3 API.
Item |
Value |
|---|---|
Path |
|
Permission |
Any authenticated user |
Response fields |
|
Field |
Type |
Meaning |
|---|---|---|
|
boolean |
The kernel of the controller that answered the request is in FIPS mode. |
|
boolean |
Security hardening is active on that controller. |
|
string |
MAAS version, such as |
The values are resolved when MAAS starts. After you change hardening_enabled, restart MAAS before you read the endpoint again.
In a high availability deployment, the response describes the controller that answered the request. Query each controller in turn to audit the whole fleet.
Summary of FIPS-conditional controls¶
Area |
Control |
|---|---|
Security hardening |
Always active. |
Public API TLS |
Certificate must meet the TLS certificate rules. Otherwise |
Web server TLS |
Only FIPS-approved cipher suites and curves are offered. |
SSH sessions |
Only FIPS-approved algorithms are negotiated. |
SSH host keys |
Unknown host keys are rejected. Trust on first use is turned off. |
User SSH keys |
Must use an approved key type and size. |
User SSL keys |
Must meet the TLS certificate rules. |
Power drivers |
Non-compliant drivers and settings are rejected. |
Password policy |
Always enforced. |
Fleet drift |
|
Web server TLS¶
When TLS is enabled on a FIPS host, the region controller web server uses these settings:
Setting |
Value |
|---|---|
Protocols |
TLS 1.2, TLS 1.3 |
TLS 1.3 cipher suites |
|
TLS 1.2 cipher suites |
|
Elliptic curves |
|
On a non-FIPS host, MAAS additionally offers ChaCha20-Poly1305 suites and the X25519 curve.
TLS certificates¶
These rules apply to the public API certificate and to SSL keys that users add for Windows WinRM access.
Property |
Allowed |
|---|---|
Key type |
RSA or ECDSA |
RSA key size |
2048 bits or larger |
Signature algorithm |
SHA-256 or stronger |
Rejected: DSA, Ed25519, and Ed448 keys; RSA keys under 2048 bits; SHA-1 and MD5 signatures.
SSH¶
Session algorithms¶
MAAS-initiated SSH sessions negotiate only the following algorithms. These sessions are used by SSH-based power drivers, such as hmc, mscm, and wedge.
Type |
Allowed algorithms |
|---|---|
Ciphers |
|
Key exchange |
|
MACs |
|
Host key algorithms |
|
If the remote device offers no allowed cipher or MAC, the connection fails and MAAS logs a fips_crypto_error event with operation=ssh_negotiation.
Host key verification¶
Host state |
Behavior for a host key that is not already known |
|---|---|
Not in FIPS mode |
Accepted |
FIPS mode |
Accepted only if it matches a trusted SSH host key. Otherwise rejected, and a |
A trusted host key matches when all three of these fields are equal:
host: the power address configured for the machine.key_type: the key type reported by the device, such asssh-rsaorecdsa-sha2-nistp256.public_key: the Base64-encoded public key.
If MAAS cannot look up the trusted keys, it rejects the connection.
Trusted SSH host keys API¶
Trusted SSH host keys can be managed in the web UI or through the MAAS v3 API.
Method |
Path |
Permission |
Description |
|---|---|---|---|
|
|
View global entities |
List trusted host keys. Supports pagination. |
|
|
View global entities |
Get one trusted host key. |
|
|
Edit global entities |
Add a trusted host key. |
|
|
Edit global entities |
Replace a trusted host key. Accepts an |
|
|
Edit global entities |
Remove a trusted host key. Accepts an |
Request body fields:
Field |
Required |
Description |
|---|---|---|
|
Yes |
Host name or IP address. 1–255 characters. Must match the machine’s power address exactly. |
|
Yes |
One of |
|
Yes |
Base64-encoded public key, without the key type or comment. |
|
No |
Free-text label. Up to 255 characters. |
On a FIPS host, key_type and public_key must also pass the public key rules. Because SSH sessions negotiate only the host key algorithms listed above, store RSA or ECDSA P-256 host keys.
Public SSH keys¶
These rules apply on a FIPS host to SSH keys that users add, and to trusted SSH host keys.
Key type |
Allowed |
|---|---|
|
Yes, if the key is 2048 bits or larger |
|
Yes |
|
Yes |
|
Yes |
Any other type, including |
No |
If MAAS cannot determine the size of an RSA key, it rejects the key.
Power drivers¶
On a FIPS host, MAAS validates power configuration when you create or update a machine or a VM host. A failure returns a validation error that includes the reason and a list of compliant drivers. MAAS also logs a fips_driver_rejected event when it rejects a driver.
Driver status¶
Driver |
FIPS status |
Reason |
|---|---|---|
|
Supported |
|
|
Supported |
|
|
Supported |
Requires SSL verification |
|
Supported |
Requires cipher suite 17 |
|
Supported |
|
|
Supported |
|
|
Supported |
|
|
Supported |
|
|
Supported |
Requires SSL verification |
|
Supported |
|
|
Supported |
|
|
Supported |
|
|
Supported |
Requires SSL verification |
|
Supported |
|
|
Rejected |
SNMPv1, no FIPS-approved authentication |
|
Rejected |
Plain HTTP basic authentication |
|
Rejected |
SNMPv1, no FIPS-approved authentication |
|
Rejected |
IPMI without cipher suite 17 support |
|
Rejected |
Plain HTTP basic authentication |
|
Rejected |
SNMPv2c, community string only |
|
Rejected |
Plain HTTP, no TLS |
|
Rejected |
Plain HTTP, no TLS |
|
Rejected |
HTTP XML API, no TLS |
Any other driver |
Rejected |
FIPS compliance not verified |
Driver settings¶
Driver |
Setting |
Required value |
|---|---|---|
|
|
|
|
|
|
The password policy also applies to power_pass, because hardening is always active on a FIPS host.
Fleet drift¶
Item |
Value |
|---|---|
Database key |
|
Set by |
A region controller that starts in FIPS mode |
Cleared by |
Nothing. The flag cannot be cleared with |
Violation |
|
Log events¶
FIPS events use the maas.fips logger.
Event |
Level |
Fields |
Emitted when |
|---|---|---|---|
|
|
|
A process reads the FIPS state. |
|
|
|
|
|
|
|
MAAS completes an outgoing TLS handshake on a FIPS host. |
|
|
|
MAAS completes an SSH connection on a FIPS host. |
|
|
|
SSH negotiation fails or a host key is not trusted. |
|
|
|
MAAS rejects a power driver. |