fips-mode-setup: Enable FIPS system-wide crypto policy.



  • Take into account the main readme for this section. README first.

    $ sudo fips-mode-setup --enable
    Kernel initramdisks are being regenerated. This might take some time.
    Setting system policy to FIPS
    Note: System-wide crypto policies are applied on application start-up.
    It is recommended to restart the system for the change of policies
    to fully take place.
    FIPS mode will be enabled.
    Please reboot the system for the setting to take effect.
    
    Warning: Using 'update-crypto-policies --set FIPS' is not sufficient for
             FIPS compliance.
             Use 'fips-mode-setup --enable' command instead.
    

    Verify after reboot.

    $ sudo fips-mode-setup --check
    FIPS mode is enabled.
    

Log in to reply
 

© Lightnetics 2024