FIPS Mode: Difference between revisions

From OSNEXUS Online Documentation Site
Jump to navigation Jump to search
m Move to the Administrator Guide: FIPS mode is appliance security configuration, not client-side access (QSTOR-12352)
m Rewrite from the product: remove the 'FIPS 140-3 cert pending' claim and state the real position (140-2 module validation, no 140-3 product certification, SED FDE on FIPS 140-3 media for deployments requiring certification); document the active/ symlink switch and the two OpenSSL versions (3.1.2 FIPS, 3.5.7 general) verified on a 6.9 build; add the three FIPS state values, the reboot requirement, and verification from the WUI, CLI and crypto log; fix the inverted heading levels (QSTOR-12352)
 
Line 1: Line 1:
[[Category:admin_guide]]
[[Category:admin_guide]]
=== QuantaStor FIPS 140-2 Module ===
QuantaStor can run its cryptographic operations through a FIPS-validated module. Enabling '''FIPS mode''' switches the appliance from its general-purpose OpenSSL libraries to the FIPS build, runs power-on self tests and integrity checks, and refuses to start the QuantaStor service if those checks fail. This page covers what FIPS mode does, how to enable and verify it, and -- importantly -- what it does and does not certify.
QuantaStor supports FIPS cryptographic standards for NIST standard FIPS 140-2. More information on the 'OSNEXUS Crypto Library' is available at the NIST web site [https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4185 here]. The OSNEXUS Crypto Library FIPS 140-2 Non-proprietary Security Policy can be found [https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4185.pdf here], and the official certificate [https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/March%202022_010422_0648_signed.pdf here]. This page will be updated with instructions to configure your QuantaStor system to enable FIPS mode.


=== Enabling FIPS Mode ===
Read '''[[#Certification status|Certification status]]''' first if you are evaluating QuantaStor against a compliance requirement. The distinction between a *FIPS-validated cryptographic module* and a *FIPS-certified product* matters, and it decides which approach fits your deployment.
To run Quantastor in FIPS mode, '''it is required that all of the nodes in your storage grid are running qstor-service version "6.0.11"''' (FIPS 140-3 cert pending for 6.1 and beyond). If any of your nodes do not meet this requirement, then the storage systems on your grid will be automatically set into FIPS Non-Approved mode. To enable or disable FIPS mode, you will need to use the 'qs-util' CLI tool. Run the following commands as the 'root' user on the QuantaStor system to be put into FIPS mode.  
 
<pre>
{| class="wikitable"
## enables FIPS mode and restarts the quantastor service
! Section !! Covers
# sudo qs-util enablefips
|-
## disables FIPS mode and restarts the quantastor service
| [[#Certification status|Certification status]] || What is validated, what is not, and what to use when certification is required
# sudo qs-util disablefips
|-
| [[#What FIPS Mode Changes|What FIPS Mode Changes]] || The library switch, and the two OpenSSL versions involved
|-
| [[#Enabling FIPS Mode|Enabling FIPS Mode]] || The procedure, including the required restart
|-
| [[#Verifying FIPS Mode|Verifying FIPS Mode]] || Reading the state from the interface, the CLI, and the logs
|-
| [[#FIPS State Values|FIPS State Values]] || The three states, and what a non-compliant state means
|-
| [[#Disabling FIPS Mode|Disabling FIPS Mode]] || Returning to non-FIPS operation
|}
 
== Certification status ==
 
'''QuantaStor 6 and 7 have not been through FIPS 140-3 certification.''' OSNEXUS maintains the OSNEXUS Crypto Library against current FIPS 140-3 compliant OpenSSL releases, so the cryptography in use is compliant -- but the product itself does not hold a 140-3 certificate. '''Compliant is not the same as certified''', and an auditor will ask for the certificate.
 
What does exist is the '''FIPS 140-2 validation of the OSNEXUS Crypto Library''', NIST certificate 4185:
 
* [https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4185 NIST CMVP certificate 4185]
* [https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4185.pdf OSNEXUS Crypto Library FIPS 140-2 Non-Proprietary Security Policy]
 
'''For deployments that require FIPS certification, we recommend using self-encrypting drives (SED) with full-disk encryption on FIPS 140-3 compliant media''', which QuantaStor integrates with. That places the certified cryptographic boundary at the drive, where the media vendor holds the certificate, rather than depending on an uncertified software module. See [[Physical Disks/Devices]] for SED capability and status reporting, and [[Storage Pools]] for hardware encryption at pool creation.
 
Enabling FIPS mode is still worthwhile without a certificate: it constrains the appliance to validated algorithms and self-tests them at every start, which satisfies many internal security policies even where a formal certification is not required.
 
== What FIPS Mode Changes ==
 
QuantaStor ships '''two complete sets of OpenSSL libraries''' and switches between them.
 
{| class="wikitable"
! Mode !! Library path !! OpenSSL !! Cryptolib
|-
| Non-FIPS ''(default)'' || <code>/opt/osnexus/common/lib/</code> || '''3.5.7''' || <code>libosn_nonfips_cryptolib</code>
|-
| FIPS || <code>/opt/osnexus/common/lib/fips/</code> || '''3.1.2''' || <code>libosn_cryptolib</code>
|}
 
The switch is made through a symlink directory. <code>qs_service</code> and the other crypto-linked binaries resolve their libraries through <code>/opt/osnexus/common/lib/active/</code>, and enabling or disabling FIPS mode repoints the symlinks inside it:
 
<pre style="font-size: smaller">
# non-FIPS
/opt/osnexus/common/lib/active/libcrypto.so.3 -> /opt/osnexus/common/lib/libcrypto.so.3
/opt/osnexus/common/lib/active/libssl.so.3    -> /opt/osnexus/common/lib/libssl.so.3
 
# FIPS
/opt/osnexus/common/lib/active/libcrypto.so.3 -> /opt/osnexus/common/lib/fips/libcrypto.so.3
/opt/osnexus/common/lib/active/libssl.so.3    -> /opt/osnexus/common/lib/fips/libssl.so.3
</pre>
 
The <code>libosn_cryptolib.so.1.0.0</code> symlink is repointed at the same time, between the FIPS and non-FIPS builds of the OSNEXUS Crypto Library. The FIPS tree also carries the OpenSSL FIPS provider module and its configuration -- <code>lib/fips/ossl-modules/fips.so</code> and <code>/opt/osnexus/common/ssl/fips/fipsmodule.cnf</code>, the latter holding the module integrity MAC.
 
'''The FIPS OpenSSL is deliberately older than the general one, and that is not neglect.''' The FIPS provider is the compliance-relevant artifact, and it is tied to the OpenSSL release it was built and validated against. Tracking the newest OpenSSL would forfeit that property, so the FIPS path stays on 3.1.2 while the general runtime moves ahead to 3.5.7. The two are pinned independently and neither is waiting to catch up with the other.
 
'''Do not use <code>openssl version</code> to check which version is in play.''' That reports the operating system's own OpenSSL, which is neither of the above and is not what QuantaStor uses. Read the library the appliance actually resolves instead:
 
<pre style="font-size: smaller">
strings /opt/osnexus/common/lib/active/libcrypto.so.3 | grep -oE 'OpenSSL 3\.[0-9]+\.[0-9]+' | sort -u
</pre>
 
== Enabling FIPS Mode ==
 
FIPS mode is a per-appliance setting and is enabled from the command line as <code>root</code>. Connect over SSH as <code>qadmin</code> and elevate.
 
<pre style="font-size: smaller">
sudo qs-util enablefips
</pre>
 
The utility repoints the library symlinks and restarts the QuantaStor service, reporting as it goes:
 
<pre style="font-size: smaller">
FIPS mode enabled in the storage system. Restarting QuantaStor Service
INFO: Stopping service quantastor via systemctl
INFO: Starting service quantastor via systemctl
</pre>
 
'''Reboot the appliance afterwards.''' Several integrity checks run only at system startup, and the reported FIPS state does not settle until they have. The service restart that <code>enablefips</code> performs is not a substitute.
 
<pre style="font-size: smaller">
sudo reboot
</pre>
</pre>


'''REBOOT: After enabling the FIPS mode, reboot the system as there are various checks that need to be done at system startup.'''
In a grid, enable FIPS mode on each appliance individually -- there is no grid-wide switch. See [[Grid Configuration]].
 
== Verifying FIPS Mode ==
 
Check the state after the reboot, not before.
 
=== From the CLI ===
 
<pre style="font-size: smaller">
qs system-get | grep -i fips
</pre>
 
On an appliance running in FIPS mode:
 
<pre style="font-size: smaller">
FIPS State: Verified
FIPS State Detail: FIPS 140-2 security validation checks succeeded, FIPS mode enabled.
</pre>
 
=== From the web interface ===
 
{{Navigation|Storage Management &rarr; Storage Systems ''(section)'' &rarr; ''select a Storage System'' &rarr; Properties ''(right-edge panel)''}}
 
'''FIPS''' and '''FIPS State Detail''' appear in the Object Details list in the Properties panel, alongside the system's other properties. Expand the panel using the strip on the right edge of the window.
 
=== From the crypto log ===


You can run the service and check the logs to verify that FIPS mode has been validated from the UI in the storage system properties. You can also run the following command to verify FIPS mode status from the CLI:
The OSNEXUS Crypto Library writes its own log, which is where the self-test detail lives:


<pre>
<pre style="font-size: smaller">
# qs sys-get | grep -i FIPS
tail -f /var/log/qs/qs_crypto.log
</pre>
</pre>


Check the QuantaStor alerts to see recent changes to FIPS mode status:<br>
A successful start records the self tests, the detected processor features, and the DRBG selection:
[[File:Fips mode status update alerts.jpg]]


Additional logging for the OSNEXUS Crypto Library Module can be followed using the following command:
<pre style="font-size: smaller">
<pre>
INFO: osncrypto: attempting osncrypto_self_test()
# tail -f /var/log/qs/qs_crypto.log
INFO: osncrypto: Start up self-tests completed successfully.
INFO: osncrypto: Detected support for DRNG_HAS_RDRAND.
INFO: osncrypto: Using OpenSSL DRBG 'CTR-DRBG'.
INFO: osncrypto: Reseeding the DRBG with personalization string 'OSNEXUS_CryptoLib_v1.0_...'.
</pre>
</pre>


== Manual Verification and Validatation of FIPS Mode ==
=== Manual validation ===
You can verify and validate the activation of FIPS mode using the osn_fipscheck CLI tool. From the command line of your QuantaStor system which you can access via ssh as user 'qadmin'.
 
Once logged in as the 'qadmin' user you'll want to elevate your permissions to 'root' before running the the following checks.
<code>osn_fipscheck</code> validates that FIPS mode is enabled and that the module passed its self tests. It returns 0 on success and 1 or greater on failure.


=== Validate osncryptolib configuration is FIPS Mode compliant ===
<pre style="font-size: smaller">
This command verifies if the user has FIPS mode enabled and that the FIPS module has been validated by self tests. If the FIPS module fails to validate, then the quantastor service will not start if designated to run in FIPS mode. Successful return value is 0, failure return is >= 1. See 'qs_crypto.log' for more information on FIPS mode errors.
sudo /opt/osnexus/quantastor/bin/osn_fipscheck validate-fips
<pre>
# sudo /opt/osnexus/quantastor/bin/osn_fipscheck validate-fips
</pre>
</pre>
If the FIPS module fails validation, the QuantaStor service will not start on an appliance configured for FIPS mode. Consult <code>qs_crypto.log</code> for the reason.
== FIPS State Values ==
{| class="wikitable"
! State !! Meaning
|-
| '''Disabled''' || FIPS mode is off; the appliance is using the general-purpose libraries. This is the default.
|-
| '''Verified (Enabled)''' || FIPS mode is on and the validation checks passed. This is the state you want.
|-
| '''NOT COMPLIANT (Enabled)''' || FIPS mode is on but the appliance is '''not''' operating in an approved state. Treat this as a failure, not a warning -- the appliance is not delivering the guarantee FIPS mode is there to provide. Check <code>qs_crypto.log</code>.
|}
'''A "Disabled" state can still report that self tests passed.''' On an appliance with FIPS mode off, the state detail reads along the lines of "Self-tests and integrity checks passed, entered Non-FIPS mode." The self tests run either way, so seeing "passed" is not confirmation that FIPS mode is active -- read the '''FIPS State''' field, not the detail text.
== Disabling FIPS Mode ==
<pre style="font-size: smaller">
sudo qs-util disablefips
sudo reboot
</pre>
This repoints the library symlinks back to the general-purpose OpenSSL and restarts the service. Reboot afterwards for the same reason as when enabling.
== Related pages ==
* [[Physical Disks/Devices]] -- SED capability and status, for the certified-media approach
* [[Storage Pools]] -- pool encryption, including hardware (SED) encryption
* [[Security Configuration]] -- the wider security surface: users, roles, MFA, certificates, TLS
* [[Grid Configuration]] -- FIPS mode is per appliance, so grid members are enabled individually
* [[QuantaStor Shell Utilities]] -- <code>qs-util</code> and the other appliance command-line tools
----
<small>''Verified against QuantaStor 6.9.0.''</small>

Latest revision as of 05:35, 3 September 2026

QuantaStor can run its cryptographic operations through a FIPS-validated module. Enabling FIPS mode switches the appliance from its general-purpose OpenSSL libraries to the FIPS build, runs power-on self tests and integrity checks, and refuses to start the QuantaStor service if those checks fail. This page covers what FIPS mode does, how to enable and verify it, and -- importantly -- what it does and does not certify.

Read Certification status first if you are evaluating QuantaStor against a compliance requirement. The distinction between a *FIPS-validated cryptographic module* and a *FIPS-certified product* matters, and it decides which approach fits your deployment.

Section Covers
Certification status What is validated, what is not, and what to use when certification is required
What FIPS Mode Changes The library switch, and the two OpenSSL versions involved
Enabling FIPS Mode The procedure, including the required restart
Verifying FIPS Mode Reading the state from the interface, the CLI, and the logs
FIPS State Values The three states, and what a non-compliant state means
Disabling FIPS Mode Returning to non-FIPS operation

Certification status

QuantaStor 6 and 7 have not been through FIPS 140-3 certification. OSNEXUS maintains the OSNEXUS Crypto Library against current FIPS 140-3 compliant OpenSSL releases, so the cryptography in use is compliant -- but the product itself does not hold a 140-3 certificate. Compliant is not the same as certified, and an auditor will ask for the certificate.

What does exist is the FIPS 140-2 validation of the OSNEXUS Crypto Library, NIST certificate 4185:

For deployments that require FIPS certification, we recommend using self-encrypting drives (SED) with full-disk encryption on FIPS 140-3 compliant media, which QuantaStor integrates with. That places the certified cryptographic boundary at the drive, where the media vendor holds the certificate, rather than depending on an uncertified software module. See Physical Disks/Devices for SED capability and status reporting, and Storage Pools for hardware encryption at pool creation.

Enabling FIPS mode is still worthwhile without a certificate: it constrains the appliance to validated algorithms and self-tests them at every start, which satisfies many internal security policies even where a formal certification is not required.

What FIPS Mode Changes

QuantaStor ships two complete sets of OpenSSL libraries and switches between them.

Mode Library path OpenSSL Cryptolib
Non-FIPS (default) /opt/osnexus/common/lib/ 3.5.7 libosn_nonfips_cryptolib
FIPS /opt/osnexus/common/lib/fips/ 3.1.2 libosn_cryptolib

The switch is made through a symlink directory. qs_service and the other crypto-linked binaries resolve their libraries through /opt/osnexus/common/lib/active/, and enabling or disabling FIPS mode repoints the symlinks inside it:

# non-FIPS
/opt/osnexus/common/lib/active/libcrypto.so.3 -> /opt/osnexus/common/lib/libcrypto.so.3
/opt/osnexus/common/lib/active/libssl.so.3    -> /opt/osnexus/common/lib/libssl.so.3

# FIPS
/opt/osnexus/common/lib/active/libcrypto.so.3 -> /opt/osnexus/common/lib/fips/libcrypto.so.3
/opt/osnexus/common/lib/active/libssl.so.3    -> /opt/osnexus/common/lib/fips/libssl.so.3

The libosn_cryptolib.so.1.0.0 symlink is repointed at the same time, between the FIPS and non-FIPS builds of the OSNEXUS Crypto Library. The FIPS tree also carries the OpenSSL FIPS provider module and its configuration -- lib/fips/ossl-modules/fips.so and /opt/osnexus/common/ssl/fips/fipsmodule.cnf, the latter holding the module integrity MAC.

The FIPS OpenSSL is deliberately older than the general one, and that is not neglect. The FIPS provider is the compliance-relevant artifact, and it is tied to the OpenSSL release it was built and validated against. Tracking the newest OpenSSL would forfeit that property, so the FIPS path stays on 3.1.2 while the general runtime moves ahead to 3.5.7. The two are pinned independently and neither is waiting to catch up with the other.

Do not use openssl version to check which version is in play. That reports the operating system's own OpenSSL, which is neither of the above and is not what QuantaStor uses. Read the library the appliance actually resolves instead:

strings /opt/osnexus/common/lib/active/libcrypto.so.3 | grep -oE 'OpenSSL 3\.[0-9]+\.[0-9]+' | sort -u

Enabling FIPS Mode

FIPS mode is a per-appliance setting and is enabled from the command line as root. Connect over SSH as qadmin and elevate.

sudo qs-util enablefips

The utility repoints the library symlinks and restarts the QuantaStor service, reporting as it goes:

FIPS mode enabled in the storage system. Restarting QuantaStor Service
INFO: Stopping service quantastor via systemctl
INFO: Starting service quantastor via systemctl

Reboot the appliance afterwards. Several integrity checks run only at system startup, and the reported FIPS state does not settle until they have. The service restart that enablefips performs is not a substitute.

sudo reboot

In a grid, enable FIPS mode on each appliance individually -- there is no grid-wide switch. See Grid Configuration.

Verifying FIPS Mode

Check the state after the reboot, not before.

From the CLI

qs system-get | grep -i fips

On an appliance running in FIPS mode:

FIPS State: Verified
FIPS State Detail: FIPS 140-2 security validation checks succeeded, FIPS mode enabled.

From the web interface

Navigation: Storage Management → Storage Systems (section) → select a Storage System → Properties (right-edge panel)

FIPS and FIPS State Detail appear in the Object Details list in the Properties panel, alongside the system's other properties. Expand the panel using the strip on the right edge of the window.

From the crypto log

The OSNEXUS Crypto Library writes its own log, which is where the self-test detail lives:

tail -f /var/log/qs/qs_crypto.log

A successful start records the self tests, the detected processor features, and the DRBG selection:

INFO: osncrypto: attempting osncrypto_self_test()
INFO: osncrypto: Start up self-tests completed successfully.
INFO: osncrypto: Detected support for DRNG_HAS_RDRAND.
INFO: osncrypto: Using OpenSSL DRBG 'CTR-DRBG'.
INFO: osncrypto: Reseeding the DRBG with personalization string 'OSNEXUS_CryptoLib_v1.0_...'.

Manual validation

osn_fipscheck validates that FIPS mode is enabled and that the module passed its self tests. It returns 0 on success and 1 or greater on failure.

sudo /opt/osnexus/quantastor/bin/osn_fipscheck validate-fips

If the FIPS module fails validation, the QuantaStor service will not start on an appliance configured for FIPS mode. Consult qs_crypto.log for the reason.

FIPS State Values

State Meaning
Disabled FIPS mode is off; the appliance is using the general-purpose libraries. This is the default.
Verified (Enabled) FIPS mode is on and the validation checks passed. This is the state you want.
NOT COMPLIANT (Enabled) FIPS mode is on but the appliance is not operating in an approved state. Treat this as a failure, not a warning -- the appliance is not delivering the guarantee FIPS mode is there to provide. Check qs_crypto.log.

A "Disabled" state can still report that self tests passed. On an appliance with FIPS mode off, the state detail reads along the lines of "Self-tests and integrity checks passed, entered Non-FIPS mode." The self tests run either way, so seeing "passed" is not confirmation that FIPS mode is active -- read the FIPS State field, not the detail text.

Disabling FIPS Mode

sudo qs-util disablefips
sudo reboot

This repoints the library symlinks back to the general-purpose OpenSSL and restarts the service. Reboot afterwards for the same reason as when enabling.

Related pages


Verified against QuantaStor 6.9.0.