FIPS Mode

From OSNEXUS Online Documentation Site
Revision as of 05:35, 3 September 2026 by Qadmin (talk | contribs) (Rewrite from the product: remove the 'FIPS 140-3 cert pending' claim and state the real position (140-2 module validation, no 140-3 product certification, SED FDE on FIPS 140-3 media for deployments requiring certification); document the active/ symlink switch and the two OpenSSL versions (3.1.2 FIPS, 3.5.7 general) verified on a 6.9 build; add the three FIPS state values, the reboot requirement, and verification from the WUI, CLI and crypto log; fix the inverted heading levels (QSTOR-12352))
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

QuantaStor can run its cryptographic operations through a FIPS-validated module. Enabling FIPS mode switches the appliance from its general-purpose OpenSSL libraries to the FIPS build, runs power-on self tests and integrity checks, and refuses to start the QuantaStor service if those checks fail. This page covers what FIPS mode does, how to enable and verify it, and -- importantly -- what it does and does not certify.

Read Certification status first if you are evaluating QuantaStor against a compliance requirement. The distinction between a *FIPS-validated cryptographic module* and a *FIPS-certified product* matters, and it decides which approach fits your deployment.

Section Covers
Certification status What is validated, what is not, and what to use when certification is required
What FIPS Mode Changes The library switch, and the two OpenSSL versions involved
Enabling FIPS Mode The procedure, including the required restart
Verifying FIPS Mode Reading the state from the interface, the CLI, and the logs
FIPS State Values The three states, and what a non-compliant state means
Disabling FIPS Mode Returning to non-FIPS operation

Certification status

QuantaStor 6 and 7 have not been through FIPS 140-3 certification. OSNEXUS maintains the OSNEXUS Crypto Library against current FIPS 140-3 compliant OpenSSL releases, so the cryptography in use is compliant -- but the product itself does not hold a 140-3 certificate. Compliant is not the same as certified, and an auditor will ask for the certificate.

What does exist is the FIPS 140-2 validation of the OSNEXUS Crypto Library, NIST certificate 4185:

For deployments that require FIPS certification, we recommend using self-encrypting drives (SED) with full-disk encryption on FIPS 140-3 compliant media, which QuantaStor integrates with. That places the certified cryptographic boundary at the drive, where the media vendor holds the certificate, rather than depending on an uncertified software module. See Physical Disks/Devices for SED capability and status reporting, and Storage Pools for hardware encryption at pool creation.

Enabling FIPS mode is still worthwhile without a certificate: it constrains the appliance to validated algorithms and self-tests them at every start, which satisfies many internal security policies even where a formal certification is not required.

What FIPS Mode Changes

QuantaStor ships two complete sets of OpenSSL libraries and switches between them.

Mode Library path OpenSSL Cryptolib
Non-FIPS (default) /opt/osnexus/common/lib/ 3.5.7 libosn_nonfips_cryptolib
FIPS /opt/osnexus/common/lib/fips/ 3.1.2 libosn_cryptolib

The switch is made through a symlink directory. qs_service and the other crypto-linked binaries resolve their libraries through /opt/osnexus/common/lib/active/, and enabling or disabling FIPS mode repoints the symlinks inside it:

# non-FIPS
/opt/osnexus/common/lib/active/libcrypto.so.3 -> /opt/osnexus/common/lib/libcrypto.so.3
/opt/osnexus/common/lib/active/libssl.so.3    -> /opt/osnexus/common/lib/libssl.so.3

# FIPS
/opt/osnexus/common/lib/active/libcrypto.so.3 -> /opt/osnexus/common/lib/fips/libcrypto.so.3
/opt/osnexus/common/lib/active/libssl.so.3    -> /opt/osnexus/common/lib/fips/libssl.so.3

The libosn_cryptolib.so.1.0.0 symlink is repointed at the same time, between the FIPS and non-FIPS builds of the OSNEXUS Crypto Library. The FIPS tree also carries the OpenSSL FIPS provider module and its configuration -- lib/fips/ossl-modules/fips.so and /opt/osnexus/common/ssl/fips/fipsmodule.cnf, the latter holding the module integrity MAC.

The FIPS OpenSSL is deliberately older than the general one, and that is not neglect. The FIPS provider is the compliance-relevant artifact, and it is tied to the OpenSSL release it was built and validated against. Tracking the newest OpenSSL would forfeit that property, so the FIPS path stays on 3.1.2 while the general runtime moves ahead to 3.5.7. The two are pinned independently and neither is waiting to catch up with the other.

Do not use openssl version to check which version is in play. That reports the operating system's own OpenSSL, which is neither of the above and is not what QuantaStor uses. Read the library the appliance actually resolves instead:

strings /opt/osnexus/common/lib/active/libcrypto.so.3 | grep -oE 'OpenSSL 3\.[0-9]+\.[0-9]+' | sort -u

Enabling FIPS Mode

FIPS mode is a per-appliance setting and is enabled from the command line as root. Connect over SSH as qadmin and elevate.

sudo qs-util enablefips

The utility repoints the library symlinks and restarts the QuantaStor service, reporting as it goes:

FIPS mode enabled in the storage system. Restarting QuantaStor Service
INFO: Stopping service quantastor via systemctl
INFO: Starting service quantastor via systemctl

Reboot the appliance afterwards. Several integrity checks run only at system startup, and the reported FIPS state does not settle until they have. The service restart that enablefips performs is not a substitute.

sudo reboot

In a grid, enable FIPS mode on each appliance individually -- there is no grid-wide switch. See Grid Configuration.

Verifying FIPS Mode

Check the state after the reboot, not before.

From the CLI

qs system-get | grep -i fips

On an appliance running in FIPS mode:

FIPS State: Verified
FIPS State Detail: FIPS 140-2 security validation checks succeeded, FIPS mode enabled.

From the web interface

Navigation: Storage Management → Storage Systems (section) → select a Storage System → Properties (right-edge panel)

FIPS and FIPS State Detail appear in the Object Details list in the Properties panel, alongside the system's other properties. Expand the panel using the strip on the right edge of the window.

From the crypto log

The OSNEXUS Crypto Library writes its own log, which is where the self-test detail lives:

tail -f /var/log/qs/qs_crypto.log

A successful start records the self tests, the detected processor features, and the DRBG selection:

INFO: osncrypto: attempting osncrypto_self_test()
INFO: osncrypto: Start up self-tests completed successfully.
INFO: osncrypto: Detected support for DRNG_HAS_RDRAND.
INFO: osncrypto: Using OpenSSL DRBG 'CTR-DRBG'.
INFO: osncrypto: Reseeding the DRBG with personalization string 'OSNEXUS_CryptoLib_v1.0_...'.

Manual validation

osn_fipscheck validates that FIPS mode is enabled and that the module passed its self tests. It returns 0 on success and 1 or greater on failure.

sudo /opt/osnexus/quantastor/bin/osn_fipscheck validate-fips

If the FIPS module fails validation, the QuantaStor service will not start on an appliance configured for FIPS mode. Consult qs_crypto.log for the reason.

FIPS State Values

State Meaning
Disabled FIPS mode is off; the appliance is using the general-purpose libraries. This is the default.
Verified (Enabled) FIPS mode is on and the validation checks passed. This is the state you want.
NOT COMPLIANT (Enabled) FIPS mode is on but the appliance is not operating in an approved state. Treat this as a failure, not a warning -- the appliance is not delivering the guarantee FIPS mode is there to provide. Check qs_crypto.log.

A "Disabled" state can still report that self tests passed. On an appliance with FIPS mode off, the state detail reads along the lines of "Self-tests and integrity checks passed, entered Non-FIPS mode." The self tests run either way, so seeing "passed" is not confirmation that FIPS mode is active -- read the FIPS State field, not the detail text.

Disabling FIPS Mode

sudo qs-util disablefips
sudo reboot

This repoints the library symlinks back to the general-purpose OpenSSL and restarts the service. Reboot afterwards for the same reason as when enabling.

Related pages


Verified against QuantaStor 6.9.0.