FIPS Mode
QuantaStor can run its cryptographic operations through a FIPS-validated module. Enabling FIPS mode switches the appliance from its general-purpose OpenSSL libraries to the FIPS build, runs power-on self tests and integrity checks, and refuses to start the QuantaStor service if those checks fail. This page covers what FIPS mode does, how to enable and verify it, and -- importantly -- what it does and does not certify.
Read Certification status first if you are evaluating QuantaStor against a compliance requirement. The distinction between a *FIPS-validated cryptographic module* and a *FIPS-certified product* matters, and it decides which approach fits your deployment.
| Section | Covers |
|---|---|
| Certification status | What is validated, what is not, and what to use when certification is required |
| What FIPS Mode Changes | The library switch, and the two OpenSSL versions involved |
| Enabling FIPS Mode | The procedure, including the required restart |
| Verifying FIPS Mode | Reading the state from the interface, the CLI, and the logs |
| FIPS State Values | The three states, and what a non-compliant state means |
| Disabling FIPS Mode | Returning to non-FIPS operation |
Certification status
QuantaStor 6 and 7 have not been through FIPS 140-3 certification. OSNEXUS maintains the OSNEXUS Crypto Library against current FIPS 140-3 compliant OpenSSL releases, so the cryptography in use is compliant -- but the product itself does not hold a 140-3 certificate. Compliant is not the same as certified, and an auditor will ask for the certificate.
What does exist is the FIPS 140-2 validation of the OSNEXUS Crypto Library, NIST certificate 4185:
For deployments that require FIPS certification, we recommend using self-encrypting drives (SED) with full-disk encryption on FIPS 140-3 compliant media, which QuantaStor integrates with. That places the certified cryptographic boundary at the drive, where the media vendor holds the certificate, rather than depending on an uncertified software module. See Physical Disks/Devices for SED capability and status reporting, and Storage Pools for hardware encryption at pool creation.
Enabling FIPS mode is still worthwhile without a certificate: it constrains the appliance to validated algorithms and self-tests them at every start, which satisfies many internal security policies even where a formal certification is not required.
What FIPS Mode Changes
QuantaStor ships two complete sets of OpenSSL libraries and switches between them.
| Mode | Library path | OpenSSL | Cryptolib |
|---|---|---|---|
| Non-FIPS (default) | /opt/osnexus/common/lib/ |
3.5.7 | libosn_nonfips_cryptolib
|
| FIPS | /opt/osnexus/common/lib/fips/ |
3.1.2 | libosn_cryptolib
|
The switch is made through a symlink directory. qs_service and the other crypto-linked binaries resolve their libraries through /opt/osnexus/common/lib/active/, and enabling or disabling FIPS mode repoints the symlinks inside it:
# non-FIPS /opt/osnexus/common/lib/active/libcrypto.so.3 -> /opt/osnexus/common/lib/libcrypto.so.3 /opt/osnexus/common/lib/active/libssl.so.3 -> /opt/osnexus/common/lib/libssl.so.3 # FIPS /opt/osnexus/common/lib/active/libcrypto.so.3 -> /opt/osnexus/common/lib/fips/libcrypto.so.3 /opt/osnexus/common/lib/active/libssl.so.3 -> /opt/osnexus/common/lib/fips/libssl.so.3
The libosn_cryptolib.so.1.0.0 symlink is repointed at the same time, between the FIPS and non-FIPS builds of the OSNEXUS Crypto Library. The FIPS tree also carries the OpenSSL FIPS provider module and its configuration -- lib/fips/ossl-modules/fips.so and /opt/osnexus/common/ssl/fips/fipsmodule.cnf, the latter holding the module integrity MAC.
The FIPS OpenSSL is deliberately older than the general one, and that is not neglect. The FIPS provider is the compliance-relevant artifact, and it is tied to the OpenSSL release it was built and validated against. Tracking the newest OpenSSL would forfeit that property, so the FIPS path stays on 3.1.2 while the general runtime moves ahead to 3.5.7. The two are pinned independently and neither is waiting to catch up with the other.
Do not use openssl version to check which version is in play. That reports the operating system's own OpenSSL, which is neither of the above and is not what QuantaStor uses. Read the library the appliance actually resolves instead:
strings /opt/osnexus/common/lib/active/libcrypto.so.3 | grep -oE 'OpenSSL 3\.[0-9]+\.[0-9]+' | sort -u
Enabling FIPS Mode
FIPS mode is a per-appliance setting and is enabled from the command line as root. Connect over SSH as qadmin and elevate.
sudo qs-util enablefips
The utility repoints the library symlinks and restarts the QuantaStor service, reporting as it goes:
FIPS mode enabled in the storage system. Restarting QuantaStor Service INFO: Stopping service quantastor via systemctl INFO: Starting service quantastor via systemctl
Reboot the appliance afterwards. Several integrity checks run only at system startup, and the reported FIPS state does not settle until they have. The service restart that enablefips performs is not a substitute.
sudo reboot
In a grid, enable FIPS mode on each appliance individually -- there is no grid-wide switch. See Grid Configuration.
Verifying FIPS Mode
Check the state after the reboot, not before.
From the CLI
qs system-get | grep -i fips
On an appliance running in FIPS mode:
FIPS State: Verified FIPS State Detail: FIPS 140-2 security validation checks succeeded, FIPS mode enabled.
From the web interface
FIPS and FIPS State Detail appear in the Object Details list in the Properties panel, alongside the system's other properties. Expand the panel using the strip on the right edge of the window.
From the crypto log
The OSNEXUS Crypto Library writes its own log, which is where the self-test detail lives:
tail -f /var/log/qs/qs_crypto.log
A successful start records the self tests, the detected processor features, and the DRBG selection:
INFO: osncrypto: attempting osncrypto_self_test() INFO: osncrypto: Start up self-tests completed successfully. INFO: osncrypto: Detected support for DRNG_HAS_RDRAND. INFO: osncrypto: Using OpenSSL DRBG 'CTR-DRBG'. INFO: osncrypto: Reseeding the DRBG with personalization string 'OSNEXUS_CryptoLib_v1.0_...'.
Manual validation
osn_fipscheck validates that FIPS mode is enabled and that the module passed its self tests. It returns 0 on success and 1 or greater on failure.
sudo /opt/osnexus/quantastor/bin/osn_fipscheck validate-fips
If the FIPS module fails validation, the QuantaStor service will not start on an appliance configured for FIPS mode. Consult qs_crypto.log for the reason.
FIPS State Values
| State | Meaning |
|---|---|
| Disabled | FIPS mode is off; the appliance is using the general-purpose libraries. This is the default. |
| Verified (Enabled) | FIPS mode is on and the validation checks passed. This is the state you want. |
| NOT COMPLIANT (Enabled) | FIPS mode is on but the appliance is not operating in an approved state. Treat this as a failure, not a warning -- the appliance is not delivering the guarantee FIPS mode is there to provide. Check qs_crypto.log.
|
A "Disabled" state can still report that self tests passed. On an appliance with FIPS mode off, the state detail reads along the lines of "Self-tests and integrity checks passed, entered Non-FIPS mode." The self tests run either way, so seeing "passed" is not confirmation that FIPS mode is active -- read the FIPS State field, not the detail text.
Disabling FIPS Mode
sudo qs-util disablefips sudo reboot
This repoints the library symlinks back to the general-purpose OpenSSL and restarts the service. Reboot afterwards for the same reason as when enabling.
Related pages
- Physical Disks/Devices -- SED capability and status, for the certified-media approach
- Storage Pools -- pool encryption, including hardware (SED) encryption
- Security Configuration -- the wider security surface: users, roles, MFA, certificates, TLS
- Grid Configuration -- FIPS mode is per appliance, so grid members are enabled individually
- QuantaStor Shell Utilities --
qs-utiland the other appliance command-line tools
Verified against QuantaStor 6.9.0.