Guides:Encryption at Rest and FIPS Mode for On-Premises Storage
By Steve Umbehocker, CTO, OSNexus · Updated October 3, 2026
Encryption at rest protects the data on a storage pool's media, so drives that leave the data center, whether failed, stolen or decommissioned, can't be read without the keys. QuantaStor encrypts storage pools with AES-256, either in software through Linux LUKS with AES-NI acceleration or in hardware on Opal 2 self-encrypting NVMe drives, with keys held on the appliance, protected by a passphrase or stored on a KMIP key server. A separate FIPS mode switches the appliance's cryptography to the FIPS 140-2 validated OSNEXUS Crypto Library and self-tests it at every start.
Why it matters
Federal, defense, healthcare and financial buyers usually face two separate requirements that are easy to mix up:
- Data at rest must be encrypted. Lost drives, RMA returns and decommissioned servers must not expose data.
- The cryptography must be FIPS validated. Many government contracts and agency policies require cryptographic modules validated under the NIST Cryptographic Module Validation Program (CMVP), and an auditor will ask for the certificate number.
Encryption alone covers the first requirement. To cover the second, the module doing the encryption needs a certificate, and that decides which of the options below fits. The End-to-end Security overview places encryption at rest alongside the other controls agencies typically review: encryption on the wire, role-based access control, password policy and data shredding.
How it works
Software encryption
Software encryption uses the Linux LUKS key management system, so it works on any media type: HDD, SATA/SAS SSD or NVMe. The AES-NI instructions in modern server processors do the encryption. It is applied when the pool is created, because the underlying devices themselves are encrypted. An encrypted pool shows a lock icon in the web interface. When you grow the pool, new devices are encrypted automatically before they're added.
Hardware encryption (self-encrypting drives)
Hardware encryption moves the work onto the drive. QuantaStor supports Opal 2 compliant NVMe self-encrypting drives (SEDs), both FIPS and non-FIPS models. For HDD-based SED encryption, the recommended approach is a Seagate Corvault system, which handles encryption in the external enclosure. Physical Disks/Devices reports each drive's SED capability and status. The older RAID-controller-based encryption is deprecated; HBA (IT) mode controllers are the current standard.
Key protection
The Encryption tab of the Create Storage Pool dialog offers three ways to protect a pool's keys:
| Key protection | Where the key lives | Behavior |
|---|---|---|
| Encrypt with No Passphrase | On the appliance | Pool starts automatically at boot; supported in HA groups |
| Encrypt with User Defined Passphrase | On the appliance, locked by the passphrase | Pool starts only after an administrator enters the passphrase; not supported in HA groups |
| Encrypt and Store on Key Server | On a KMIP key server | Keys are managed centrally through a key server profile |
KMIP is the standard protocol for talking to enterprise key managers. You add a key server profile, then select it when you create a pool. You can also move a pool's locally stored keys onto the key server later by modifying the pool and selecting the profile.

FIPS mode
FIPS mode controls which cryptographic library the appliance uses. QuantaStor ships two complete OpenSSL library sets and switches between them:
| Mode | OpenSSL | Crypto library |
|---|---|---|
| Non-FIPS (default) | 3.5.7 | Non-FIPS build of the OSNEXUS Crypto Library |
| FIPS | 3.1.2 with the OpenSSL FIPS provider | OSNEXUS Crypto Library (FIPS build) |
In FIPS mode the appliance runs power-on self-tests and integrity checks, and the QuantaStor service won't start if they fail. The FIPS path stays on OpenSSL 3.1.2 on purpose: the FIPS provider is tied to the OpenSSL release it was built and validated against, so it is pinned separately from the general runtime.
Design and sizing
Certified versus compliant
Be precise about what is validated. The OSNEXUS Crypto Library holds FIPS 140-2 Level 1 validation, NIST CMVP certificate 4185, with a public non-proprietary security policy. QuantaStor 6 and 7 have not been through FIPS 140-3 certification. The crypto library is maintained against current FIPS 140-3 compliant OpenSSL releases, but compliant isn't the same as certified.
Where a deployment requires FIPS certification, the documented recommendation is self-encrypting drives with full-disk encryption on FIPS 140-3 validated media. That puts the certified cryptographic boundary at the drive, where the media vendor holds the certificate. Running FIPS mode on the appliance as well is still worthwhile: it limits management cryptography to validated algorithms and self-tests them at every start, which satisfies many internal security policies.
Choosing an approach
| Requirement | Recommended configuration |
|---|---|
| Encrypt at rest, no formal certification | Software encryption, no passphrase or KMIP |
| Certificate required for data at rest | FIPS 140-3 SED media with hardware encryption, plus FIPS mode |
| Keys held off the appliance under central control | Software encryption with a KMIP key server profile |
| Pool must not start without a person present | Software encryption with a user-defined passphrase (not with HA) |
| HA failover between two controllers | Software encryption without a passphrase, or SEDs |
Performance
Software encryption typically reduces a pool's performance by about 15%, and by as much as 30% depending on the CPU and the number of devices. Hardware encryption avoids that CPU cost, so if your media is SED Opal compliant, it's the better option. Plan software-encrypted pools with that headroom in mind, especially all-NVMe pools, where the CPU is more likely to be the bottleneck.
Setting it up
Create an encrypted pool
- Go to Storage Management → Storage Pools → Create. See Storage Pools for the General tab settings.
- On the Encryption tab, select Software Encryption or Hardware Encryption.
- Under Key Protection, choose no passphrase, a user-defined passphrase, or Encrypt and Store on Key Server with a key server profile.
- Finish creating the pool. Encryption can't be added after the pool is created.
Back up the keys
Immediately after you create the pool, use Storage Pool Encryption → Export Keys (Storage Pool Export Encryption Keys) and keep the backup somewhere secure. If the boot media is lost, you reinstall QuantaStor on new boot devices, run Import Keys and start the pool. The same ribbon group holds Re-Key Pool.

Enable FIPS mode
FIPS mode is set per appliance, from the console as root. A grid has no grid-wide switch, so repeat this on every appliance (see Grid Configuration). Connect over SSH as qadmin, then run:
sudo qs-util enablefips sudo reboot
enablefips repoints the library symlinks and restarts the service, reporting FIPS mode enabled in the storage system. Restarting QuantaStor Service. The reboot is required. Several integrity checks run only at system startup, and the FIPS state doesn't settle until they have. Restarting the service isn't a substitute.
HA and the rest of the security stack
Encrypted pools work in storage pool HA groups like unencrypted pools, provided they have no passphrase. For data on the wire, use SMB3 encryption, IPsec and HTTPS, and CHAP authentication for iSCSI. Grid management and replication traffic use SSL/TLS 1.2 with strong ciphers; see Custom SSL TLS Security. Administrative access is covered by Security Configuration (role-based access control) and the password policy, which supports HIPAA and CJIS requirements.
Operating and testing
Check the FIPS state after the reboot, not before:
qs system-get | grep -i fips sudo /opt/osnexus/quantastor/bin/osn_fipscheck validate-fips tail -f /var/log/qs/qs_crypto.log
On an appliance in FIPS mode, qs system-get reports:
FIPS State: Verified FIPS State Detail: FIPS 140-2 security validation checks succeeded, FIPS mode enabled.
osn_fipscheck validate-fips confirms that FIPS mode is enabled and the module passed its self-tests, returning 0 on success and 1 or greater on failure. A healthy start logs Start up self-tests completed successfully and the DRBG in use (CTR-DRBG) in qs_crypto.log. In the web interface, the FIPS and FIPS State Detail fields appear in the storage system's Properties panel.
To confirm which OpenSSL the appliance actually uses, don't run openssl version, which reports the operating system's copy. Read the active library instead:
strings /opt/osnexus/common/lib/active/libcrypto.so.3 | grep -oE 'OpenSSL 3\.[0-9]+\.[0-9]+' | sort -u
Routine operations on an encrypted pool work the same as on a plain one: adding devices, replacing a faulted drive, and adding write log, cache or spare devices to a passphrase-protected pool. After a reboot, a passphrase-protected pool stays stopped until an administrator starts it with the passphrase from the web interface or the CLI. To change a passphrase, remove it and apply a new one.
When a pool is retired, delete it using a data shredding option: the 4-pass DoD 5220.22-M (section 8-306) procedure, the 4-pass NNSA Policy Letter NAP-14.1-C procedure or the US Army AR380-19 method. Shredding runs at the block level, concurrently across all disks in the pool, and the encryption keys can be shredded too.
FAQ
Is QuantaStor FIPS 140 validated?
The OSNEXUS Crypto Library, which QuantaStor uses in FIPS mode, holds FIPS 140-2 Level 1 validation under NIST CMVP certificate 4185. QuantaStor 6 and 7 haven't been through FIPS 140-3 certification. Where a 140-3 certificate is required for data at rest, use FIPS 140-3 validated self-encrypting drives, where the drive vendor holds the certificate.
Is it suitable for US government and defense deployments?
It provides the controls these environments usually review: AES-256 encryption at rest, a FIPS mode that uses a validated crypto library, support for FIPS SED media, encryption on the wire with SMB3, IPsec and TLS 1.2, role-based access control, password policy that supports HIPAA and CJIS requirements, and DoD 5220.22-M, NNSA and AR380-19 data shredding. Whether a given deployment passes accreditation depends on the agency's specific control set, so map these controls to it.
Can I encrypt an existing pool?
No. Software encryption encrypts the underlying devices, so it has to be selected when the pool is created. To encrypt existing data, create a new encrypted pool and move the data onto it.
What happens if I lose the boot drives?
If you exported the pool keys, reinstall on new boot media, import the keys and start the pool. Without the key backup, a software-encrypted pool can't be recovered, so export the keys as soon as you create the pool.
Does encryption work with high availability?
Yes. Encrypted pools fail over between controllers like unencrypted pools, provided they have no passphrase. A passphrase would stop the pool from starting automatically on the surviving controller.
Part of the QuantaStor Guides series. For reference documentation, see the QuantaStor documentation.