SV-268168r1131141_rule
V-268168
SRG-OS-000478-GPOS-00223
ANIX-00-001840
CAT I
10
Configure NixOS to run in FIPS mode.
Add the following Nix code to the NixOS Configuration, usually located in /etc/nixos/configuration.nix or /etc/nixos/flake.nix:
boot.kernelParams = [ "fips=1" ];
Rebuild and switch to the new NixOS configuration:
$ sudo nixos-rebuild switch
A reboot is required for the changes to take effect.
Verify NixOS is configured to operate in FIPS mode with the following command:
$ grep fips /proc/cmdline
BOOT_IMAGE=(hd0,msdos1)/nix/store/glc0midc78caq9sc7pzciymx4c3in7kn-linux-6.1.64/bzImage init=/nix/store/grl4baymr9q60mbcz3sidm4agckn3bx5-nixos-system-nixos-23.1.1.20231129.057f9ae/init audit=1 audit_backlog_limit=8192 fips=1 loglevel=4
If the "fips" entry does not equal "1" or is missing, this is a finding.
V-268168
False
ANIX-00-001840
Verify NixOS is configured to operate in FIPS mode with the following command:
$ grep fips /proc/cmdline
BOOT_IMAGE=(hd0,msdos1)/nix/store/glc0midc78caq9sc7pzciymx4c3in7kn-linux-6.1.64/bzImage init=/nix/store/grl4baymr9q60mbcz3sidm4agckn3bx5-nixos-system-nixos-23.1.1.20231129.057f9ae/init audit=1 audit_backlog_limit=8192 fips=1 loglevel=4
If the "fips" entry does not equal "1" or is missing, this is a finding.
M
5658