SV-270744r1137699_rule
V-270744
SRG-OS-000478-GPOS-00223
UBTU-24-600030
CAT I
10
Configure the system to run in FIPS mode. Add "fips=1" to the kernel parameter during Ubuntu 24.04 LTSs install.
Enabling a FIPS mode on a pre-existing system involves a number of modifications to Ubuntu 24.04 LTS. Refer to the Ubuntu Pro security certification documentation for instructions.
A subscription to the "Ubuntu Pro" plan is required to obtain the FIPS Kernel cryptographic modules and enable FIPS.
Note: Ubuntu Pro security certification instructions can be found at: https://ubuntu.com/security/certifications/docs/fips-enablement
The basic steps use the following commands:
$ sudo pro attach <token>
$ sudo pro enable fips-updates
Verify the system is configured to run in FIPS mode with the following command:
$ grep -i 1 /proc/sys/crypto/fips_enabled
1
If a value of "1" is not returned, this is a finding.
V-270744
False
UBTU-24-600030
Verify the system is configured to run in FIPS mode with the following command:
$ grep -i 1 /proc/sys/crypto/fips_enabled
1
If a value of "1" is not returned, this is a finding.
M
5673