security¶
Security compliance operations including FIPS 140 mode management.
Commands¶
Command |
Description |
|---|---|
|
Manage FIPS 140 mode (enable, disable, status) |
security fips¶
Manage Federal Information Processing Standards (FIPS) 140 compliance mode.
Check FIPS status:
sudo hvmcli security fips status
FIPS Status
───────────────────────────────────
Kernel FIPS mode: ❌ DISABLED
FIPS kernel package: not installed
GRUB fips=1: not configured
Packages:
✗ ubuntu-fips — not-installed
✗ linux-fips — not-installed
✗ fips-initramfs — not-installed
sudo hvmcli security fips status --json
Enable FIPS mode (dry run):
Preview what changes would be made without applying them:
sudo hvmcli security fips enable --dry-run
Enable FIPS mode:
sudo hvmcli security fips enable --force
sudo hvmcli security fips enable --force --reboot
Options:
--force— Skip confirmation prompts--reboot— Automatically reboot the node after enabling FIPS (required for kernel-level FIPS activation)--dry-run— Preview changes without applying
Recover from an invalidated FIPS payload (offline enable):
If an OS update invalidates the on-disk FIPS payload, re-stage it from an offline bundle before re-enabling FIPS. --offline and --file are only valid with enable and must be used together:
sudo hvmcli security fips enable --offline --file /path/to/fips_bundle.zip --force
Options:
--offline— Re-stage the FIPS payload from an offline bundle before enabling; requires--file--file <bundle.zip>— Path to the offline bundle carrying the FIPS payload; use with--offline
Disable FIPS mode (dry run):
sudo hvmcli security fips disable --dry-run
Disable FIPS mode:
sudo hvmcli security fips disable --force --reboot
Options:
--force— Skip confirmation prompts--reboot— Automatically reboot after disabling FIPS--dry-run— Preview changes without applying
Important
Enabling or disabling FIPS mode requires a reboot for the kernel FIPS mode to take effect. Use --reboot to handle this automatically, or plan a manual reboot.
Note
FIPS 140 mode enforces the use of FIPS-validated cryptographic modules for all system-level encryption operations. This is required for compliance with certain government and regulatory standards.