Categories: BlogCanonicalUbuntu

Monitor Ubuntu Advantage FIPS configurations

In regulated environments, some machines must adhere to strict cryptography requirements designed to protect systems from being cracked, altered, or tampered with. Using cryptographic modules that are FIPS certified or compliant ensure a systems’ encryption solutions adequately protect its digital assets. FIPS validated operating systems are a prerequisite for government agencies, their partners, and those wanting to conduct business with the federal government.

There are multiple ways to enable, manage, and monitor FIPS on Ubuntu.

Network access control influences the mode for FIPS enablement

FIPS validated operating systems are deployed across two network types:

  1. Connected: machines have the ability to contact subdomains on canonical.com to stay current with an evolving security baseline
  2. Sponsored
  3. Airgapped: machines can not reach beyond their local network

You may have some machines which require strict adherence to FIPS validation. There may be other machines that require FIPS compliance and critical vulnerability updates right away, before a formal FIPS certification process can be completed. In that case, network accessibility and the nature of the workload will influence which flavour of FIPS is required.

FIPS in connected environments

Ubuntu Advantage entitlements, associated with your free or paid subscription, can be managed in the Ubuntu Advantage dashboard at ubuntu.com/advantage. FIPS configurations, or access to FIPS Updates, can be associated with a unique token within the Ubuntu Advantage dashboard. Running a single ua attach command with the appropriate token will enable the entitlements according to your selections on the Ubuntu Advantage dashboard, on the target Ubuntu machine. The free tier grants you access to one token, which serves as a default configuration profile for a set of machines. If you do not wish to automatically enable any entitlements, or if you are using Ubuntu Pro and your UA Client is already attached, this tutorial provides a walkthrough of using the UA Client to enable FIPS.

Monitoring FIPS configurations with Landscape

Landscape is Canonical’s monitoring and management tool for Ubuntu. Organisations incorporate Landscape into their compliance strategies, because of its highly configurable auditing and logging capabilities. In less than 15 minutes, you can configure Landscape to audit UA Client FIPS configurations in your entire Ubuntu estate.

Sponsored

FIPS in air-gapped environments

Massimiliano Gori, Cybersecurity Compliance Product Manager at Canonical, will discuss how to enable FIPS on Ubuntu in air-gapped environments in a live webinar which you can attend from the comfort of your own desk. Please mark February 23th at 9 AM PST, 12:00 PM EST on your calendar. We look forward to answering all of your questions about FIPS and Landscape.

If you want to learn more about FIPS, Landscape, or our professional services options, do not hesitate to contact us to discuss your needs with one of our advisors.

Contact Us

Ubuntu Server Admin

Recent Posts

Canonical achieves IEC 62443-4-1 compliance in Industrial Automation and Control Systems

Canonical is proud to announce it has achieved compliance with IEC 62443-4-1 for cybersecurity in…

4 hours ago

VirtualBox 7.2.2 Fixed TPM 2.0 Emulation & KVM Conflict

Oracle VirtualBox, announced the first maintenance update for the 7.2 release series few days ago.…

1 day ago

Firefox 143.0 is out with Microsoft Copilot AI Integration

Firefox 143.0, the new monthly release of the popular free open-source web browser, is available…

1 day ago

VLC 3.0.22 Adds Qt6 & AMD AI Frame Interpolation Support [Ubuntu PPA]

VLC, the popular free open-source media player, rolled out the new 3.0.22 version few days…

1 day ago

Dash to Panel updated with GNOME 49 (Ubuntu 25.10) Support

Dash to Panel, the popular Gnome Shell extension, updated few days ago with support for…

2 days ago

Ubuntu Weekly Newsletter Issue 909

Welcome to the Ubuntu Weekly Newsletter, Issue 909 for the week of September 7 –…

3 days ago