Enabling FIPS 140-2 Mode in AlmaLinux: Decision and Implementation Guide
A technical guide on deciding when and how to enable FIPS 140-2 mode in AlmaLinux, including algorithm restrictions, implementation steps, and verification methods.
20 Dec 2025, 20:15 UTC

The FIPS Compliance Decision
Organizations operating in regulated environments—particularly those dealing with US government data—often face a hard requirement for FIPS 140-2 (Federal Information Processing Standard) validation. In AlmaLinux, enabling FIPS mode is not merely a configuration change; it is a system-wide enforcement that restricts the kernel and cryptographic libraries to a subset of NSA-approved algorithms.
The primary takeaway is that FIPS mode is restrictive. Once enabled, any application attempting to use non-approved primitives (such as MD5 or RC4) will trigger a failure. You must decide if your application stack is compatible with these restrictions before proceeding, as reverting this state is complex.
Comparing FIPS Mode vs. Standard Mode
| Feature | Standard Mode (Default) | FIPS Mode (Enabled) |
|---|---|---|
| Algorithm Availability | Full suite (including MD5, RC4, DES) | Approved only (AES, SHA-256, RSA) |
| Library Behavior | Permissive; uses fastest/most compatible | Strict; rejects non-validated modules |
| Boot Process | Standard initramfs | FIPS-aware initramfs via dracut-fips |
| Performance | Baseline | Minor overhead (<5% for typical workloads) |
Trade-offs and Constraints
Before enabling FIPS mode, evaluate these three critical constraints:
- Application Compatibility: Legacy software that relies on MD5 for non-cryptographic checksums may crash or throw errors because the library will refuse to initialize the MD5 algorithm.
- Operational Downtime: Activating FIPS mode requires a kernel-level change and a full system reboot to initialize the cryptographic modules during the boot sequence.
- Reversibility: While
fips-mode-setup --disableexists, reverting a production system to a non-FIPS state can be inconsistent. The most reliable way to return to a standard state is via a system snapshot rollback or a fresh installation.
Implementation Steps
The following steps assume you are running AlmaLinux 8 or 9 and have root or sudo privileges. These commands must be run on the local terminal of the server.
- Install the FIPS boot package:
sudo dnf install dracut-fipsThis package provides the necessary modules for the
dracuttool to build a FIPS-compliant initial RAM disk (initramfs). - Enable FIPS mode:
sudo fips-mode-setup --enableThis command updates the kernel boot parameters and configures the system to use the FIPS-validated cryptographic modules.
- Reboot the system:
sudo rebootThe system must reboot to load the kernel with the
fips=1parameter and initialize the validated libraries.
Validation and Diagnostics
After the reboot, you must verify that the enforcement is active. Do not assume the command succeeded based on the exit code alone.
Check 1: Kernel Parameter
Run the following to check the kernel's internal FIPS flag. A value of 1 confirms the mode is active:
cat /proc/sys/crypto/fips_enabled
Check 2: System Utility
Use the built-in setup tool to verify the current state:
fips-mode-setup --check
Expected output: FIPS mode is enabled.
Check 3: OpenSSL Validation
Verify that the OpenSSL library is operating in FIPS mode:
openssl version -a
Look for the fips flag or a reference to the FIPS provider in the output string.
Rollback Procedure
If critical applications fail after enabling FIPS, you can attempt to disable it. Note that this may leave some configuration files in a hybrid state.
- Run
sudo fips-mode-setup --disable - Reboot the system.
- Verify
/proc/sys/crypto/fips_enabledreturns0.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.