FIPS Status Check (original) (raw)

NGINX ONE

  1. Home
  2. F5 NGINX Plus
  3. Admin Guide
  4. Dynamic Modules FIPS Status Check

For F5 NGINX Plus, the cryptographic boundary includes all functionality that is implemented by the http_ssl, http_v2, stream_ssl, and mail_ssl modules. These modules implement SSL and TLS operations for inbound and outbound connections which use HTTP, HTTP/2, TCP, and mail protocols.

  1. Check the Technical Specifications page to verify that the module is supported by your operating system.
  2. Install the FIPS module package nginx-plus-module-fips-check.
    For Amazon Linux 2, CentOS, Oracle Linux, and RHEL:
    shell
sudo yum update && \  
sudo yum install nginx-plus-module-fips-check  
sudo yum update && \  
sudo yum install nginx-plus-module-fips-check  

for Amazon Linux 2023, AlmaLinux, Rocky Linux:
shell

sudo dnf update && \  
sudo dnf install nginx-plus-module-fips-check  
sudo dnf update && \  
sudo dnf install nginx-plus-module-fips-check  

For Debian and Ubuntu:
shell

sudo apt update && \  
sudo apt install nginx-plus-module-fips-check  
sudo apt update && \  
sudo apt install nginx-plus-module-fips-check  

For SLES:
shell

sudo zypper refresh && \  
sudo zypper install nginx-plus-module-fips-check  
sudo zypper refresh && \  
sudo zypper install nginx-plus-module-fips-check  

For Alpine:

apk add nginx-plus-module-fips-check  
apk add nginx-plus-module-fips-check  

For FreeBSD:
shell

sudo pkg update && \  
sudo pkg install nginx-plus-module-fips-check  
sudo pkg update && \  
sudo pkg install nginx-plus-module-fips-check  

After installation you will need to enable and configure the module in NGINX Plus configuration file nginx.conf.

  1. Enable dynamic loading of the module with the load_module directive specified in the top-level (“main”) context:
    nginx
load_module modules/ngx_fips_check_module.so;  
http {  
    # ...  
}  
load_module modules/ngx_fips_check_module.so;  
http {  
    # ...  
}  
  1. Perform additional configuration as required by the module.
  2. Test the NGINX Plus configuration. In a terminal, type-in the command:
    Expected output of the command:
    shell
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok  
nginx: configuration file /etc/nginx/nginx.conf is successful  
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok  
nginx: configuration file /etc/nginx/nginx.conf is successful  
  1. Reload the NGINX Plus configuration to enable the module: