无安全背景如何基于合规OpenSSL构建Linux平台FIPS合规OpenSSH?
Hey there! Since you already have a FIPS-compliant OpenSSL build configured with the fipscanister, getting a FIPS-compliant OpenSSH up and running on your Linux distro is totally manageable. Let’s walk through this step by step, keeping things straightforward even if you don’t have a cybersecurity background:
1. Gather OpenSSH Source & Build Dependencies
- First, grab the source code for a stable, FIPS-compatible OpenSSH version (v8.0+ is recommended, as these have mature FIPS support). You can pull it from the official OpenSSH repository or your distro’s source package archive.
- Install the essential build tools if you haven’t already:
- For Debian/Ubuntu-based systems:
sudo apt install build-essential autoconf automake libtool - For RHEL/CentOS/Fedora-based systems:
sudo yum groupinstall "Development Tools"
- For Debian/Ubuntu-based systems:
2. Compile OpenSSH Against Your FIPS-Compliant OpenSSL
This is the core step—we need to force OpenSSH to link against your existing FIPS OpenSSL instead of the system default:
- First, set environment variables to point to your FIPS OpenSSL installation (replace
/path/to/your/fips-opensslwith your actual directory):export OPENSSL_DIR=/path/to/your/fips-openssl export PATH="$OPENSSL_DIR/bin:$PATH" export LD_LIBRARY_PATH="$OPENSSL_DIR/lib:$LD_LIBRARY_PATH" export CPPFLAGS="-I$OPENSSL_DIR/include" export LDFLAGS="-L$OPENSSL_DIR/lib" - Navigate to your OpenSSH source directory, then run the configure script with FIPS support enabled:
./configure \ --prefix=/usr/local/openssh-fips \ --with-ssl-dir=$OPENSSL_DIR \ --enable-fips--prefix: Sets where your FIPS-compliant OpenSSH will be installed (pick a directory that makes sense for your system).--with-ssl-dir: Ensures we link against your FIPS-approved OpenSSL.--enable-fips: The critical flag that enables OpenSSH’s FIPS mode.
- Compile and install:
make -j$(nproc) # Uses all available CPU cores for faster build sudo make install
3. Configure OpenSSH to Enforce FIPS Compliance
After installation, tweak the config files to only use FIPS-approved cryptographic algorithms:
- Edit the SSH daemon config (
/usr/local/openssh-fips/etc/sshd_config—adjust path if you used a different--prefix):FIPSMode yes # Restrict to FIPS-approved ciphers Ciphers aes256-ctr,aes192-ctr,aes128-ctr # Restrict to FIPS-approved MACs MACs hmac-sha2-256,hmac-sha2-512 # Restrict to FIPS-approved key exchange algorithms KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256 - Edit the client config (
/usr/local/openssh-fips/etc/ssh_config) to enable FIPS mode for client connections too:FIPSMode yes - Validate the config files to catch any syntax errors:
/usr/local/openssh-fips/sbin/sshd -t /usr/local/openssh-fips/bin/ssh -G user@your-host | grep fipsmode
4. Replace System Default OpenSSH (Optional but Recommended)
If you want your system to use this FIPS-compliant OpenSSH by default:
- Stop the existing SSH daemon:
sudo systemctl stop sshd - Back up the original binaries:
sudo mv /usr/bin/ssh /usr/bin/ssh-original sudo mv /usr/sbin/sshd /usr/sbin/sshd-original - Create symlinks to your FIPS-compliant binaries:
sudo ln -s /usr/local/openssh-fips/bin/ssh /usr/bin/ssh sudo ln -s /usr/local/openssh-fips/sbin/sshd /usr/sbin/sshd - Restart the SSH daemon:
sudo systemctl start sshd
5. Verify FIPS Compliance
Finally, confirm everything is working as expected:
- Check that OpenSSH is linked to your FIPS OpenSSL:
The output should point to theldd /usr/local/openssh-fips/bin/ssh | grep libssllibssl.soin your FIPS OpenSSL directory. - Test that non-FIPS algorithms are blocked: Try connecting with a non-approved cipher like
aes128-cbc—you should get an error saying the cipher is not permitted:ssh -c aes128-cbc user@your-host - Confirm FIPS mode is enabled:
You should seessh -G user@your-host | grep fipsmodefipsmode yesin the output.
内容的提问来源于stack exchange,提问作者Raven
相关产品推荐
相关产品推荐

