You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无安全背景如何基于合规OpenSSL构建Linux平台FIPS合规OpenSSH?

Hey there! Since you already have a FIPS-compliant OpenSSL build configured with the fipscanister, getting a FIPS-compliant OpenSSH up and running on your Linux distro is totally manageable. Let’s walk through this step by step, keeping things straightforward even if you don’t have a cybersecurity background:

1. Gather OpenSSH Source & Build Dependencies
  • First, grab the source code for a stable, FIPS-compatible OpenSSH version (v8.0+ is recommended, as these have mature FIPS support). You can pull it from the official OpenSSH repository or your distro’s source package archive.
  • Install the essential build tools if you haven’t already:
    • For Debian/Ubuntu-based systems:
      sudo apt install build-essential autoconf automake libtool
      
    • For RHEL/CentOS/Fedora-based systems:
      sudo yum groupinstall "Development Tools"
      
2. Compile OpenSSH Against Your FIPS-Compliant OpenSSL

This is the core step—we need to force OpenSSH to link against your existing FIPS OpenSSL instead of the system default:

  • First, set environment variables to point to your FIPS OpenSSL installation (replace /path/to/your/fips-openssl with your actual directory):
    export OPENSSL_DIR=/path/to/your/fips-openssl
    export PATH="$OPENSSL_DIR/bin:$PATH"
    export LD_LIBRARY_PATH="$OPENSSL_DIR/lib:$LD_LIBRARY_PATH"
    export CPPFLAGS="-I$OPENSSL_DIR/include"
    export LDFLAGS="-L$OPENSSL_DIR/lib"
    
  • Navigate to your OpenSSH source directory, then run the configure script with FIPS support enabled:
    ./configure \
      --prefix=/usr/local/openssh-fips \
      --with-ssl-dir=$OPENSSL_DIR \
      --enable-fips
    
    • --prefix: Sets where your FIPS-compliant OpenSSH will be installed (pick a directory that makes sense for your system).
    • --with-ssl-dir: Ensures we link against your FIPS-approved OpenSSL.
    • --enable-fips: The critical flag that enables OpenSSH’s FIPS mode.
  • Compile and install:
    make -j$(nproc)  # Uses all available CPU cores for faster build
    sudo make install
    
3. Configure OpenSSH to Enforce FIPS Compliance

After installation, tweak the config files to only use FIPS-approved cryptographic algorithms:

  • Edit the SSH daemon config (/usr/local/openssh-fips/etc/sshd_config—adjust path if you used a different --prefix):
    FIPSMode yes
    # Restrict to FIPS-approved ciphers
    Ciphers aes256-ctr,aes192-ctr,aes128-ctr
    # Restrict to FIPS-approved MACs
    MACs hmac-sha2-256,hmac-sha2-512
    # Restrict to FIPS-approved key exchange algorithms
    KexAlgorithms ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256
    
  • Edit the client config (/usr/local/openssh-fips/etc/ssh_config) to enable FIPS mode for client connections too:
    FIPSMode yes
    
  • Validate the config files to catch any syntax errors:
    /usr/local/openssh-fips/sbin/sshd -t
    /usr/local/openssh-fips/bin/ssh -G user@your-host | grep fipsmode
    

If you want your system to use this FIPS-compliant OpenSSH by default:

  • Stop the existing SSH daemon:
    sudo systemctl stop sshd
    
  • Back up the original binaries:
    sudo mv /usr/bin/ssh /usr/bin/ssh-original
    sudo mv /usr/sbin/sshd /usr/sbin/sshd-original
    
  • Create symlinks to your FIPS-compliant binaries:
    sudo ln -s /usr/local/openssh-fips/bin/ssh /usr/bin/ssh
    sudo ln -s /usr/local/openssh-fips/sbin/sshd /usr/sbin/sshd
    
  • Restart the SSH daemon:
    sudo systemctl start sshd
    
5. Verify FIPS Compliance

Finally, confirm everything is working as expected:

  • Check that OpenSSH is linked to your FIPS OpenSSL:
    ldd /usr/local/openssh-fips/bin/ssh | grep libssl
    
    The output should point to the libssl.so in your FIPS OpenSSL directory.
  • Test that non-FIPS algorithms are blocked: Try connecting with a non-approved cipher like aes128-cbc—you should get an error saying the cipher is not permitted:
    ssh -c aes128-cbc user@your-host
    
  • Confirm FIPS mode is enabled:
    ssh -G user@your-host | grep fipsmode
    
    You should see fipsmode yes in the output.

内容的提问来源于stack exchange,提问作者Raven

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:36:38