# Issues trying to enable FIPS 140-2 on Centos 8

**URL:** <https://discuss.elastic.co/t/issues-trying-to-enable-fips-140-2-on-centos-8/300505>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 23, 2022, 9:31pm UTC](https://discuss.elastic.co/t/issues-trying-to-enable-fips-140-2-on-centos-8/300505 "2022-03-23T21:31:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ryann](https://avatars.discourse-cdn.com/v4/letter/r/bbe5ce/32.png) [@ryann](https://discuss.elastic.co/u/ryann)\
**Post date:** [March 23, 2022, 9:31pm UTC](https://discuss.elastic.co/t/issues-trying-to-enable-fips-140-2-on-centos-8/300505/1 "2022-03-23T21:31:34Z")

</div>

Trying to enable FIPS mode in Elasticsearch and running into issues. When using default bundled JVM with FIPS mode enabled configuration passes bootstrap checks. Enabled fips globally in Centos and pointed systemd file to use system java install instead. When trying to start the service back up running into error.

> java.security.NoSuchAlgorithmException: PBKDF2WithHmacSHA512 SecretKeyFactory not available

Here is my elasticsearch.yml contents:

```auto
# ---------------------------------- Security ----------------------------------
#
# ***WARNING***
#
# Elasticsearch security features are not enabled by default.
# These features are free, but require configuration changes to enable them.
# This means that users don’t have to provide credentials and can get full access
# to the cluster. Network connections are also not encrypted.
#
# To protect your data, we strongly encourage you to enable the Elasticsearch security features.
# Refer to the following documentation for instructions.
#
# https://www.elastic.co/guide/en/elasticsearch/reference/7.16/configuring-stack-security.html
xpack.security.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.key: /etc/elasticsearch/ssl/http-key.key
xpack.security.http.ssl.certificate: /etc/elasticsearch/ssl/http-cert.crt

xpack.security.fips_mode.enabled: true
xpack.security.authc.password_hashing.algorithm: pbkdf2_stretch

```

After turning FIPS mode on also reset all passwords for users.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 24, 2022, 2:57am UTC](https://discuss.elastic.co/t/issues-trying-to-enable-fips-140-2-on-centos-8/300505/2 "2022-03-24T02:57:39Z")

</div>

> [@ryann](#):
>
> When using default bundled JVM with FIPS mode enabled

What exactly do you mean by this?  
If you simply set `xpack.security.fips_mode.enabled: true` in `elasticsearch.yml` then it is unsurprising that it worked - all that setting does is configure Elasticsearch to avoid non-FIPS approved algorithms. It does not configure the underlying JVM to run in FIPS mode.

> [@ryann](#):
>
> Enabled fips globally in Centos and pointed systemd file to use system java install instead.

I'm not an expert of what Centos does to set java into FIPS mode.  
Do you know what underlying crypto provider it uses for that?  
I think it uses the Sun PKCS#11 provider with the Operating System's NSS setup acting as a PKCS#11 token.  
In theory that _might_ work, but it's not a config we test or support.

Per our [support matrix](https://www.elastic.co/support/matrix#matrix_jvm) the only supported configuration is the Oracle JVM with the BouncyCastle FIPS provider.

---

<div class="post-metadata">

**Author:** ![ryann](https://avatars.discourse-cdn.com/v4/letter/r/bbe5ce/32.png) [@ryann](https://discuss.elastic.co/u/ryann)\
**Post date:** [March 24, 2022, 1:16pm UTC](https://discuss.elastic.co/t/issues-trying-to-enable-fips-140-2-on-centos-8/300505/3 "2022-03-24T13:16:27Z")

</div>

> [@TimV](#):
>
> What exactly do you mean by this?

Correct, I didn't configure the bundled JVM at all just set `xpack.security.fips_mode.enabled: true` just to confirm I was clearing all the elasticsearch bootstrap checks before configuring the JVM.

You are correct Centos is using `Sun PKCS#11` when fips mode is enabled globally. I will try adding the BouncyCastle provider and see if that works.

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2022, 1:16pm UTC](https://discuss.elastic.co/t/issues-trying-to-enable-fips-140-2-on-centos-8/300505/4 "2022-04-21T13:16:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
