FIPS compatibility for Nagios/NCPA

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
hbouma
Posts: 483
Joined: Tue Feb 27, 2018 9:31 am

FIPS compatibility for Nagios/NCPA

Post by hbouma »

Our IT Security team is requiring FIPs mode for all RHEL 8 servers going forward. We are seeing that the NCPA agent has been having issues on some of these servers, and may be running into issues with our Nagios XI instance (https://support.nagios.com/forum/viewto ... 16&t=64456).

My question is, does the Nagios XI 5.8.6+ version and NCAP 2.4.0 support FIPS mode? We are running into this issue with our NCPA system: https://github.com/NagiosEnterprises/ncpa/issues/655
ssax
Dreams In Code
Posts: 7682
Joined: Wed Feb 11, 2015 12:54 pm

Re: FIPS compatibility for Nagios/NCPA

Post by ssax »

Nagios XI and NCPA are not compatible with operating in FIPS mode at this time.

I haven't personally tried compiling NRPE on a FIPs mode system but since it's compiled it may work as an agent long as the protocols/ciphers are supported on the XI server.
hbouma
Posts: 483
Joined: Tue Feb 27, 2018 9:31 am

Re: FIPS compatibility for Nagios/NCPA

Post by hbouma »

Is there an ETA for when FIPS mode will be supported? It is a requirement by our IT Security team as well as a recommendation from Red Hat.
ssax
Dreams In Code
Posts: 7682
Joined: Wed Feb 11, 2015 12:54 pm

Re: FIPS compatibility for Nagios/NCPA

Post by ssax »

I'm unable to give an ETA at this time but I talked with development the other day about NCPA/FIPS and they said they will take a closer look at supporting FIPS in NCPA 3.

I labbed it up with a FIPS enabled remote system and you can also monitor it through SSH as an alternative:

https://assets.nagios.com/downloads/nag ... ng_SSH.pdf
Locked