---
sourceDocument: Australia ServiceNow AI Platform Capabilities
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/servicenow-platform

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia ServiceNow AI Platform Capabilities

ft:clusterId :

    - platcap

bundleId :

    - platcap

workflow :

    - Platform


---

# MID Server FIPS Enforced Mode

# MID Server FIPS Enforced Mode {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 Minuten Lesedauer

The MID Server supports the National Security Cloud (NSC) IL-5 environment, which
requires all utilized cryptography to be FIPS validated. The MID server can be run in FIPS
Enforced Mode, where only cryptographic algorithms which are FIPS validated are utilized.

|-|
|   |
[ ]

{#mid-fips-enforced__table_yfh_kv4_nhb}

The Federal Information Processing Standards are a group of standards compiled by the National
Institute of Standards and Technology for use in computer systems. There are many FIPS
publications, but for the sake of this discussion we are specifically referring to [++FIPS 140-2: Security Requirements for Cryptographic Modules++](https://csrc.nist.gov/publications/detail/fips/140/2/final).
Cryptographic algorithms can proceed through a validation process specified by the NIST. For the
purposes of our new secure cloud environment, the MID server will be utilizing algorithms that
have been validated by such process.

Only MID Servers of the Rome release family or later with a JRE version of 11.0.9+11 or later
can be set to run in FIPS Enforced Mode.

## FIPS Enforced Mode {#mid-fips-enforced__section_uhm_ygr_gqb}

The following algorithms are not available for use in these SSH functions by the MID Server in
FIPS Enforced Mode.

Key Exchange:
:   diffie-hellman-group1-sha1

Mac:
:
    * hmac-md5
    * hmac-md5-96
    {#mid-fips-enforced__ul_rjq_ygr_gqb}

The following restrictions are now in place for SNMP for use by the MID Server in FIPS
Enforced Mode.

* SNMP v1 and v2 are completely disabled.
* For SNMP v3, the following protocol uses are not permitted by the MID Server in FIPS Enforced Mode:
  * auth protocol: none or MD5
  * privacy protocol: none or DES
  {#mid-fips-enforced__ul_tjq_ygr_gqb}

{#mid-fips-enforced__ul_sjq_ygr_gqb}

Other functionality that utilizes the MID Server may be impacted when run in FIPS Enforced
Mode. Please refer to that functionality's specific documentation for details.
**Zugehörige Konzepte**   

* [MID Server certificate check policies](https://servicenow-prod.fluidtopics.net/VBqU5CHqCSU2m2xJd2a6uA "MID Server uses four kinds of security checks to secure external traffic. The security checks use TLS/SSL certificate validation, hostname validation, Certificate Revocation List (CRL), and Online Certificate Status Protocol (OCSP) validation to improve security. Control these security checks with the MID Server certificate check policies table.")
* [MID Server authentication credentials and SOAP requests](https://servicenow-prod.fluidtopics.net/80f2cul5Bjz0opflAxzxPg#mid-authentication-soap-requests "Set basic authentication credentials to update the web service invocation data. For added security, you can enforce basic authentication on each incoming SOAP request to the MID Server.")
* [MID Server unified key store](https://servicenow-prod.fluidtopics.net/zWbtuI59iqjA5LfLDw8VPA#mid-unified-keystore "The MID Server unified key store allows all products on the MID Server to use common certificates and key pairs. This feature allows applications to use the same secure communication channel to the MID Server that the MID Server uses to connect to the instance.")
* [MID Server command audit log](https://servicenow-prod.fluidtopics.net/hMnNVhNJPmpY4gLr76lWAg "The command audit log records the commands run by the MID Server for the Discovery application. Review the commands to check for anomalies or errors.")
* [MID Server Governance](https://servicenow-prod.fluidtopics.net/aFXIuu3zlxcmFMjRZPM1Ug "Improve MID Server security by setting an automatic timeout to invalidate and shut down inactive MID Servers. You can enable this feature and set the inactivity timeout period globally and for each MID Server.")  
**Zugehörige Tasks**   

* [Encrypt or decrypt MID Server configuration file values](https://servicenow-prod.fluidtopics.net/iCgc9bn4JQYK9vgd1wAC6w "The value of any MID Server parameter in the config.xml file can be encrypted. The attributes for all encrypted values are managed from within the configuration file, including the security attribute of the login password.")
* [Enable MID Server mutual authentication](https://servicenow-prod.fluidtopics.net/UdSuWRmz6ZGA~Y6dkWvyeQ "Configure the MID Server to use a client certificate for authenticating to the instance. This avoids the need to create a basic authentication credentials in the Key Store for the MID Server's configuration.")
* [MID Server Azure Key Vault integration](https://servicenow-prod.fluidtopics.net/q98R6SSVMU1wN5ZSqPpYrw#mid_azure_key_vault_integration "The MID Server integration with the Azure Key vault enables Orchestration, Discovery, and Service Mapping to run without storing any credentials on the instance.")
* [Rekey a MID Server](https://servicenow-prod.fluidtopics.net/pL97YclPNbf5hsjR6JhaEA "Rekey a MID Server to generate a new private key. Private keys are used to decrypt automation credentials, so that MID Servers can transmit information securely. Key pairs are initially generated when a MID Server is validated, and MID Servers should be rekeyed periodically to meet security requirements.")
* [Add SSL certificates for the MID Server](https://servicenow-prod.fluidtopics.net/Wze_LuvGY3XWJMv9a~ORjg#add-ssl-certificates "Configure the MID Server to connect to a source over SSL.")
* [Attach a script file to a file synchronized MID Server](https://servicenow-prod.fluidtopics.net/vu1Hjk_D3VmPooctXzxerQ#mid-server-script-attach "You can attach a script file to synchronize to a connected MID Server. Windows Internet Explorer enhanced security blocks downloaded files that it determines are potentially dangerous. However synchronizing the files avoids this security problem.")  
**Zugehörige Verweise**   

* [MID Server configuration file security](https://servicenow-prod.fluidtopics.net/pExtHd2xoAcm8Vh~FXV9oQ "Sensitive MID Server configuration data can be protected using several different schemes, including internal and external data encryption and external data storage.")
* [MID Server SSH cryptographic algorithms](https://servicenow-prod.fluidtopics.net/6XDl6hCCpG2wR7zHUqkWng "The MID Server utilizes SSH clients to perform many discovery actions. During the SSH handshake, both the client and server first determine which algorithms both parties support, then client picks the highest priority algorithm. For the Host Key Algorithm, the client picks highest priority algorithm which both parties support that matches the key type.")

## Enable MID Server FIPS Enforced Mode {#ariaid-title2}

The MID server can be run in FIPS Enforced Mode, where only cryptographic algorithms
which are FIPS validated are utilized.

### Vorbereitungen

Role required: admin

### Prozedur

1. Deploy a new MID Server or upgrade existing MID Servers to the Rome family release or later.
2. Shut down the MID Server.
3. Execute the following bundled script provided to convert the MID to run in FIPS Enforced Mode:  
   * For Windows hosts: `> <MID install directory>\agent\bin\scripts\set-fips-enforced-mode.bat on`
   * For Linux hosts: `$ <MID install directory>/agent/bin/scripts/set-fips-enforced-mode.sh on `
   {#mid-enable-fips-enforced__ul_eqw_whr_gqb}  
   Success will be logged to the console including the location of modified files and any backups generated during the conversion process. If invoked programmatically, success will be indicated by a 0 return code.
4. Start the MID Server.

### Nächste Maßnahme

The mode the MID is running in can be confirmed via two methods:

1. Check the agent logs after start-up and look for the following log line: `Running in FIPS Enforced mode `
2. Check the ecc_agent table on the instance and look for the value of the FIPS Enforced boolean column.
{#mid-enable-fips-enforced__ol_hnb_f3r_gqb}

## Manually convert the MID Server to FIPS Enforced Mode {#ariaid-title3}

The MID server can be run in FIPS Enforced Mode, where only cryptographic algorithms that are FIPS-validated are utilized.

### Vorbereitungen

Role required: admin

### Warum und wann dieser Vorgang ausgeführt wird

To manually convert the MID Server to FIPS Enforced Mode while using an external JRE, you must perform the following steps while the MID Server is shut down:

* Convert the JRE's TrustStore to BCFKS type.

* Set the JRE's default KeyStore type to be BCFKS.

* Set the FIPS Enforced Mode flag in the MID Server's configuration file.

{#mid-manual-fips-enforced__ul_rhg_djr_gqb}

### Prozedur

1. Convert the JRE's cacerts file type to BCFKS by using the [Java Keytool](https://docs.oracle.com/javase/8/docs/technotes/tools/unix/keytool.html) with a command similar to:  
   `$ keytool -importkeystore -srckeystore `**<source keystore path>**` -srcstoretype `**<source keystore type>**` -srcstorepass changeit -destkeystore `**<destination keystore path>**` -deststoretype
   BCFKS -deststorepass changeit -provider org.bouncycastle.jcajce.provider.BouncyCastleFipsProvider -providerpath `**<BouncyCastle FIPS jar path>**`
   `  
   Hinweis:  
   Rome and later MID installations contain a BouncyCastle jar suitable for this purpose. It can be found at: .../agent/lib/bc-fips.jar
2. The JRE's default KeyStore type can be set in the \<JRE installation directory\>\\conf\\security\\java.security file.
3. In that file, find the `keystore.type` line and set its value as follows: `keystore.type=bcfks `
4. In the MID Server's .../agent/conf/wrapper-override.conf file, uncomment the FIPS line and set its value to true.  
   The line should read: `wrapper.java.additional.106=-Dorg.bouncycastle.fips.approved_only=true`

