MID Server FIPS Enforced Mode
The MID Server supports the National Security Cloud (NSC) IL-5 environment, which requires all utilized cryptography to be FIPS validated. The MID server can be run in FIPS Enforced Mode, where only cryptographic algorithms which are FIPS validated are utilized.
The Federal Information Processing Standards are a group of standards compiled by the National Institute of Standards and Technology for use in computer systems. There are many FIPS publications, but for the sake of this discussion we are specifically referring to FIPS 140-2: Security Requirements for Cryptographic Modules. Cryptographic algorithms can proceed through a validation process specified by the NIST. For the purposes of our new secure cloud environment, the MID server will be utilizing algorithms that have been validated by such process.
Only MID Servers of the Rome release family or later with a JRE version of 11.0.9+11 or later can be set to run in FIPS Enforced Mode.
FIPS Enforced Mode
The following algorithms are not available for use in these SSH functions by the MID Server in FIPS Enforced Mode.
- Key Exchange:
- diffie-hellman-group1-sha1
- Mac:
- hmac-md5
- hmac-md5-96
The following restrictions are now in place for SNMP for use by the MID Server in FIPS Enforced Mode.
- SNMP v1 and v2 are completely disabled.
- For SNMP v3, the following protocol uses are not permitted by the MID Server in FIPS
Enforced Mode:
- auth protocol: none or MD5
- privacy protocol: none or DES
Other functionality that utilizes the MID Server may be impacted when run in FIPS Enforced Mode. Please refer to that functionality's specific documentation for details.
Enable MID Server FIPS Enforced Mode
The MID server can be run in FIPS Enforced Mode, where only cryptographic algorithms which are FIPS validated are utilized.
Antes de Iniciar
Role required: admin
Procedimento
O que Fazer Depois
The mode the MID is running in can be confirmed via two methods:
- Check the agent logs after start-up and look for the following log line:
Running in FIPS Enforced mode - Check the ecc_agent table on the instance and look for the value of the FIPS Enforced boolean column.
Manually convert the MID Server to FIPS Enforced Mode
The MID server can be run in FIPS Enforced Mode, where only cryptographic algorithms that are FIPS-validated are utilized.
Antes de Iniciar
Role required: admin
Por Que e Quando Desempenhar Esta Tarefa
Convert the JRE’s TrustStore to BCFKS type.
Set the JRE’s default KeyStore type to be BCFKS.
Set the FIPS Enforced Mode flag in the MID Server's configuration file.