Configuring FIPS 140-3 on the BigFix Server

Starting from BigFix Platform Version 11.0.7, you can configure the BigFix server to use FIPS 140-3.

On Windows

To enable FIPS 140-3, perform the following steps:
  1. On the BigFix server, launch the BigFix Administration Tool by selecting Start > All Programs > BigFix > BigFix Administration Tool.
  2. Browse to the location of your site license and click OK
  3. Select the Masthead Management tab.
  4. Click Edit Masthead.
  5. Check Require use of FIPS compliant cryptography ; it will enable the two mutually exclusive FIPS alternatives, with FIPS 140-2 selected by default.
  6. Select the Use FIPS 140-3 compliant cryptography option.
  7. Click OK.
  8. Restart the BigFix server processes.
To ensure that the FIPS 140-3 mode has been successfully enabled, verify if the following messages are present in the C:\Program Files (x86)\BigFix Enterprise\BES Server\BESRelay.log file of the BigFix Server:
OpenSSL Initialized (FIPS Mode)
FIPS mode: 140-3 Compliant Mode selected.

For more information about how to manage FIPS with BigFix Administration Tool on Windows, see Editing the Masthead on Windows systems.

On Linux

To enable FIPS 140-3, perform the following steps:
  1. On the BigFix server, move to the /opt/BESServer/bin directory.
  2. Run the following BigFix Administration Tool command:
    BESAdmin.sh -editmasthead -advRequireFIPS_140_3_Crypto=true -sitePvkLocation=/opt/iemlic/license.pvk
  3. Enter the license.pvk password.
  4. Restart the BigFix server processes.
To ensure that the FIPS 140-3 mode has been successfully enabled, verify if the following messages are present in the /var/log/BESRelay.log file of the BigFix Server:
OpenSSL Initialized (FIPS Mode)
FIPS mode: 140-3 Compliant Mode selected.

For more information about how to manage FIPS with BigFix Administration Tool on Linux, see Editing the Masthead on Linux systems.