Configuring FIPS 140-3 on the BigFix Server
Starting from BigFix Platform Version 11.0.7, you can configure the BigFix server to use FIPS 140-3.
On Windows
To enable FIPS 140-3, perform the following steps:
- On the BigFix server, launch the BigFix Administration Tool by selecting Start > All Programs > BigFix > BigFix Administration Tool.
- Browse to the location of your site license and click OK
- Select the Masthead Management tab.
- Click Edit Masthead.
- Check Require use of FIPS compliant cryptography ; it will enable the two mutually exclusive FIPS alternatives, with FIPS 140-2 selected by default.
- Select the Use FIPS 140-3 compliant cryptography option.
- Click OK.
- Restart the BigFix server processes.
To ensure that the FIPS 140-3 mode has been successfully enabled, verify if the following
messages are present in the C:\Program Files (x86)\BigFix Enterprise\BES
Server\BESRelay.log file of the BigFix
Server:
OpenSSL Initialized (FIPS Mode)
FIPS mode: 140-3 Compliant Mode selected.For more information about how to manage FIPS with BigFix Administration Tool on Windows, see Editing the Masthead on Windows systems.
On Linux
To enable FIPS 140-3, perform the following steps:
- On the BigFix server, move to the /opt/BESServer/bin directory.
- Run the following BigFix Administration Tool command:
BESAdmin.sh -editmasthead -advRequireFIPS_140_3_Crypto=true -sitePvkLocation=/opt/iemlic/license.pvk - Enter the license.pvk password.
- Restart the BigFix server processes.
To ensure that the FIPS 140-3 mode has been successfully enabled, verify if the following
messages are present in the /var/log/BESRelay.log file of the
BigFix Server:
OpenSSL Initialized (FIPS Mode)
FIPS mode: 140-3 Compliant Mode selected.For more information about how to manage FIPS with BigFix Administration Tool on Linux, see Editing the Masthead on Linux systems.