Enabling FIPS compliance on the controller
The IBM® BigFix® Remote Control controller is a Java™ application that requires a FIPS certified cryptographic provider when FIPS compliance is enabled. Only the IBM Java Runtime Environment (JRE) is supported in FIPS-compliant mode.
About this task
The IBM JRE for Windows® operating system and Linux® (Intel®) operating systems is included with IBM BigFix Remote Control and is installed when you install the controller software.
If you are using Windows operating system, the JRE is included in the controller package trc_controller_setup.exe and trc_controller.msi. For Linux operating system, the JRE is included in the package ibm-trc-controller-jre-9.x.x.i386.rpm. Where 9.x.x is the version that you want to install. For example, 9.1.0. These packages install the IBM Java Runtime Environment pre-configured with the IBM FIPS certified cryptographic provider. They also register the MIME type application/x-ibm-trc-jws and a file association for *.trcjws files. The file types are used by the IBM BigFix Remote Control server in FIPS-compliant mode to start the controller. For more information about installation instructions for the controller, see Install the controller.
To enable FIPS compliance on the controller if you are not using the version of IBM JRE supplied with IBM BigFix Remote Control, complete the following steps:
Procedure
Results
Check to see whether the controller is configured for FIPS by completing the following step during a remote control session.
- Click in the controller window.
- Windows systems
- [controller install dir]\trc_controller.cfg
Where [controller install dir] is the installation directory that is chosen when you install the controller.
- Linux systems
- opt/ibm/trc/controller/trc_controller.cfg