
Updating to FIPS 140-2 security standards
Federal Information Processing Standards (FIPS) are standards and guidelines that are
issued by the National Institute of Standards and Technology (NIST) for federal government computer
systems. Federal Information Processing Standards publication 140-2 (FIPS 140-2) covers the security
standards that are required for cryptographic modules. When in FIPS 140-2 mode, IBM WebSphere
Commerce, through IBM WebSphere Application Server and IBM HTTP Server, uses the FIPS 140-2 approved
cryptographic providers: IBMJCEFIPS (certificate 376) and IBMJSSEFIPS (certificate 409) for
cryptography. The certificates are listed on the NIST website at
http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm.
Before you begin
- Ensure that you are running on WebSphere Application Server 7.0.0.41 or higher. To upgrade WebSphere Application Server, download the fix at IBM Fix Central.Warning: A potential security vulnerability was found in all versions at or below 7.0.0.39. For more information, see CVE-2016-0306.
- Install WebSphere Commerce Version 7 Fix Pack 8.
- If you are using any of the following features, you must upgrade to Feature Pack 7.
Gift Center
WebSphere Commerce search
Data Load utility
IBM Digital Analytics
Bazaarvoice
Procedure
Enable FIPS 140-2 mode within the WebSphere Application Server for WebSphere Commerce and WebSphere Commerce search.
Enable FIPS 140-2 mode for all WebSphere Commerce application web servers and WebSphere Commerce search web servers.