FAQ - Security configurations
A list of questions and answers related to security configurations:
When installing the HCL Workload Automation, you might have the need to customize some parameters to suit your environment.
- Can I install any HCL Workload Automation components without setting up the SSL configuration?
- No, starting from version 10.2.1, certificates, either default or custom, are required when installing HCL Workload Automation. You can no longer install HCL Workload Automation without securing your environment with certificates.
- Q:How do I set up SSL communication using custom certificates for master domain manager and dynamic agent?
- See the detailed explanation in Customizing certificates for master domain manager and dynamic agent communication.
- Q:How do I set up SSL communication using custom certificates for master domain manager and Dynamic Workload Console?
- See the detailed explanation in Customizing certificates for master domain manager and Dynamic Workload Console communication.
- Q: How do I set up SSL communication using custom certificates for agents?
- You can use the -sslkeysfolder and --sslpassword parameters when installing fault-tolerant agents and dynamic agents with the twsinst command. For more information, see Agent installation parameters - twsinst script.
- How do I configure master domain manager and dynamic domain manager in SSL mode?
- See the detailed explanation in Configuring your master domain manager and dynamic domain manager in SSL mode.
- Q: Is FIPS supported?
- FIPS compliance is not supported in the current product version. This is because OpenSSL 3.0 libraries do not provide a FIPS-compliant validation algorithm for P12 certificates. Development is in progress with the aim of supporting FIPS in upcoming releases.