Enabling and disabling FIPS

FIPS is a U.S. government security standard that defines security requirements for cryptographic modules used to protect sensitive information. FIPS 140-3 is the latest version of the U.S. and Canadian government security standard that defines security requirements for cryptographic modules in IT and telecommunications products. Its purpose is to ensure that products handling sensitive data via cryptography are secure and reliable. Federal agencies must use FIPS 140-3 validated modules. It is also widely adopted by defence contractors and financial institutions.

To ensure FIPS compliance, all HCL Workload Automation components must be at version 10.2.5 or later, certificates must employ at least a robust 2K RSA key and use encryption algorithms different from MD5-RSA and SHA1-RSA. FIPS is supported on all supported operating systems with the exception of IBM i operating systems.

Read the following topics to find out how to enable FIPS in your environment:
Note: FIPS 140-3 compliance: In agreement with the specifications provided in point 3 in FIPS certified cryptography in IBM Semeru Runtimes, HCL Workload Automation operates under an exception regarding read access to PKCS#12 keystores by using a specific provider.