FIPS mode is a feature of the High Security (HS) module. The mechanisms and interfaces for enabling, disabling, and using FIPS cryptographic mode is available during the HS module evaluation period.
You can enable FIPS mode for:
inbound SFTP (SSH2)
inbound HTTPs/FTPs (SSL)
outbound HTTPs/FTPs (SSL) through Event Rules (except when using AWE).
FIPS mode does not apply to:
outbound client SFTP (SSH2) through Event Rules
AWE-based HTTPs/FTPs (SSL)
AWE-based SFTP (SSH2)
AS2 inbound nor outbound transactions
After you enable or disable FIPS mode, you must restart the EFT Server service.
To enable FIPS mode for SSL Connections
In the Administrator, connect to EFT Server and click the Server tab.
In the left pane, click the Server node on which you want to enable FIPS mode.
In the right pane, click the Security tab.
In the Federal Information Processing Standards (FIPS) area, select the Use FIPS certified library for SSL connections check box.
Click Apply to save the changes on EFT Server.
Stop and then restart the EFT Server service. Review the Statistics area of EFT Server's General tab to verify that the service started.
If the HS module has expired when you attempt to start a Site on a Server that has FIPS mode enabled, an error message appears in the Administrator, and the Server sends an error message to the Event Log.
In Internet Explorer (IE) version 6, TLS mode must be enabled for SSL communications to work. (In Internet Explorer, click Tools > Internet Options. Click the Advanced tab. Scroll to the Security settings and select the Use TLS 1.0 check box. TLS is enabled by default in IE7.)