Previous Topic: Security Policy GroupNext Topic: Providers Policy Group


FIPS 140 Settings Policy Group

The FIPS 140 Settings policy group contains the following policies for switching the Federal Information Processing Standard (FIPS). You can modify policy parameter values by double-clicking a policy to display the Setting Properties dialog.

FIPS 140 Setting

Specifies the FIPS mode for Client Automation cryptography. You can select one of the following options:

No compliance level set

Specifies that all Client Automation cryptography continues to use legacy encryption that is not compliant with FIPS 140 standards.

FIPS 140 approved security functions are preferred

Sets the FIPS mode to FIPS-preferred. In FIPS-preferred mode, the Client Automation components support both FIPS-compliant cryptography and legacy cryptography to help ensure backward compatibility.

Only FIPS 140 approved security functions are allowed

Sets the FIPS mode to FIPS-only. In FIPS-only mode, Client Automation components support only FIPS-compliant cryptography and do not support communication with pre-Release 12.9 components.

Change action

Specifies the action to take when you change the FIPS modes in the FIPS 140 Settings policy. You can select one of the following options:

Forcibly restart CAF and all ITCM components

Specifies that CAF and all Client Automation components be automatically restarted immediately after the policy changes are applied on the target computers and then switch the FIPS mode.

Switch FIPS mode on next restart of ITCM

Specifies that the FIPS mode be switched next time when Client Automation is restarted.

Politely ask user to restart ITCM when ready

Specifies that the user be presented with a dialog seeking confirmation for restarting Client Automation and then switch the FIPS mode only if the user confirms.

Note: For more information about FIPS modes and the process of switching FIPS modes, see the CA Client Automation Implementation Guide.