

Client Automation Security Features › FIPS-Compliant Cryptography › Run the Conversion Utility
Run the Conversion Utility
Running the conversion utility configures DSM components to use the required FIPS mode. Run this utility in the following order:
- Enterprise manager (if present)
- Domain managers
To run the conversion utility
- Verify that all the configuration policies are sealed on the manager.
- Open the command-line window and navigate to the ITCM_installpath\bin folder.
- Execute the following command:
dmscript dsm_fips_conv.dms FIPS_Mode
- FIPS_Mode
-
Specifies the FIPS mode you want to switch to. Valid values are FIPS-Only and FIPS-Preferred.
After the utility completes, it returns a success or failure message. If you have executed the utility with the FIPS-ONLY parameter, the utility changes the FIPS mode of the corresponding manager depending on the success or failure of the utility execution.
- Open DSM Explorer on the manager, click the root node, and check the System Status portlet for FIPS-140.
The FIPS-140 setting displays the FIPS mode of the manager.
- If the utility had executed successfully, this setting displays FIPS-Preferred (Ready for FIPS-Only). You can proceed to modify the configuration policy to change the FIPS mode in this case.
- If the utility had failed, the setting displays FIPS‑Preferred (Error Running dsm_fips_conv). The manager continues to operate in this mode until the conversion utility is successfully run on the manager.
Note: When the manager is operating in any of these two modes, r12 clients (DSM Explorer, CLI, and so on) are prevented from connecting to the manager.
- Perform the following steps, if the utility had completed with errors or warnings:
- View the log file osimfiputil.log in the ITCM_installpath\bin folder if the script completed with errors or warnings. You can also find more information in the Event log.
- Take corrective actions to fix the errors and run the conversion utility again.
The DSM components are configured to use the required FIPS mode.
Example: Command for running the conversion utility for FIPS-only mode:
dmscript dsm_fips_conv.dms FIPS_ONLY
More information:
How to Switch to FIPS-Only Mode
How to Switch to FIPS-Preferred Mode
Verify the FIPS Mode of DSM Components
Copyright © 2014 CA Technologies.
All rights reserved.
 
|
|