Federation Manager Installation and Upgrade Guide › Migrate Federation Manager to Use FIPS Encryption › How to Migrate from FIPS_COMPAT Mode to FIPS_Only Mode › Set the Policy Engine to FIPS_Only Mode
Set the Policy Engine to FIPS_Only Mode
The final step in the migration process is to set the policy engine to FIPS_Only mode.
Follow these steps:
- (Solaris only) Source the Federation Manager environment script, ca_federation_env.ksh to set the proper environment variables.
- From a command prompt, run the setFIPSmigration command, as follows:
- Windows
-
Enter setFIPSonly
- UNIX
-
- Navigate to federation_mgr_home\secure-proxy.
- Enter setFIPSonly.ksh.
- Run the environment script, ca_federation_env.ksh to set the environment variables.
After the command is successful, the words FIPS_ONLY appears at the command prompt.
- Do one of the following:
- Windows
-
Reboot the Federation Manager system.
- UNIX
-
Restart the Federation Manager services by executing the following scripts from a command window:
- federation_mgr_home/fedmanager.sh stop
- federation_mgr_home/fedmanager.sh start
- Verify that the policy engine is operating in FIPS_ONLY mode. Check the smps log in the directory federation_mgr_home\logs\server.
|
Copyright © 2012 CA.
All rights reserved.
|
|