After re-encrypting all the necessary data to use FIPS-compatible algorithms, confirm all that all the partnerships and the SSL configuration is FIPS-compatible.
To confirm the settings
Use the Federation Manager stop and start shortcuts as follows:
a. Open a command window.
b. Run the following scripts:
federation_mgr_home/fedmanager.sh stop
federation_mgr_home/fedmanager.sh start
When you run the fedmanager.sh script, it sources the Federation Manager environment script, ca_federation_env.ksh.
Note: Do not stop and start the services as the root user. You must be a non-root user.
The Configure Deployment Settings dialog opens.
If these two conditions are not met, one or more of the partnerships or the SSL configuration is not FIPS-enabled. A partnership is not FIPS-enabled because of the following reasons:
If you configure the Redirect Mode setting to use an open format cookie with a PBE encryption algorithm, the mode is not FIPS-compatible.
If you configure the Provisioning Delivery Type to use an open format cookie with a PBE encryption algorithm, this delivery mechanism is not FIPS-compatible.
If you set the open format cookie settings in the Deployment Settings dialog to use a PBE encryption algorithm, the cookie is not FIPS-compatible.
To correct these problems, do the following:
The Federation Manager UI is now operating in FIPS_ONLY mode.
| Copyright © 2010 CA. All rights reserved. | Email CA about this topic |