Federal Information Processing Standards (FIPS)

You can configure WebSphere Automation 1.6.3 or later to be Federal Information Processing Standards (FIPS)-compliant. FIPS enablement is not configured by default.

The National Institute of Standards and Technology (NIST) issues Federal Information Processing Standards (FIPS), which are standards and guidelines for federal government computer systems. The standards are developed when compelling federal government requirements for standards, such as for security and interoperability, exist, but acceptable industry standards or solutions do not exist. Government agencies and financial institutions use these standards to ensure that products conform to specified security requirements.

Encryption with FIPS support enabled

When FIPS support is enabled, WebSphere Automation uses cryptographic modules that are compliant with Level 1 of the Federal Information Processing Standard FIPS-140-2. Certificates that are used internally are encrypted by using FIPS-approved cryptography algorithms. FIPS-approved modules can be used for the transmission of data. Traffic inside the WebSphere Automation boundary is still secure, as traffic between nodes is automatically encrypted at the Red Hat® OpenShift® Container Platform level when TLS protection is enabled. Traffic inside a node happens in-memory and does not leave the node.

FIPS overview

FIPS (Federal Information Processing Standards) compliant encryption is validated for WebSphere Automation services and components, including the IBM Cloud Pak foundational services that are used by WebSphere Automation.

With FIPS enabled, data is FIPS encrypted at rest and inbound communications are FIPS encrypted. Outbound communications can support both FIPS enabled and nonenabled connections. For FIPS enabled connections, outbound connections rely on the server to ensure that FIPS ciphers are chosen. To ensure that connections (including observers) are FIPS enabled, an external service is necessary to mandate the use of FIPS-compliant ciphers when encryption is negotiated. You can view a listing of supported cipher suites for FIPS-enabled clusters on the WebSphere Automation Security considerations documentation page.

Enabling FIPS support

To enable FIPS support, you must enable this support when you are installing Red Hat OpenShift Container Platform and WebSphere Automation. For more information, see the following pages.