Federal Information Processing Standard

Federal Information Processing Standards (FIPS) are standards and guidelines that are issued by the National Institute of Standards and Technology (NIST) for federal government computer systems.

Government agencies and financial institutions use Federal Information Processing Standard (FIPS) to ensure that the products conform to specified security requirements. For more information about these standards, see the NIST website.

FIPS is the standard that defines the security requirements for cryptographic modules that are used within a system that handles sensitive but unclassified information. Compliance with the FIPS standard has two aspects that affect License Metric Tool: the algorithms that are used to manage sensitive data must be FIPS-approved and a FIPS-approved implementation must be used when data is transmitted with the SSL/TLS.

FIPS standards

License Metric Tool can use the following FIPS standards depending on the application update. For information how to configure FIPS compliance, see: Configuring the server to achieve FIPS compliance.
Table 1. FIPS standards
Application update FIPS standard Comments
Application update 9.2.43 and later
  • FIPS 140-3-Weakly-Enforced restricted security mode profile
  • FIPS 140-3-Strongly-Enforced restricted security mode profile
Configuring FIPS 140-3 restricted security mode profile is not supported. However, FIPS 140-3-Strongly-Enforced restricted security mode profile can remain FIPS 140-3 compliant on condition that you properly configure services that the Strongly-Enforced profile allows. Out of these services, only PKCS file support is used by License Metric Tool. For more information about the profiles, see: FIPS 140-3 cryptography solution in IBM Semeru Runtimes.
Application update 9.2.42 and earlier FIPS 104-2