CryptoModeSet
Trigger this action to set the appliance-wide cryptographic mode for the next firmware reload.
Notes:
- On AIX®, Linux®, and Windows, IBM® MQ provides FIPS 140-3 compliance through the GSKit 9 IBM Crypto for C (ICC) cryptographic module. The NIST certification associated with the FIPS 140-3 module can be viewed at https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4755.
- FIPS support is currently not available for Linux s390x. Customers on this platform who require FIPS support should remain at a previous version of IBM MQ. Support for FIPS 140-3 will be enabled in a future FixPack once the IBM Crypto for C (ICC) cryptographic module has received its certification on this platform.
- The FIPS 140-3 cryptographic module within IBM Semeru Runtime was approved by NIST in August 2024. IBM MQ 10.0.0 adds support for the handling of IBM MQ classes for JMS and IBM MQ classes for Java client connections using TLS for FIPS 140-3 in Java 8 and IBM Semeru Runtime 11+. The NIST certification associated with the FIPS 140-3 module can be viewed at https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4755.
- For IBM MQ in Containers, the IBM MQ Operator 3.2.0 and queue manager container image 9.4.0.0 onwards are based
on UBI 9. FIPS 140-3 compliance for IBM MQ in Containers is currently
pending.
If FIPS is enabled, IBM MQ in Container control processes use a FIPS 140-3 Certified OpenSSL Module. Details of the NIST certification can be viewed at: https://access.redhat.com/compliance/fips. IBM MQ queue managers running in container images have the same FIPS certification level as the base image platform version of IBM MQ.
Use the HTTP POST method with the resource
/mgmt/actionqueue/default, specifying
a request payload with the following
format:{
"CryptoModeSet": {
"Mode": "crypto-mode"
}
}- Mode
- String
Example
To set the appliance cryptographic mode to the FIPS 140-2 Level 1 mode, post the following
payload to https://yourhost:5554/mgmt/actionqueue/default:
{
"CryptoModeSet": {
"Mode": "fips-140-2-l1"
}
}