SSLFIPSMODE
The SSLFIPSMODE option specifies whether the Federal Information Processing Standards (FIPS) mode is in effect for Secure Sockets Layer (SSL). The default is NO.
Because SSLv3 is not supported by FIPS mode, when you are using SSL with version 6.1 or
version 5.5 clients, you must turn off FIPS mode.
Syntax
Parameters
- No
- Specifies that SSL FIPS mode is not active on the server. This setting is required when Backup-Archive Client versions previous to IBM Storage Protect 6.3 are to connect to the server with SSL.
- Yes
- A value of YES indicates that SSL FIPS mode is active on the server. This setting restricts SSL session negotiation to use FIPS-approved cipher suites. Specifying YES is suggested when SSL communication is activated and all Backup-Archive Clients are at version 6.3 or later.
Example: Enable SSL FIPS mode on the server
sslfipsmode yes
