SSLFIPSMODE

The SSLFIPSMODE option specifies whether the Federal Information Processing Standards (FIPS) mode is in effect for Secure Sockets Layer (SSL). The default is NO.

Because SSLv3 is not supported by FIPS mode, when you are using SSL with version 6.1 or version 5.5 clients, you must turn off FIPS mode.

Syntax

Read syntax diagramSkip visual syntax diagramSSLFIPSMODE=NoSSLFIPSMODE=NoYes

Parameters

No
Specifies that SSL FIPS mode is not active on the server. This setting is required when Backup-Archive Client versions previous to IBM Storage Protect 6.3 are to connect to the server with SSL.
Yes
A value of YES indicates that SSL FIPS mode is active on the server. This setting restricts SSL session negotiation to use FIPS-approved cipher suites. Specifying YES is suggested when SSL communication is activated and all Backup-Archive Clients are at version 6.3 or later.

Example: Enable SSL FIPS mode on the server

sslfipsmode yes