Upgrading from a FIPS-enabled environment
Upgrading from a FIPS-enabled environment
To ensure FIPS compliance, all IBM® Workload Scheduler components must meet the
following requirements:
- All components must be at version 10.2.5 or later.
- The certificates must employ at least a robust 2K RSA key and use encryption
algorithms different from
MD5-RSAandSHA1-RSA. - The key must be in a format where the algorithms are supported by FIPS. For example, avoid the PKCS1 format with the MD5 algorithm or the PKCS8 format with the 3DES algorithm.
When upgrading from an environment where FIPS is enabled, you can
encounter one of the following situations:
- If certificates do not meet FIPS standards
- An error message is displayed stating that the current security configuration does not support FIPS mode and the upgrade stops. To enable FIPS in full mode, proceed to step 1.
- If certificates meet FIPS standards
- You can upgrade and maintain FIPS enabled. Proceed to step 2.
To make your environment FIPS compliant, perform the procedure described below on all components in your environment.