The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Default FedRamp support in ENS for Mac

Prev Next

ENSM 26.8.0 and later provides FIPS mode. This mode follows security guidelines in section 140-2 of the federal standard.

This enhancement enables product components to use FIPS-capable OpenSSL libraries. These libraries ensure secure communication and data protection.

Note

This release supports FIPS mode. The product is not FIPS-certified.

Automatic activation

FIPS-capable libraries are active by default. Relevant binaries use these libraries regardless of your environment configuration.

You do not need to register the product. You do not need to configure settings to enable FIPS mode. You cannot disable this mode.

System architecture

The Reputation Business Object (RBO) initializes the cryptographic context during service startup. The following dependent modules leverage this shared context:

  • Threat Prevention (TP)

  • Adaptive Threat Protection (ATP)

  • Web Protection (WP)

In FIPS mode, bundled OpenSSL libraries only use approved cryptographic algorithms. These libraries do not support unapproved algorithms like MD5.

Some platform operations use macOS cryptographic services. These services might use non-approved algorithms where applicable.

Certificate management

The product uses the default macOS Keychain to manage certificates. You do not need to manually import certificates for FedRAMP or commercial environments.