ENSM 26.8.0 and later provides FIPS mode. This mode follows security guidelines in section 140-2 of the federal standard.
This enhancement enables product components to use FIPS-capable OpenSSL libraries. These libraries ensure secure communication and data protection.
Note
This release supports FIPS mode. The product is not FIPS-certified.
Automatic activation
FIPS-capable libraries are active by default. Relevant binaries use these libraries regardless of your environment configuration.
You do not need to register the product. You do not need to configure settings to enable FIPS mode. You cannot disable this mode.
System architecture
The Reputation Business Object (RBO) initializes the cryptographic context during service startup. The following dependent modules leverage this shared context:
Threat Prevention (TP)
Adaptive Threat Protection (ATP)
Web Protection (WP)
In FIPS mode, bundled OpenSSL libraries only use approved cryptographic algorithms. These libraries do not support unapproved algorithms like MD5.
Some platform operations use macOS cryptographic services. These services might use non-approved algorithms where applicable.
Certificate management
The product uses the default macOS Keychain to manage certificates. You do not need to manually import certificates for FedRAMP or commercial environments.