Administer > System security > FIPS mode > Configuring LW-SSO in FIPS mode

Configuring LW-SSO in FIPS mode

When running in FIPS mode, the Service Manager (SM) Server, Web Tier, Mobility Client, SRC, and Openfire Chat Server use a FIPS validated cryptographic provider for Lightweight Single Sign-On (LW-SSO).

When Service Manager is running in FIPS mode, the following rules apply for web services clients (integrations):

  • It is recommended to enable FIPS mode for the web service clients as well.
  • Web service clients that do not support FIPS mode can still integrate with SM through normal TLS connections.
  • LW-SSO will not work if the web service client does not support FIPS mode.

For more information about the support of FIPS mode for HPE products that can integrate with SM, see the documentation of the specific products. This document covers only SM components.

The steps to configure LW-SSO in SM for FIPS mode are the same as for non-FIPS mode, except the cryptographic provider configuration part. The steps are described in the following tasks:

Configure LW-SSO in the Server for FIPS mode

Configure LW-SSO in the Web tier for FIPS mode

Configure LW-SSO in the Mobility Client for FIPS mode

Configure LW-SSO in SRC for FIPS mode

Configure LW-SSO in the Chat Server for FIPS mode

Configure LW-SSO in the Chat Service for FIPS mode