11.3 Configuring Sending Events in FIPS Mode

This section describes how to configure Sentinel integration when Sentinel, Secure Configuration Manager, or both are in FIPS mode.

11.3.1 When Sentinel is in FIPS Mode

For information about FIPS mode configuration in Sentinel, see the Sentinel Documentation.

By default, FIPS mode enabled Sentinel uses a NSS provider. To connect to the Secure Configuration Manager server, you need to add the Secure Configuration Manager server certificate to Sentinel's NSS truststore.

To add the Secure Configuration Manager server certificate to Sentinel's NSS truststore:

  1. Export the Secure Configuration Manager certificate to Sentinel NSS truststore from vtls.keystore using keytool.

  2. Import the Secure Configuration Manager certificate to FIPS mode enabled Sentinel.

11.3.2 When Secure Configuration Manager is in FIPS Mode

When Secure Configuration Manager is in FIPS mode, it uses a NSS provider. You need to import the Sentinel certificate to the Secure Configuration Manager NSS database.

To export a Sentinel Server certificate and import it to the Secure Configuration Manager Server:

  1. Export the Sentinel web server certificate.

  2. Import the certificate to the Secure Configuration Manager server.

11.3.3 When Both Secure Configuration Manager and Sentinel are in FIPS Mode

If Sentinel and Secure Configuration Manager are both in FIPS mode, each uses a NSS provider. You need to import each application’s certificate into the other application’s NSS Keystore.

To import the Secure Configuration Manager certificate to Sentinel:

  1. Export the certificate from the Secure Configuration Manager NSS Store.

  2. Enter Password or PIN for the NSS FIPS Certificate DB. You can also specify it in the nss/keystore/password field in the Advanced tab of the Core Services Configuration Utility.

  3. Import the certificate to the Sentinel server.

  4. Set the trust flags.

To import the Sentinel certificate to Secure Configuration Manager:

  1. Export the certificate from the Sentinel NSS Store.

  2. Import the certificate to Secure Configuration Manager.

  3. Set the certificate flag.