Network Management
Enable FIPS for compliance
This article covers how to Enable FIPS on the Solarwinds server.
First published date
Last published date
Overview
Product section
Resolution
To configure a FIPS-compliant SolarWinds installation:
- Configure the server on which you have installed your SolarWinds software for FIPS compliance. For more information on using FIPS compliant algorithms, refer to the Microsoft Support knowledge base (© 2019 Microsoft, available at https://support.microsoft.com, obtained on January 21, 2019).
- Start the SolarWinds FIPS 140-2 Manager (
SolarWinds.FipsManager.exe).
Note: By default,SolarWinds.FipsManager.exeis located inInstall_Volume:\Program Files (x86)\ - Review the welcome text, and then click Next.
- If you have configured your SolarWinds server to "use FIPS-compliant algorithms for encryption, hashing and signing", the SolarWinds FIPS 140-2 Manager will attempt to confirm that the current configuration of your SolarWinds products is FIPS-compliant.
- If any currently installed SolarWinds products are not FIPS compliant, the FIPS Manager will notify you of which SolarWinds modules are not FIPS-compliant. Click Close, and then remove any non-compliant SolarWinds modules from your FIPS-compliant server before running the FIPS 140-2 Manager again.
Note: SolarWinds recommends that you install all FIPS-compliant SolarWinds software on specifically FIPS-compliant servers and separately maintain all non-compliant software on specifically non-compliant servers. - If FIPS 140-2 is currently is disabled, check Enable FIPS 140-2, and then click Next.
- The FIPS Manager may provide a list of objects and saved network discovery definitions that are not FIPS-enabled.
Note: This list of non-compliant objects does not auto-refresh. To refresh the list of non-compliant objects after editing required credentials, restart the FIPS 140-2 Manager. - For each listed object that is not FIPS-compliant:
- Click the non-compliant object.
- If the non-compliant object is a monitored node, edit its Polling Method properties as follows:
- Select SNMPv3 as the SNMP Version.
- Select FIPS-compliant Authentication and Privacy/Encryption methods, and provide appropriate passwords.
Note: SHA1 is a FIPS-compliant authentication method. AES128, AES192, and AES256 are FIPS-compliant Privacy/encryption methods. - Click Submit.
- If the non-compliant object is a network discovery, edit SNMP credentials as follows:
- Confirm that all SNMP credentials are SNMPv3. Either delete or edit any credentials that are not VIPS-compliant SNMPv3.
- Confirm that all SNMP credentials use FIPS-compliant FIPS-compliant Authentication and Privacy/Encryption methods, and provide appropriate passwords.
Note: SHA1 is a FIPS-compliant authentication method. AES128, AES192, and AES256 are FIPS-compliant Privacy/encryption methods. - Complete the Network Sonar Wizard using the updated credentials.
- Each listed agent runs FIPS non-compliant version. Please update or remove it.
- If all monitored objects and network discoveries are FIPS-compliant, click Restart now to restart all relevant SolarWinds services.
Enabling FIPS manually using gpedit.msc
1. Click Start>Run. Then type the code below and press enter.
gpedit.msc
2. Go to Local Computer Policy>Computer Configuration>Windows Settings>Security Settings>Local Policies>Security Options>
3. Disable System Cryptography: Use FIPS Compliant algorithms for encryption