<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ONTAP 9.3P15: Enabling FIPS Mode in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153584#M34354</link>
    <description>&lt;P&gt;Hi there!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This page shows the output of "security config show" when FIPS is enabled -&amp;nbsp;&lt;A href="https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-950%2Fsecurity__config__show.html" target="_blank"&gt;https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-950%2Fsecurity__config__show.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which includes the line you suspected it would show, as well as showing tls1.1 is enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="pre screen" space="preserve"&gt;ALL:!LOW:!aNULL:!EXP:!eNULL:!RC4&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;Hope this helps!&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jan 2020 02:42:30 GMT</pubDate>
    <dc:creator>AlexDawson</dc:creator>
    <dc:date>2020-01-17T02:42:30Z</dc:date>
    <item>
      <title>ONTAP 9.3P15: Enabling FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153565#M34348</link>
      <description>&lt;P&gt;Has anyone enabled FIPS mode? We have several FAS 8060 nodes in a cluster with ONTAP 9.3P15 and we are looking to enable FIPS mode.&lt;/P&gt;
&lt;P&gt;I am looking at this document:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-nmg%2FGUID-A799B86D-B1B5-4AB6-B610-D0651D7C1548.html" target="_blank"&gt;https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-nmg%2FGUID-A799B86D-B1B5-4AB6-B610-D0651D7C1548.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if I run and reboot:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color: #333333; color: #ffffff; font-family: Menlo, Monaco, Consolas, 'Courier New', monospace; font-size: 14.4px;"&gt;security config modify -interface SSL -is-fips-enabled true&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the security config looks like this?&lt;/P&gt;
&lt;DIV class="body taskbody"&gt;
&lt;DIV id="GUID-A799B86D-B1B5-4AB6-B610-D0651D7C1548__GUID-03F8085D-6BC5-47E4-93BF-5BC30B222F4B" class="section context"&gt;
&lt;UL id="GUID-A799B86D-B1B5-4AB6-B610-D0651D7C1548__UL_F20D03846B1044019CD848F51F3DC64E" class="ul"&gt;
&lt;LI id="GUID-A799B86D-B1B5-4AB6-B610-D0651D7C1548__LI_B86EE41BF03A4E6CA46296A97083B73A" class="li"&gt;FIPS: &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI id="GUID-A799B86D-B1B5-4AB6-B610-D0651D7C1548__LI_4001632DBEA04441809AF57B3571BC33" class="li"&gt;&lt;SPAN class="div_linebreak"&gt;&lt;KBD class="ph userinput"&gt;SSL protocol = {TLSv1.2}&lt;/KBD&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI id="GUID-A799B86D-B1B5-4AB6-B610-D0651D7C1548__LI_5F06071593714E8FA3C0DD07B9D8F876" class="li"&gt;&lt;SPAN class="div_linebreak"&gt;&lt;KBD class="ph userinput"&gt; SSL ciphers = {ALL:!LOW:!aNULL:!EXP:!eNULL:!RC4}&lt;/KBD&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="div_linebreak"&gt;Any issue anyone experience?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="div_linebreak"&gt;What if we need TLS v1.1?&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 16 Jan 2020 12:41:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153565#M34348</guid>
      <dc:creator>duanebachi</dc:creator>
      <dc:date>2020-01-16T12:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP 9.3P15: Enabling FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153584#M34354</link>
      <description>&lt;P&gt;Hi there!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This page shows the output of "security config show" when FIPS is enabled -&amp;nbsp;&lt;A href="https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-950%2Fsecurity__config__show.html" target="_blank"&gt;https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-950%2Fsecurity__config__show.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which includes the line you suspected it would show, as well as showing tls1.1 is enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="pre screen" space="preserve"&gt;ALL:!LOW:!aNULL:!EXP:!eNULL:!RC4&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 02:42:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153584#M34354</guid>
      <dc:creator>AlexDawson</dc:creator>
      <dc:date>2020-01-17T02:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP 9.3P15: Enabling FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153598#M34357</link>
      <description>&lt;P&gt;Hi Alex,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your reply. That page you showed me is for 9.5 and also that is the default when FIPS is disabled. One of the things I need to know is that if I enable FIPS, does it only allow TLS1.2? Will it let me add TLS 1.1 or would that invalidate FIPS?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 12:46:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153598#M34357</guid>
      <dc:creator>duanebachi</dc:creator>
      <dc:date>2020-01-17T12:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP 9.3P15: Enabling FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153687#M34390</link>
      <description>&lt;P&gt;Hi there! The page for 9.3 is the same -&amp;nbsp;&lt;A href="https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-930%2Fsecurity__config__show.html" target="_blank" rel="noopener"&gt;https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-930%2Fsecurity__config__show.html&amp;nbsp;&lt;/A&gt;- which includes showing TLS 1.1 is enabled with FIPS mode on, so you won't need to change anything.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2020 02:56:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/153687#M34390</guid>
      <dc:creator>AlexDawson</dc:creator>
      <dc:date>2020-01-22T02:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP 9.3P15: Enabling FIPS Mode</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/460350#M44922</link>
      <description>&lt;P&gt;This document states that for ONTAP versions prior to 9.11.1, if the FIPS 140-2 compliance mode is enabled, both TLSv1 and SSLv3 will be disabled, while only TLSv1.1 and TLSv1.2 will remain enabled. However, TLSv1.1 has been regarded as an insecure protocol&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap-technical-reports/ontap-security-hardening/tls-ssl.html" target="_blank"&gt;FIPS mode and TLS and SSL management in ONTAP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_to_harden_ONTAP_9_TLS_configuration" target="_blank"&gt;How to harden ONTAP 9 TLS configuration - NetApp Knowledge Base&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Apr 2025 09:05:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-9-3P15-Enabling-FIPS-Mode/m-p/460350#M44922</guid>
      <dc:creator>liu</dc:creator>
      <dc:date>2025-04-27T09:05:54Z</dc:date>
    </item>
  </channel>
</rss>

