View Single Post
  #1  
Old 11-02-2020, 11:28 AM
bgagnon bgagnon is offline
VanDyke Technical Support
 
Join Date: Oct 2008
Posts: 4,633
Question Why does VShell log “Not accepting FTPS connections because VShell FIPS mode is on"

On the Windows platform, VShell’s FTPS/HTTPS implementation utilizes the SChannel crypto library native to the Windows Operating system.

Although FIPS mode may be enabled in VShell (and active for SSH/SFTP connections)…

… FTPS/HTTPS functionality will not be allowed unless FIPS mode is also enabled in Windows.

If FIPS mode is enabled in VShell but not enabled at the operating system level within Windows, VShell’s FTPS/HTTPS logs will display a warning: Not accepting FTPS (HTTPS) connections because VShell FIPS mode is on. For example:


An inspection of your Windows system’s local security policy will likely reveal that in the Security Options section of your Windows machine’s Local Policies, the System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing option is currently Disabled.



To enable FIPS mode for Windows/SChannel, a Windows system admin must edit the Local Security Policy on the Windows machine where VShell is installed and enable the System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing security option.

To summarize, if FIPS mode has been enabled in VShell via an ADM template…

…and the system level configuration has been made:
Then the warn category message in VShell’s FTPS/HTTPS log file becomes an info category message that reads: VShell FIPS mode is enabled and the Microsoft SChannel setting for FIPS is on.
Attached Images
File Type: jpg 01_vshellCP_w_FIPS_on.jpg (111.4 KB, 657 views)
File Type: jpg 02_vshell_log_before.jpg (123.0 KB, 596 views)
File Type: jpg 03_sys_SChannel_disabled.jpg (99.3 KB, 644 views)
File Type: jpg 04_vshell_FIPS_on_ADM_torn.jpg (103.2 KB, 799 views)
File Type: jpg 05_vshell_log_after_sys_FIPS_enabled_torn.jpg (295.6 KB, 671 views)
__________________
Thanks,
--Brenda

VanDyke Software
Technical Support
support@vandyke.com
(505) 332-5730