v5.0.4: FIPS compliant

If you are having a problem using Vault, post a message here.

Moderator: SourceGear

Post Reply
kha
Posts: 221
Joined: Fri Sep 12, 2008 8:25 am

v5.0.4: FIPS compliant

Post by kha » Tue Oct 26, 2010 2:51 pm

Here is the scenario:
1) Hosting server is windows 2008, before turning any FIPS compliant option on, i have SourceGear Vault web works fine.
2) I have to turn on the FIPS complaint because it's required by the security procedure from client

There are 2 FIPS complaint options that we need to enable:
1) Local Security Policy -> Security Options -> System cryptopraphy: Use FIPS compliant algorithms for encryption, hashing, and signing
2) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\fipsalgorithmpolicy registry subkey is set to 1

Before enabling any of the two FIPS options above, I got Vault web worked perfectly fine. But as I enabled either or both FIPS option(s), going to vault web, I got error "Unable to validate data". Once i disabled the FIPS complaint option, it works again.

My questions:
1) Is there anyway to get Vault work with the FIPS complaint enabled? It has something to do with FIPS enabled, I know if I turn it off, i will have Vault works fine, but i have to turn it on as part of security requirement for the server.
2) If not, is there any work around?

lbauer
Posts: 9736
Joined: Tue Dec 16, 2003 1:25 pm
Location: SourceGear

Re: v5.0.4: FIPS compliant

Post by lbauer » Wed Oct 27, 2010 7:29 am

Vault is not currently FIPS compliant. We do hope to add this functionality to a future release. We're not aware of any workaround at this time, sorry.

feat 13145
Linda Bauer
SourceGear
Technical Support Manager

Post Reply