Welcome to the VanDyke Software Forums

Join the discussion today!


Go Back   VanDyke Software Forums > General

Notices

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 11-02-2020, 10:28 AM
bgagnon bgagnon is offline
VanDyke Technical Support
 
Join Date: Oct 2008
Posts: 4,636
Question Why does VShell log “Not accepting FTPS connections because VShell FIPS mode is on"

On the Windows platform, VShell’s FTPS/HTTPS implementation utilizes the SChannel crypto library native to the Windows Operating system.

Although FIPS mode may be enabled in VShell (and active for SSH/SFTP connections)…

… FTPS/HTTPS functionality will not be allowed unless FIPS mode is also enabled in Windows.

If FIPS mode is enabled in VShell but not enabled at the operating system level within Windows, VShell’s FTPS/HTTPS logs will display a warning: Not accepting FTPS (HTTPS) connections because VShell FIPS mode is on. For example:


An inspection of your Windows system’s local security policy will likely reveal that in the Security Options section of your Windows machine’s Local Policies, the System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing option is currently Disabled.



To enable FIPS mode for Windows/SChannel, a Windows system admin must edit the Local Security Policy on the Windows machine where VShell is installed and enable the System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing security option.

To summarize, if FIPS mode has been enabled in VShell via an ADM template…

…and the system level configuration has been made:
Then the warn category message in VShell’s FTPS/HTTPS log file becomes an info category message that reads: VShell FIPS mode is enabled and the Microsoft SChannel setting for FIPS is on.
Attached Images
File Type: jpg 01_vshellCP_w_FIPS_on.jpg (111.4 KB, 5397 views)
File Type: jpg 02_vshell_log_before.jpg (123.0 KB, 5381 views)
File Type: jpg 03_sys_SChannel_disabled.jpg (99.3 KB, 5409 views)
File Type: jpg 04_vshell_FIPS_on_ADM_torn.jpg (103.2 KB, 5565 views)
File Type: jpg 05_vshell_log_after_sys_FIPS_enabled_torn.jpg (295.6 KB, 5467 views)
__________________
Thanks,
--Brenda

VanDyke Software
Technical Support
support@vandyke.com
(505) 332-5730
Closed Thread

Tags
error , fips mode , ftp , ftp/s , ftp/ssl , ftp/tls , ftps , http , https

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 06:20 AM.