Enforcing FIPS mode for Distributed Issuer¶
Distributed Issuer is available as a FIPS-compliant container image. Once you've installed with a FIPS image, enable FIPS mode in the Next-Gen Trust Security (NGTS) user interface.
FIPS mode and certificate issuance
Setting FIPS mode controls the cryptography Distributed Issuer uses for its own operations, such as its TLS-served API endpoints. It doesn't restrict the algorithms Distributed Issuer uses to issue certificates. To remain FIPS-compliant, restrict non-compliant key types and signing algorithms in your NGTS issuance policy.
To set all Distributed Issuer instances to FIPS mode in NGTS:
- Sign in to NGTS.
- Click Configurations > Certificate Configurations > Issuer Configurations, and select an issuer configuration.
- In the side panel, select Require Issuer instances to be FIPS compliant.