22.3 Enabling FIPS 140-2 Mode on Remote Collector Managers and Correlation Engines

You must enable FIPS 140-2 mode on the remote Collector Manager and Correlation Engine if you want to use FIPS-approved communications with the Sentinel server running in FIPS 140-2 mode.

To enable a remote Collector Manager or Correlation Engine to run in FIPS 140-2 mode:

  1. Navigate to <sentinel_installation_path>/opt/novell/sentinel/3rdparty/opensearch/config/certs/in the Sentinel server.

  2. Copy node.pem, client.pem, root-ca.pem and admin.pemcertificate files to all the RCMs.

  3. Login to the remote Collector Manager or Correlation Engine system.

  4. Switch to novell user:

    su novell 
  5. Navigate to the bin directory. The default location is /opt/novell/sentinel/bin.

  6. Run the convert_to_fips.sh script and follow the on-screen instructions.

    Provide the path of the OpenSearch certificates, when prompted for the external certificate, as <path of the certificate copied above>/<certificate_name>.pem.

    Where <certificate_name> has following values:

    • root-ca

    • admin

    • node

    • client

    NOTE:For each external certificate prompt, add the above certificates one by one, with the respective path.

    For example:

    <path of the certificate copied above>/root-ca.pem

    Provide a unique alias name for this certificate when prompted. Repeat the step to add all the four certificates one by one and provide unique alias name to each of them when prompted.

  7. Restart the Collector Manager or Correlation Engine.

  8. Complete the FIPS 140-2 mode configuration by following the tasks mentioned in Section 23.0, Operating Sentinel in FIPS 140-2 Mode.