In the Workbench : FIPS Mode vs. Non-FIPS Mode

In some cases, it may be necessary to run Workbench in non-FIPS mode, even if Workbench is licensed for FIPS.

This may be necessary if:

  • You are connecting to a non-FIPS station, with a non-FIPS compliant password.

    In this situation, the connection fails due to a non-FIPS strength password and the Authentication window displays a FIPS error message:

    Figure 1.   Non-FIPS strength password invokes Authentication error message
    Image

    To proceed, you need to connect using a non-FIPS client (i.e. a non-FIPS instance of Workbench or other non-FIPS station), or contact your administrator, or log in as a different user (one with a FIPS-compliant password.

  • You are connecting to a factory JACE that is still using the default, non-FIPS compliant password.

    In this case, the Change Platform Defaults Wizard displays, which includes a step to indicate whether the remote platform will be licensed for FIPS. If so, the wizard enforces the FIPS strength password requirement.

There are two ways to start Workbench in non-FIPS mode when licensed for FIPS. Use either of the following methods as needed.

  • When running in FIPS mode, select File > Non-FIPS Restart.

    This closes your current Workbench and restarts it in non-FIPS mode.

    Note that when Workbench is running in non-FIPS mode and licensed for FIPS, there is a corresponding File > FIPS Restart command. This method is useful when you only need to run in non-FIPS mode once.

  • In Tools > Options > FIPS Options, set the Start Workbench In Non-FIPS Mode By Default to true.

    This causes Workbench to run in non-FIPS mode every time you start it. You will need to restart Workbench for this to take effect. This method is useful when you need to run in non-FIPS mode most of the time.