Skip to content

Enforcing FIPS mode for Distributed Issuer

Distributed Issuer is available as a FIPS-compliant container image. Once you've installed with a FIPS image, enable FIPS mode in the Next-Gen Trust Security (NGTS) user interface.

FIPS mode and certificate issuance

Setting FIPS mode controls the cryptography Distributed Issuer uses for its own operations, such as its TLS-served API endpoints. It doesn't restrict the algorithms Distributed Issuer uses to issue certificates. To remain FIPS-compliant, restrict non-compliant key types and signing algorithms in your NGTS issuance policy.

To set all Distributed Issuer instances to FIPS mode in NGTS:

  1. Sign in to NGTS.
  2. Click Configurations > Certificate Configurations > Issuer Configurations, and select an issuer configuration.
  3. In the side panel, select Require Issuer instances to be FIPS compliant.