Supportability of disabling Federal Information Processing Standards (FIPS) in vSphere Supervisor
search cancel

Supportability of disabling Federal Information Processing Standards (FIPS) in vSphere Supervisor

book

Article ID: 434333

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service

Issue/Introduction

Information regarding the supportability and potential impact of disabling Federal Information Processing Standards (FIPS) on a vSphere Supervisor.

Environment

VMware vSphere Kubernetes Service

Resolution

  • Disabling FIPS on a vSphere Supervisor is not natively supported. No API or recommended method exists for this operation. The impact of disabling FIPS at the guest OS layer of the Supervisor VMs is completely untested.

  • The vSphere Supervisor and vCenter Server communicate over TLS. As long as a compatible set of ciphers can be negotiated between the client and server, communication will succeed. Neither the client nor the server verifies the other's FIPS compliance. FIPS enforcement does not extend beyond the boundary of a single machine unless an explicitly incompatible algorithm (such as MD5) is required, which a FIPS-enabled machine will reject.

  • To request official support for disabling FIPS in the vSphere Supervisor, a feature request must be submitted. For instructions on how to submit a request for new functionality, see Submit a VMware by Broadcom feature request.

Additional Information