Dell Unity: Enabling and Disabling FIPS on Unity Systems

Summary: This article explains how to enable or disable Federal Information Processing Standards (FIPS) mode on Dell Unity storage systems.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

Management support for FIPS 140-2

Federal Information Processing Standard 140-2 (FIPS 140-2) is a standard that describes US Federal government requirements that IT products should meet for Sensitive, but Unclassified (SBU) use. The standard defines the security requirements that must be satisfied by a cryptographic module used in a security system protecting unclassified information within IT systems. To learn more about FIPS 140-2, refer to FIPS 1402-2 publication (external link).


The storage system supports FIPS 140-2 mode for the SSL modules that handle client management traffic. Management communication into and out of the system is encrypted using SSL. As a part of this process, the client and the storage management software negotiate a cipher suite to use in the exchange. Enabling FIPS 140-2 mode restricts the negotiable set of cipher suites to only those that are listed in the FIPS 140-2 Approved Security Functions publication. If FIPS 140-2 mode is enabled, you may find that some of your existing clients can no longer communicate with the management ports of the system if they do not support FIPS 140-2 Approved cipher suites. FIPS 140-2 mode cannot be enabled on a storage system when non-FIPS-compliant certificates exist in the certificate store. You must remove all non-FIPS compliant certificates from the storage system before you enable the FIPS 140-2 mode.


Managing FIPS 140-2 mode on the storage system

Only the Administrator and Security Administrator have the privileges to manage the FIPS 140-2 mode setting. Use the following CLI command to set the FIPS 140-2 mode setting on a storage system:

uemcli /sys/security set -fips140Enabled yes will set it to FIPS 140-2 mode.

uemcli /sys/security set -fips140Enabled no will set it to non-FIPS 140-2 mode.

 

Use the following CLI command to determine the current FIPS 140-2 mode for the storage system:

uemcli /sys/security show

 

When you change the FIPS 140-2 mode setting on a storage system, both Storage Processors (SP) are automatically rebooted in sequence in order to apply the new setting. When the first SP has completed rebooting, the other SP is rebooted. The system will only operate fully in the configured FIPS 140-2 mode after both SPs have completed rebooting. 

Additional Information

For more information about FIPS 140-2, refer to the following documents:

  1. FIPS 140-2 publication (external link)
  2. Dell Unity™ Family Security Configuration Guide

If STIG must be enabled on a FIPS-compliant system; disable FIPS, enable STIG, and enable FIPS again. Refer to Dell Unity: How To Enable Hardening (STIG) (User correctable) 

Affected Products

Dell EMC Unity, Dell Command | Configure, Dell EMC Unity Family |Dell EMC Unity All Flash, Dell EMC Unity Hybrid
Article Properties
Article Number: 000458572
Article Type: How To
Last Modified: 04 مايو 2026
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.