Use FIPS-Compliant Algorithms
Use the FIPS compliant algorithms for encryption, hashing and signing group policy to put the DirectControl agent into FIPS mode. In FIPS mode the agent uses only FIPS-approved cryptographic algorithms for encryption, hashing and signing in the Kerberos and NTLM authentication protocols.
Beginning with Release 2026 (6.3.0), an agent in FIPS mode uses the FIPS provider supplied by the operating system by default, rather than the FIPS provider shipped with DirectControl. Where the platform’s provider carries a FIPS 140-3 validation, DirectControl in FIPS mode operates under that validation.
FIPS 140-3 applies to the cryptographic module actually in use. It applies to a DirectControl deployment only where the agent is configured to use the operating system’s FIPS provider and that provider is itself FIPS 140-3 validated on the platform and version in question. Setting fips.provider.os to false selects the DirectControl FIPS provider instead, which is not 140-3 validated.
Basic Requirements
Delinea supports FIPS compliance with the following requirements and caveats:
-
FIPS mode is available only on specific UNIX and Linux platforms: Red Hat Enterprise Linux (x86_64), SUSE Linux Enterprise Server (x86_64 and aarch64), Ubuntu (x86_64), and AIX. Computers on other platforms ignore the policy.
-
On a computer where DirectControl does not support the operating system’s FIPS provider, set
fips.provider.osto false before the policy applies, so that the agent uses the DirectControl FIPS provider instead. -
Domain controllers must be at Windows Server 2008 domain functional level, or later.
-
The administrator must explicitly add the
centrifydc_fips.xmlor directly edit the administrative template to enable this policy.Delinea recommends that you use the
centrifydc_fips.xmltemplate. When you do, the agent performs several checks before implementing the policy to confirm that your domain controller and joined computers meet the requirements. -
If multiple encryption types are specified, only the AES128-CTS and AES256-CTS encryption type keys (with RSA for public key generation, SHA1, SHA256, SHA384 or SHA512 for hashing) are generated and saved to the keytab file. However, if arcfour-hmac-md5 encryption is specified, the MD4Hash of the machine password will be generated and saved to the keytab file.
Which encryption types are used in each joined computer is controlled by a parameter set in each Linux or UNIX computer’s configuration file. See the
adclient.krb5.permitted.encryption.typesdescription in the Notes section on Related Configuration Parameters for an explanation. -
Inter-realm keys for the AES128-CTS or AES256-CTS encryption types must be established between any trusted domains to enable Active Directory users to log on to a joined computer (see the
ksetuputility to set up inter-realm keys). -
FIPS mode only allows NTLM pass-through authentication over SChannel. FIPS mode is not available for NTLM authentication over SMB or SMB2.
-
In some environments, offline multi-factor authentication is not compatible with FIPS mode. See the Multi-factor Authentication Quick Start Guide for details about this restriction.
Enable the Policy
To enforce FIPS compliance, select the Computer Configuration > Policies> Centrify Settings > DirectControl Settings > Use FIPS compliant algorithms for encryption, hashing, and signing policy, open the properties, and select Enabled.
The policy takes effect after the next group policy update.
On each computer where DirectControl supports FIPS mode, the agent sets fips.mode.enable to true in /etlicc/centrifydc/centrifydc.conf and restarts. Computers on platforms where FIPS mode is not supported ignore the policy.
After a successful restart, the adjoin, adleave, and adinfo commands run in FIPS mode immediately.
There are several restrictions and rules governing the use of FIPS mode:
- Pre-validated groups and users that use FIPS mode to log on when disconnected must have each user’s Active Directory
msDSSupportedEncryptionTypesattribute set to use Kerberos AES 128- or 256-bit encryption. You can set this attribute in the users’ accounts using Active Directory Users and Computers or ADSI Edit. - The value of the corresponding Windows policy to use FIPS compliant algorithms has no effect on the Windows, Linux, UNIX, or Mac OS X computers managed through the Delinea Agent. You must use the Delinea policy to enable FIPS mode. The Delinea policy is only available when you add the
centrifydc_fips.xmlorcentrifydc_fips.admxtemplate (see Adding Delinea policies from XML files).
Verify FIPS Mode on a Managed Computer
Run adinfo with the --fips option to confirm that the agent is in FIPS mode:
$ adinfo --fips
Expected output:
FIPS Mode: Enabled
Which FIPS provider the agent uses is given by fips.provider.os in /etc/centrifydc/centrifydc.conf.
Related Configuration Parameters
The following centrifydc.conf configuration parameters affect FIPS operation. See the Configuration and Tuning Reference Guide for details about these parameters.
fips.mode.enable: Enable FIPS mode on a per-computer basis. This group policy modifies thefips.mode.enableparameter incentrifydc.conf.-
fips.provider.os: Determines which FIPS provider (module) is used when FIPS mode is enabled. Set it to true to use the FIPS provider supplied by the operating system, or false to use the DirectControl FIPS provider. When FIPS mode is disabled, the DirectControl FIPS provider is used and this parameter is ignored. (The default is true.) Changing the provider while FIPS mode is enabled requires a restart of adclient. -
fips.openssl.sync: Determines whether the OpenSSL configuration used by DirectControl is kept in step with FIPS mode. That is, it determines whether the FIPS OpenSSL configuration is selected when FIPS mode is enabled and the non-FIPS configuration when FIPS mode is disabled. Set to false to keep the behavior of earlier DirectControl versions, where the non-FIPS OpenSSL configuration is always selected. (The default is true.) After changing this parameter, restart adclient. adclient.krb5.clean.nonfips.enctypes: If FIPS mode is enabled and this configuration parameter is set totrue,adclientscans the computer’skeytabfile and removes all non-AES encryption keys for service principal names (SPNs) during startup. The default isfalse.adclient.krb5.permitted.encryption.types: If FIPS mode is enabled, and if you include thearcfour-hmac-md5encryption type in this configuration parameter, and ifadclient.krb5.clean.nonfips.enctypesistrue,adclientgenerates the MD4 hash for the computer password and saves it in the keytab file.
Upgrade a Deployment Already in FIPS Mode
The procedure described in this section is not needed for new installations, because they use the operating system's provider from the beginning.
When you upgrade an agent earlier than 6.3.0 on a computer where FIPS mode is already enabled, the parameter fips.provider.os is set to false. The computer continues to use the DirectControl FIPS provider, and its cryptographic behavior does not change across the upgrade.
To move such a computer onto the operating system’s provider, so it is under the provider's FIPS 140-3 validation, set the fips.provider.os parameter in /etc/centrifydc/centrifydc.conf to true:
fips.provider.os: true
Then restart the agent:
# /usr/share/centrifydc/bin/centrifydc restart