We've updated the ServiceNow Community Code of Conduct, adding guidelines around AI usage, professionalism, and content violations. Read more

Discovery of FIPS‑enabled servers

Mercedes Pons 1
Tera Contributor

I would appreciate some guidance with Discovery configuration in the MIDServer to run Discovery on FIPS‑enabled Linux servers.  

I've created the SSH Key credential, and I've tested several options of mid.ssh.algorithms.host_key property in the MidServer, but nothing seems to work.  I've been told that the Server doesn't see the attempt by ecdsa-sha2-nistp384 private key, but the log shows the attempt from another SSH Key we use (not FIPS).  

I'm using "Quick Discovery" for the specific IPs 

 

If the property is setup to:  +ssh-rsa,ecdsa-sha2-nistp384

FIPs doesn't work, but our regular SSH Key works

 

If the property is setup to: +ssh-rsa,+ecdsa-sha2-nistp384

then I get an error for both FIPS and regular SSH.

 

I've tried different variations, but I don't seem to make it work.   Any experience with this kind of Discovery?

 

Our MIDServers are not FIPS enabled, and I want to keep it that way, as this is just for 3 or 4 Linux Servers we just added to our environment.

 

Thank you

 

0 REPLIES 0