如何在 Windows 7 上启用 FIPS
必须从客户端测试要在已启用 FIPS 的计算机上运行的 ac# 应用程序
Have to test a c# application from client that is to work on a machine that has FIPS enbaled
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
首先,请了解在 Windows 中实施 FIPS140-2 兼容加密时实际发生的情况。详细信息请访问http://technet.microsoft.com/en-us/library/cc750357.aspx。然而,主要的“陷阱”(旧的 SSL 网站不再在 IE 中运行)在下面链接的文章中有详细介绍。
启用 FIPS 140-2 合规性的官方说明位于 http://support.microsoft.com/kb/811833,但可以概括如下:
节点,双击Windows 设置,然后双击安全
设置。
然后点击安全选项。
符合 FIPS 的加密、散列和签名算法。
加密、散列和签名对话框,单击启用,然后
单击确定关闭对话框。
如果您希望手动执行此操作,也可以简单地将注册表项
HKLM\System\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy\Enabled
更改为 1最后,重复一遍,这非常重要 在启用此功能之前,请通读文档 - 它会更改整个加密系统,包括如何允许文件系统(EFS 和 Bitlocker)和网络(IE、远程桌面和主要加密库)加密,以及您是否允许恢复丢失的加密密钥。
First, be aware of what actually happens when you enforce FIPS140-2 complient encryption within Windows. Details are at http://technet.microsoft.com/en-us/library/cc750357.aspx. However, the main 'gotcha' (old SSL website's don't work in IE anymore) is detailed in the article linked below.
The official instructions to enable FIPS 140-2 complience are at http://support.microsoft.com/kb/811833, but can be summarised as follows:
node, double-click Windows Settings, and then double-click Security
Settings.
then click Security Options.
FIPS-compliant algorithms for encryption, hashing, and signing.
encryption, hashing, and signing dialog box, click Enabled, and then
click OK to close the dialog box.
If you wish to do this manually, you can also simply change the registry key
HKLM\System\CurrentControlSet\Control\Lsa\FIPSAlgorithmPolicy\Enabled
to 1Finally, to repeat, it is very important that you read through the documentation before you enable this - it changes cryptography system wide, including how the file system (both EFS and Bitlocker) and network (IE, Remote Desktop and the main cryptographic libraries) are allowed to encrypt, as well as if you allowed to recover lost encryption keys.
作为替代方案,对于 Windows 7 用户(具有管理员权限),这是“网络属性”之一。步骤:
另外,请记住:
As an alternative, for Windows 7 users (with admin rights), this is one of the "Network Properties". Step by step:
Also, have in mind: