And just to add to the fun, some of the certificates may refuse to import because of non-FIPS algorithms.
Charles On Fri, 26 Apr 2024 11:26:20 -0500, Charles Mills <[email protected]> wrote: >That is my *impression*, that there is no easier way. > >CM > >On Thu, 25 Apr 2024 07:36:54 -0400, Mark Regan <[email protected]> wrote: > >>At a site I support we need to start using FIPS mode. At the present our >>certificates are in gskkyman database that was not set up to support FIPS. >>From what I understand we have to export the certificates from the non-FIPS >>database and then import them into a new FIPS one. Since we have many >>certificates is there a simpler way of doing this? > >---------------------------------------------------------------------- >For IBM-MAIN subscribe / signoff / archive access instructions, >send email to [email protected] with the message: INFO IBM-MAIN ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO IBM-MAIN
