cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
markgarza
Level 10
Report Inappropriate Content
Message 1 of 2

Management of Native Encryption on Mac shows FIPS disabled

Hi, we use MNE to report on encryption status for Mac mobile devices. We have not been using it to enforce encryption since we can never seem to get it to work, so we manually encrypt the machine with Filevault and install MNE in a report only mode.

I am noticing as I've had to reload a couple machines that they are reporting to EPO as FIPS mode being disabled. In the past, when I've turned on Filevault manually and installed MNE to report on status, FIPS mode is shown as enabled. There is nothing different between my process for turning on Filevault now than there was before, just the manual way through the Security and Privacy settings on the Mac, but now a few machines have been reloaded and FIPS is shown as disabled. 

I am not aware of any particular steps or options within the Filevault encrypting process that allows me to "choose" FIPS mode, and Macs that have existed in EPO and have not been reloaded still show their FIPS mode as enabled. 

Where does MNE get this FIPS information from on the Mac? Does anyone know of a way to "enable" FIPS mode on a Mac so MNE can report it as enabled?

1 Reply
avinashraghu
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: Management of Native Encryption on Mac shows FIPS disabled

Hello Mark,

 

Sorry to hear that Filevault is not getting activated with MNE. May i know what is the error message?

MNE checks the client systems for FIPS certification and reports whether the client systems are running in FIPS mode or not. For this to happen, 

-Make sure that the OS is running in FIPS mode. For Mac systems, install the FIPS Administration tools (http://support.apple.com/kb/HT5396).

-Send an agent wake-up call.

MNE will automatically report the FIPS status back to McAfee ePO.

NOTE: For Mountain Lion 10.8.4 or above Mac systems, the FIPS status is reported automatically to McAfee ePO by MNE, and the user does not have to install the FIPS Administration tools.

Also in MNE policy-> Security Posture Report Settings policy, check the status of Security posture reporting.

 

Thank you,

Avinash Raghunathan

Data Protection

 

 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community