Use this page to view the FIPS compliance status and module details for selected client systems in the System Tree.
Option / UI label | Possible Values |
|---|---|
Overall FIPS Modules' Status | OK / Failed / Unknown / Not Applicable |
TCC AES 32-bit Version | Trellix Core Cryptographic AES Module - 6.0.0 / Not reported |
TCC AES 32-bit Status | OK / Failed / Not reported |
TCC AES 64-bit Version | Trellix Core Cryptographic AES Module - 6.0.0 / Not reported |
TCC AES 64-bit Status | OK / Failed / Not reported |
WolfCrypt 32-bit Version | WolfCrypt v5.2.3 / Not reported |
WolfCrypt 32-bit Status | Normal / Degraded / Failed / Not reported |
WolfCrypt 64-bit Version | WolfCrypt v5.2.3 / Not reported |
WolfCrypt 64-bit Status | Normal / Degraded / Failed / Not reported |
Values definitions:
Failed - The module failed its integrity check due to one of the following:
TCC AES: The IntegrityStatus registry value is anything other than "Passed", or the value is missing or inaccessible.
WolfCrypt: STATUS registry DWORD is non-zero (error code), or MODE is 0 (still initializing) or 3 (critical failure).
Overall Status: Any individual module is in Failed or Degraded state.
Degraded - Applies to WolfCrypt only. The module is running but in a reduced-capability mode. FIPS-approved algorithms remain functional, but non-approved fallbacks might be active. Occurs when WolfCrypt MODE = 2. Although this represents a partial-pass state, it is reported as Failed in FipsOverallStatus.
Unknown - Applies to overall status only. FIPS mode is enabled on the system but no module data could be collected at all. Emitted as a fallback by FfSystemScanner.cpp when collection fails entirely.
Not reported - The module's data was absent from the status/version map, indicating the client did not locate the module on the system (for example, the registry key for the module prefix was missing). Used as a fallback string in FfFipsCryptoStatusFetcher.cpp for both version and status fields.
Not Applicable - This value is not reported by the client. It is a server-side display fallback in FRPSystemDa.java. It appears when FipsOverallStatus is null or empty, indicating that the client never reported the property (for example, FIPS mode is disabled or the endpoint has not reported FIPS data).