Skip to main content

Features disabled in the FIPS distribution

The following capabilities are unavailable in the FIPS distribution. They’re disabled in the product and cannot be re-enabled through licensing, feature flags, or configuration.

Ensure that your operational processes do not depend on these capabilities.

Feature

Reason it is disabled

Network scans

Scanning stack cannot be constrained to validated cryptography.

Cloud scans

Depends on external scanning services outside the authorization boundary.

Custom plugins

Allows loading code that isn’t covered by the product's validated build.

Agent automation post-processing scripts

Arbitrary script execution on managed endpoints isn’t permitted.

Script management

Same rationale as post-processing scripts.

Docker-based sensor

Sensor variant cannot meet the validated cryptography requirement.

DigiCert PKI Platform 8

Legacy connector that cannot meet FedRAMP cryptographic requirements.

Note

If a user reports that one of these features is missing, that is expected behavior in a FedRAMP deployment and not a defect.