Features disabled in the FIPS distribution
The following capabilities are unavailable in the FIPS distribution. They’re disabled in the product and cannot be re-enabled through licensing, feature flags, or configuration.
Ensure that your operational processes do not depend on these capabilities.
Feature | Reason it is disabled |
|---|---|
Network scans | Scanning stack cannot be constrained to validated cryptography. |
Cloud scans | Depends on external scanning services outside the authorization boundary. |
Custom plugins | Allows loading code that isn’t covered by the product's validated build. |
Agent automation post-processing scripts | Arbitrary script execution on managed endpoints isn’t permitted. |
Script management | Same rationale as post-processing scripts. |
Docker-based sensor | Sensor variant cannot meet the validated cryptography requirement. |
DigiCert PKI Platform 8 | Legacy connector that cannot meet FedRAMP cryptographic requirements. |
Note
If a user reports that one of these features is missing, that is expected behavior in a FedRAMP deployment and not a defect.