Kaseya FIPS Edge Service

The Kaseya FIPS Edge Service is a new component introduced in VSA 9.5.27 that handles Transport Layer Security (TLS) termination and Federal Information Processing Standard (FIPS) 140-3 compliant cryptographic operations. It replaces the TLS termination role previously performed by the VSA Edge Service, helping you meet modern security and compliance requirements.

Key capabilities

  • FIPS 140-3 cryptographic operations: Performs all TLS and cryptographic operations using OpenSSL with a SafeLogic FIPS 140-3 compliant module.
  • TLS termination: Handles all inbound TLS connections in place of the existing VSA Edge Service.
  • IPv4 and IPv6 support: Accepts connections over both IPv4 and IPv6 networks.
  • Automated certificate validation and repackaging: Detects non-FIPS-compliant certificate packages during installation and offers in-place remediation using FIPS-approved algorithms.
  • Dedicated logging: Provides a separate logging framework to simplify FIPS compliance validation and troubleshooting.
  • Enhanced agent security: Extends FIPS-enabled cryptographic operations to agent communications, with automatic cipher and certificate migration during upgrade.

How it works

The Kaseya FIPS Edge Service sits in front of the existing VSA Edge Service and intercepts all TLS traffic. When a connection arrives, the FIPS Edge Service performs TLS termination using its FIPS 140-3 validated OpenSSL module, then forwards the decrypted traffic to the VSA Edge Service for standard processing. Configuration settings previously managed by the VSA Edge Service — including listening port management, TLS configuration, FIPS configuration settings, and IP filtering — are now owned by the FIPS Edge Service and stored in a dedicated configuration file.

NOTE  After upgrading to VSA 9.5.27, any SSL certificate changes require a restart of the FIPS Edge Service rather than the traditional Edge Service.