You can configure Kerberos to run in FIPS 140-2 mode in Oracle Solaris. If your realm contains legacy applications or systems that are not FIPS 140-2-compliant, then the realm cannot run in FIPS 140-2 mode.
When running in FIPS 140-2 mode, Kerberos is said to be a consumer of the FIPS 140-2 provider. The provider in Oracle Solaris is the OpenSSL FIPS 140-2 provider. For instructions, see How to Configure Kerberos to Run in FIPS 140-2 Mode and Using a FIPS 140-2 Enabled System in Oracle Solaris 11.3.