Previous Topic: FIPS 140-2 Overview

Next Topic: How to Configure CA EEM Server in FIPS-only Mode

Supported Security Modes in CA EEM

CA EEM supports two modes of operation: non-FIPS and FIPS-only. The functionality of CA EEM is the same in both these modes. The difference in these two modes is in the cryptographic algorithms used for storage and verification of passwords, and the communication of sensitive data between CA EEM and other products such as LDAP directories, CA SiteMinder, and so on.

non-FIPS

Refers to the mode that uses non-FIPS compliant techniques for cryptography. In this mode MD5 is the default algorithm used to encrypt and decrypt sensitive data. Fresh installations or upgrades are always run in a non-FIPS mode. In non-FIPS mode, the CA EEM Server is backward compatible with the CA EEM clients. For example, you can use the CA EEM r8.4 SDK to connect to a CA EEM r8.4 SP3 server.

FIPS-only

Refers to the mode that uses only FIPS-compliant techniques for cryptography. This mode is not compatible with clients running in non-FIPS mode. You can use only CA EEM r8.4 SP3 SDK FIPS-only clients with CA EEM r8.4 SP3 servers running in FIPS-only mode.