Does your organization require the use of Federal Information Processing Standard (FIPS) 1402 compliant algorithms?
The SiteMinder implementation of the Advanced Encryption Standard (AES) supports the FIPS 1402 standard. FIPS is a US government computer security standard used to accredit cryptographic modules that meet the AES.
The Policy Server uses certified FIPS 1402 compliant cryptographic libraries. These cryptographic libraries provide a FIPS mode of operation when a SiteMinder environment only uses AEScompliant algorithms to encrypt sensitive data. A SiteMinder environment can operate in one of the following FIPS modes of operation.
Note: For more information about the cryptographic libraries SiteMinder uses and the AES algorithms used to encrypt sensitive data in FIPSonly mode, see the Policy Server Administration Guide. For more information about the FIPS modes of operation and which to use when installing the Policy Server, see the Policy Server Installation Guide.
If you are implementing AES encryption through FIPS-only mode, consider the following:
Note: For more information about your vendors ability to support the FIPS 1402 standard, see the vendor-specific documentation.
Important! An environment that is running in FIPSonly mode cannot operate with and is not backward compatible to earlier versions of SiteMinder. This requirement includes all agents, custom software using older versions of the Agent API, and custom software using PM APIs or any other API that the Policy Server exposes. Relink all such software with the r12.0 SP2 versions of the respective SDKs to achieve the required support for FIPSonly mode.
Copyright © 2010 CA. All rights reserved. | Email CA about this topic |