2.4 Understanding FIPS 140-2 Implementation

NetIQ security products support Federal Information Processing Standard (FIPS) 140-2 communication among the product components. You can configure the UNIX Agent manager, Security Agent for UNIX, and the NetIQ security products (Sentinel, Change Guardian, and Secure Configuration Manager) to enable all communications to FIPS 140-2 validated cryptographic modules. When you configure them to use only these communication algorithms, the servers cannot fully communicate with any Agent that does not use these algorithms.

The Security Agent for UNIX uses OpenSSL libraries for its internal encryption and other functions. OpenSSL is a FIPS 140-2 validated cryptographic provider. The purpose of doing so is to ensure that the Agent is in FIPS mode and is compliant with United States federal purchasing policies and standards.

UNIX Agent Manager uses Mozilla NSS libraries and Java SSL libraries for creating the listener on port 2222 and OpenSSL libraries for communicating with Agents. For UNIX Agent Manager, we ship our own copies of the Mozilla NSS libraries. Red Hat Enterprise Linux (RHEL) and SUSE Linux Enterprise Server (SLES) have a different set of NSS packages. The NSS cryptographic module provided by RHEL and SLES are FIPS 140-2 validated.

IMPORTANT:If you deploy the Agent in FIPS mode, you must deploy the NetIQ security products in FIPS mode. If not, you can deploy all the components in non-FIPS mode.

2.4.1 Installation Options

The following are different ways in which you can implement FIPS 140-2:

NOTE:If you have converted the Agent to FIPS mode, you cannot revert back to non-FIPS mode.

Tasks

For more information, see…

Local installation: To enable the Agent in FIPS 140-2 mode during local installation

Local installation

Remote installation: To enable the Agent in FIPS 140-2 mode during remote installation

Remote installation

2.4.2 FIPS-Enabled Components

The following components provide FIPS 140-2 support:

  • Sentinel Server 7.4 and later

  • Change Guardian Server 4.2.1

  • Secure Configuration Manager Core 6.1 and later

  • Sentinel Security Agent for UNIX 7.5

  • Change Guardian Security Agent for UNIX 7.5

  • Secure Configuration Manager Security Agent for UNIX 7.5

  • UNIX Agent Manager 7.5

  • Sentinel Agent Manager Connector 2011.1r5