2.5 Understanding FIPS 140-2 Implementation

NetIQ security products support Federal Information Processing Standard (FIPS) 140-2 communication among the product components. You can configure the UAM, Security Agent for UNIX, and the NetIQ security products (Sentinel, Change Guardian, and Secure Configuration Manager) to enable all communications to FIPS 140-2 validated cryptographic modules. When you configure them to use only these communication algorithms, the servers cannot fully communicate with any Agent that does not use these algorithms.

The Security Agent for UNIX uses OpenSSL libraries for its internal encryption and other functions. OpenSSL is a FIPS 140-2 validated cryptographic provider. The purpose of doing so is to ensure that the Agent is in FIPS mode and is compliant with United States federal purchasing policies and standards.

UAM uses Mozilla NSS libraries and Java SSL libraries for creating the listener on port 2222 and OpenSSL libraries for communicating with Agents. For UAM, we ship our own copies of the Mozilla NSS libraries. Red Hat Enterprise Linux (RHEL) and SUSE Linux Enterprise Server (SLES) have a different set of NSS packages. The NSS cryptographic module provided by RHEL and SLES are FIPS 140-2 validated.

IMPORTANT:If you deploy the Agent in FIPS mode, you must deploy the NetIQ security products in FIPS mode. If not, you can deploy all the components in non-FIPS mode.

2.5.1 Installation Options

The following are different ways in which you can implement FIPS 140-2:

NOTE:If you have converted the Agent to FIPS mode, you cannot revert back to non-FIPS mode.

Tasks

For more information, seeā€¦

Local installation: To enable the Agent in FIPS 140-2 mode during local installation

Local installation

Remote installation: To enable the Agent in FIPS 140-2 mode during remote installation

Remote installation

2.5.2 FIPS-Enabled Components

The following components provide FIPS 140-2 support:

  • Sentinel Server 7.4 and later

  • Change Guardian Server 4.2.1 and later

  • Secure Configuration Manager Core 6.1 and later

  • Sentinel Security Agent for UNIX 7.5 and later

  • Change Guardian Security Agent for UNIX 7.5 and later

  • Secure Configuration Manager Security Agent for UNIX 7.5 and later

  • UAM 7.5 and later

  • Sentinel Agent Manager Connector 2011.1r5 and later