6.0 Deployment Considerations for Operating Sentinel in FIPS140-2 Mode

Sentinel can optionally be configured to use Mozilla Network Security Services (NSS), which is a FIPS 140-2 validated cryptographic provider, for its internal encryption and other functions. The purpose of doing so is to ensure that Sentinel is ‘FIPS 140-2 Inside’ and is compliant with United States federal purchasing policies and standards.

Enabling Sentinel FIPS 140-2 mode causes communication between the Sentinel Server, Sentinel remote Collector Managers, Sentinel remote Correlation Engines, the Sentinel Web UI, the Sentinel Control Center, and the Sentinel Advisor service to use FIPS 140-2 validated cryptography.