Explains the FIPS 140-2 cryptographic-module standard, the Cisco Common Cryptographic Module, and the Cisco IOS XR applications verified for FIPS compliance.
Federal Information Processing Standard (FIPS) 140-2 is a U.S. and Canadian government certification standard that
-
defines requirements for cryptographic modules
-
specifies practices for algorithms, key material, data buffers, and operating-system interaction, and
-
supports level 1 compliance in Cisco IOS XR software through the Cisco Common Cryptographic Module (C3M).
C3M provides FIPS-validated cryptographic primitives and functions that applications and protocols can use.
Applications verified for FIPS compliance
Cisco IOS XR software verifies these applications for FIPS compliance:
-
Secure Shell (SSH)
-
Secure Sockets Layer (SSL)
-
Transport Layer Security (TLS)
-
Internet Protocol Security (IPsec) for Open Shortest Path First version 3 (OSPFv3)
-
Simple Network Management Protocol version 3 (SNMPv3)
-
AAA password security
C3M also provides cryptographic services for protocols and applications such as RTP and 802.1X.