Introduces FIPS, outlining its guidelines and restrictions, providing instructions for self-tests and configuration, explaining FIPS operation in HA setups, and describing procedures for monitoring and verifying FIPS compliance.
A Federal Information Processing Standard (FIPS) is a security standard that
-
defines requirements for cryptographic modules intended to secure sensitive but unclassified (SBU) information
-
is mandated for use by U.S. government agencies and adopted by many regulated industries such as finance and healthcare, and
-
establishes assurance levels to validate the strength and reliability of cryptographic implementations.
Sensitive but unclassified (SBU) information: Data that, while not classified for national security, still requires protection due to its sensitive nature and potential impact if disclosed.
Additional reference information
Federal Information Processing Standard (FIPS) 140-2 is a well-known FIPS standard specifying security requirements for cryptographic modules protecting SBU information. These cryptographic modules are produced by the private sector for use in government and regulated environments.With FIPS in the enabled state, some passwords and pre-shared keys must have the following minimum lengths:
-
For Software-Defined Access Wireless, between the controller and map server, a pre-shared key (such as the LISP authentication key) used for authenticating TCP messages must be at least 14 characters long.
-
The ISAKMP key (for example, the Crypto ISAKMP key) must also be at least 14 characters long.