ePO - On-prem provides an operating mode with a higher level of security for environments that require it. This mode (FIPS mode) follows security guidelines detailed in section 140 of the Federal Information Processing Standard (FIPS).
The United States Government developed the Federal Information Processing Standards (FIPS) to define procedures, architecture, algorithms, and other techniques used in computer systems. FIPS 140-2 is a government standard for encryption and cryptographic modules where each individual encryption component in the overall solution requires an independent certification.
Federal Information Processing Standard 140-2 specifies requirements for hardware and software products that implement cryptographic functionality. FIPS 140-2 is applicable to "all Federal agencies that use cryptographic-based security systems to protect sensitive [but unclassified] information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104–106." The "-2" in FIPS 140-2 denotes the revision of the standard.
The full FIPS text is available online from the National Institute of Standards and Technology (NIST).
FIPS cryptographic modules and certification
FIPS compliance requires an explicitly defined continuous perimeter that establishes the physical bounds of a cryptographic module.
The cryptographic boundary defines this perimeter and contains the set of hardware, software, and firmware that implements valid security functions. Only the approved set of interfaces can access the cryptographic modules inside the cryptographic boundary. No other mechanism is allowed or provided when in FIPS mode.
Modules in the boundary perform these processes:
FIPS-validated security methods performing cryptography, hashing, and related services running in ePO - On-prem
Startup and verification testing required by FIPS
Extension and executable signature verification
TLS connection management
Cryptographic API wrapping
Important
Some older versions of Trellix products use non-FIPS-compliant ways to access ePO - On-prem cryptography and hashing services. Because these products violate the cryptographic boundary, they can't be used in FIPS mode. Check new versions of Trellix products for further information about FIPS compliance as they are released.
Trellix leverages these cryptographic modules to meet the requirements for FIPS-compliance.
Cryptographic module | Certificate number | Link |
|---|---|---|
Bouncy Castle FIPS Java API (BC-FJA) 1.0.2.3 | 3514 | https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/3514 |
OpenSSL FIPS Object Module 3.1.2
| 2398 | https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/2398 |
For ePO - On-prem 5.10.0 Service pack 1 Update 5, FIPS 140-3 modules are recommended.
Cryptographic module | Certificate number | Link |
|---|---|---|
Bouncy Castle FIPS Java API (BC-FJA) 2.0.0 | 4743 | https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4743 |
OpenSSL FIPS Object Module 3.1.2
| 2398 | https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/2398 |