FIPS basics

Prev Next

ePO - On-prem provides an operating mode with a higher level of security for environments that require it. This mode (FIPS mode) follows security guidelines detailed in section 140 of the Federal Information Processing Standard (FIPS).

The United States Government developed the Federal Information Processing Standards (FIPS) to define procedures, architecture, algorithms, and other techniques used in computer systems. FIPS 140-2 is a government standard for encryption and cryptographic modules where each individual encryption component in the overall solution requires an independent certification.

Federal Information Processing Standard 140-2 specifies requirements for hardware and software products that implement cryptographic functionality. FIPS 140-2 is applicable to "all Federal agencies that use cryptographic-based security systems to protect sensitive [but unclassified] information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104–106." The "-2" in FIPS 140-2 denotes the revision of the standard.

The full FIPS text is available online from the National Institute of Standards and Technology (NIST).

FIPS cryptographic modules and certification

FIPS compliance requires an explicitly defined continuous perimeter that establishes the physical bounds of a cryptographic module.

The cryptographic boundary defines this perimeter and contains the set of hardware, software, and firmware that implements valid security functions. Only the approved set of interfaces can access the cryptographic modules inside the cryptographic boundary. No other mechanism is allowed or provided when in FIPS mode.

Modules in the boundary perform these processes:

  • FIPS-validated security methods performing cryptography, hashing, and related services running in ePO - On-prem

  • Startup and verification testing required by FIPS

  • Extension and executable signature verification

  • TLS connection management

  • Cryptographic API wrapping

Important

Some older versions of Trellix products use non-FIPS-compliant ways to access ePO - On-prem cryptography and hashing services. Because these products violate the cryptographic boundary, they can't be used in FIPS mode. Check new versions of Trellix products for further information about FIPS compliance as they are released.

Trellix leverages these cryptographic modules to meet the requirements for FIPS-compliance.

Validated FIPS 140-2 cryptographic modules used by ePO - On-prem

Cryptographic module

Certificate number

Link

Bouncy Castle FIPS Java API (BC-FJA) 1.0.2.3

3514

https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/3514

OpenSSL FIPS Object Module 3.1.2

Note

This module is used only for TLS communication between ePO - On-prem and the Trellix Agent.

2398

https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/2398



For ePO - On-prem 5.10.0 Service pack 1 Update 5, FIPS 140-3 modules are recommended.

Validated FIPS 140-3 cryptographic modules used by ePO - On-prem

Cryptographic module

Certificate number

Link

Bouncy Castle FIPS Java API (BC-FJA) 2.0.0

4743

https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4743

OpenSSL FIPS Object Module 3.1.2

Note

This module is used only for TLS communication between ePO - On-prem and the Trellix Agent.

2398

https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/2398