HTTPS

The following HTTPS configurations are affected in FIPS mode:

The FIPS 140-2 cipher suites consist of the following algorithms:

  • AES (FIPS 197) for symmetric key encryption and decryption.
  • Secure Hash Standard (SHA-256, SHA-384, and SHA-512) (FIPS 180-2) for hashing).
  • HMAC (FIPS 198) for keyed hash
  • Random number generator Hash DRBG (NIST SP800-90).
  • Diffie-Hellman, EC Diffie-Hellman, or Key Wrapping using RSA keys for key establishment
  • RSA (PKCS #1 v2.1) for signature generation and verification for all ICX platforms; for ICX 7450 platform, RSA (PKCS #1 v2.1) or ECDSA (ANSI X9.62)

The following cipher suites are allowed in FIPS mode:

  • TLS_DHE_RSA_WITH_AES_128_CBC_SHA
  • TLS_DHE_RSA_WITH_AES_256_CBC_SHA
  • TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
  • TLS_DHE_RSA_WITH_AES_256_CBC_SHA256