![NetApp AltaVault AVA400 Administration Manual Download Page 104](http://html.mh-extra.com/html/netapp/altavault-ava400/altavault-ava400_administration-manual_1669933104.webp)
104
NetApp AltaVault Cloud Integrated Storage Administration Guide
Beta Draft
Configuring AltaVault appliances for FIPS-compliant cryptography
Understanding FIPS on AltaVault
AltaVault requires all imported and generated keys sizes for RSA-based and DSA-based certificates to be 2048 bits or
higher.
NetApp Cryptographic Security Module
The NetApp Cryptographic Security Module is the part of AltaVault software that separates the cryptography that is
FIPS compliant from the rest of the AltaVault.
The NetApp Cryptographic Security Module is compatible with FIPS 140-2 Level 1 requirements.
The NetApp Cryptographic Security Module appears as the validated cryptographic module on the NIST vendor page
instead of a specific AltaVault. The NIST vendor page is available at this URL:
http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm
Note:
Throughout this guide,
FIPS-mode
and
FIPS-compliance
refers to use of the NetApp Cryptographic Security Module.
Compliant FIPS cryptography features
The following features use FIPS-compliant cryptography:
Web interface (Apache Web server)
Local user passwords and local authentication using SHA256-based or SHA512-based hash
Image integrity checks for AltaVault OS
File transfers
NTP with SHA authentication
Secure vault
SNMP except if SNMP user passwords are configured with MD5 or DES protocols
SSH with approved ciphers
SSL optimization
AltaVault Storage Optimization Service
AltaVault data replication
Domain-join feature in the AltaVault
Noncompliant FIPS cryptography features
The following features are not FIPS compliant. The system does not prevent you from using these features, but it does
warn you that they are not FIPS compliant. You need to ensure that the system is configured in FIPS mode and uses
only FIPS-compliant features to achieve full compliance.
Features Depending on NTLM or Kerberos Domain Authentication
SMB signing
Summary of Contents for AltaVault AVA400
Page 2: ...Beta Draft ...
Page 10: ...Beta Draft Contents ...