The algorithms implemented in the Sensor image are FIPS 140-2 compliant. Make note of the following features when FIPS compliant images are enabled in the Sensor:
Note
For a list of Sensor features that do not specifically relate to FIPS mode, refer to Trellix Intrusion Prevention System 10.1.x Product Guide.
- The Sensor version supports features that are mandatory requirement for Common Criteria certification.
- This FIPS Sensor image only permits the subsequent load of a SHA-256 signed Sensor image. This is mandated by FIPS 140-2, effective 2014. A subsequent load of a Sensor image signed using a weaker algorithm (for example, sha1WithRSAEncryption) fails. You must netboot the Sensor to load a non-FIPS image signed with a weaker algorithm.
- All critical security parameters (CSPs) are zeroized, in compliance with FIPS 140-2.
- The following channels operate with algorithms approved by FIPS 140-2:
- Alert Channel
- Log Channel
- Authentication Channel
Note
The SNMPv3 channel between the Manager and Sensor uses AES128 encryption, SHA authentication, and is RFC3414 and RFC3826 compliant. All CSP information on this channel is additionally encrypted by the Manager using the Sensor 2048-bit RSA and can be decrypted only by the Sensor private key.
- Common Criteria compliance requires the use of specific secure protocols. Hence, SNMPv3 is further encapsulated within TLS. The Sensor will use port 18500 as a TLS server for this service.
Note
If the trust between the Manager and Sensor is established using a self-signed certificate, the Sensor will use port 8500 to service SNMPv3 as a TCP/UDP server. If the trust between the Manager and Sensor is established using a CA-signed certificate, the Sensor will use port 18500 to service SNMPv3 as a TLS server.
-
The Sensor supports read-only access to third party SNMPv3 clients. Third party SNMPv3 clients can only be configured at the Manager. The Sensor retains the use of port 8500 for SNMPv3 service to these clients.
- The Sensor alert, packet log, and authentication channels use TLS-ECDHE-RSA-AES128_GCM-SHA256.
- TACACS+ authentication configuration is disabled at the Sensor level.
- Stronger authentication for user login enforced.
- The Manager version that supports FIPS can manage Sensors that are not FIPS compliant. In the Common Criteria (CC) evaluated configuration, all Sensors must be in FIPS mode.
- When a Sensor of a fail-over pair is running a FIPS image, it is mandatory for the peer Sensor to also be FIPS compliant.
Note
Before you upgrade, convert the Sensors in the fail-over pair to standalone Sensors. If you do not do this, trust will not be re-established after the upgrade.
- The channels use RSA certificates based on 2048-bit RSA keys.
- Use SCP for file transfers. The use of TFTP is not permitted.
- Cryptographic support is provided by Trellix modified OpenSSL-FIPS-Object-Module v2.0 and OpenSSL v1.0.2za.
- Trellix modified OpenSSH v7.8p1 is configured to support only the following:
- Ciphers: aes256-gcm, aes128-gcm
- MACs: hmac-sha2-256 and hmac-sha2-512
- KexAlgorithms: ecdh-sha2-nistp256
- HostKeyAlgorithms: ecdsa-sha2-nistp256
- SSH in 10.1 FIPS Sensor image is restricted to AES GCM Mode cipher only. The use of AES CBC or CTR mode is not permitted.
- This requires that an external SSH client or server must support AES GCM mode ciphers. Some popular clients (like PuTTY) may not support them currently. In such scenarios, you must migrate to an alternative SSH client or server approved by your local administrator.
- The external SSH client is used to log into a Sensor running 10.1 FIPS image.
- The external SSH server is used to host a remote Sensor image, that you can SCP into the Sensor running a 10.1 FIPS image using the loadimage CLI command.