About FIPS enablement for Replication Gateway appliance
Federal Information Processing Standards (FIPS) is a set of standards that describe document processing, encryption algorithms, and other information technology standards for use within the non-military government agencies and by government contractors and vendors who work with these agencies.
Resiliency Platform Data Mover lets you configure encryption of data over WAN (Wide Area Network). It uses the openssl library provided by the operating system vendor RedHat to encrypt the data before transmitting the data. Openssl library shipped with RHEL 6.6 and onwards is certified under the certificate numbers 2446 and 2447:
http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/1401val2015.htm
Veritas Resiliency Platform provides 128 bit and 256 bit encryption schemes. When the operating system gets started with FIPS mode enabled, Veritas Resiliency Platform operates in the FIPS compliant mode.
You can enable the FIPS mode for a Replication Gateway during the bootstrap process:
You can enable, disable, or view the status of the FIPS mode by using the manage > fips option of klish menu:
Note:
You need to keep similar FIPS setting for the paired Replication Gateways.
More Information