4 ms·
Usually with government systems, they use a lot of commercial off the shelf (COTS) either configured or modified (MOTS) to only use FIPS certified implementatio
by gte525u 5y ago
Usually with government systems, they use a lot of commercial off the shelf (COTS) either configured or modified (MOTS) to only use FIPS certified implementation/module.
You'll see technologies like S/MIME, IPSEC, and CAC Cards or other tokens/smartcards.
- treesknees 5y agoIn my experience from the vendor side of FIPS/CC certified software and hardware, yes and no. It was pretty common for us to fully support running the servers/devices we sold in FIPS/CC compliant mode. However most customers just used that as a RFC checkbox during procurement and never turned it on. If you look at releases of OpenSSL that are FIPS certified for example, they're incredibly out of date. FIPS != Security, it's more about being able to audit the system. Most operators would file for some exemption and not actually run their devices in that mode, opting for actual security in the way of turning on newer encryption settings and the like.