[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: FIPS-140 required?




Hi Dan,

definitely. I'm interested, and so are some other folks that have talked to me. At present, the default crypto algorithms and parameters for SRTP are on the FIPS-140 approved algorithms list (http://csrc.nist.gov/publications/fips/fips140-2/ fips1402annexa.pdf). It is also highly desirable to have a media plane keying method that is FIPS-140 conformant.

There is an FIPS-140 issue that I'm aware of for SRTP. Some voip implementations use a 32-bit authentication tag in SRTP. It is not clear yet whether or not this weak authentication is a currently acceptable parameter choice for FIPS-140, but the default tag length is 80 bits, and there is no problem with that length.

David

On Jan 26, 2007, at 2:54 PM, Dan Wing wrote:


Is anyone seeing a requirement for FIPS-140 for products that implement
SRTP?

(FIPS 140-2 is "Security Requirements for Cryptographic Modules",
http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf )

-d