Search

Navigation
  • Home
  • App dev (5) RSS
  • Client Notes.inis (3) RSS
  • Customer self-assist (5) RSS
  • Database mail file (0) RSS
  • Designer agents (1) RSS
  • Domino Access for Microsoft Outlook (1) RSS
  • Domino admin (8) RSS
  • Domino agents (2) RSS
  • Domino clusters (4) RSS
  • Domino database performance (36) RSS
  • Domino database replication (4) RSS
  • Domino databases (20) RSS
  • Domino DB2 (2) RSS
  • Domino deployment issues (10) RSS
  • Domino deployment scenarios (4) RSS
  • Domino diagnostics (5) RSS
  • Domino directory (2) RSS
  • Domino disk management (1) RSS
  • Domino logging (8) RSS
  • Domino memory (12) RSS
  • Domino messaging (31) RSS
  • Domino migration (0) RSS
  • Domino operating systems (1) RSS
  • Domino policies (5) RSS
  • Domino security (6) RSS
  • Domino server performance (11) RSS
  • Domino server tasks (3) RSS
  • Domino transactions (5) RSS
  • Domino troubleshooting (8) RSS
  • Domino upgrade (3) RSS
  • Domino Web Access admin (1) RSS
  • Domino Web Access deployment scenarios (0) RSS
  • Domino Web Access installation (0) RSS
  • Domino Web Access messaging (0) RSS
  • Domino Web Access operating systems (0) RSS
  • Domino Web Access performance (0) RSS
  • Domino Web Access policies (1) RSS
  • Domino Web Access security (0) RSS
  • Domino Web Access troubleshooting (0) RSS
  • Domino Web server (1) RSS
  • Java (3) RSS
  • Learning (5) RSS
  • Notes calendaring and scheduling (3) RSS
  • Notes client (3) RSS
  • Notes client provisioning and install (6) RSS
  • Notes deployment issues (9) RSS
  • Notes deployment scenarios (0) RSS
  • Notes messaging (1) RSS
  • Notes security (1) RSS
  • Notes templates (0) RSS
  • Notes Traveler administration (0) RSS
  • Notes Traveler deployment issues (0) RSS
  • Notes Traveler deployment scenarios (1) RSS
  • Notes Traveler installation (0) RSS
  • Notes Traveler mail (0) RSS
  • Notes Traveler performance (0) RSS
  • Notes Traveler security (0) RSS
  • Notes Traveler troubleshooting (0) RSS
  • Notes troubleshooting (1) RSS
  • Notes Widgets and Live Text (4) RSS
  • Server Notes.inis (64) RSS


  • Deploying FIPS 140-2 certified ID and document encryption


    Article information
    Domino deployment scenarios , Domino security
    encryption , FIPS
    Kendra Bowker
    02/20/2008
    Amy Smith
    06/06/2008
      Written by IBM

  • Edit
  • 6/6/2008 11:47:05 AMAmy Smith
    Federal Information Processing Standard (FIPS) regulates cryptography and the use of cryptographic libraries. Lotus Domino and Notes 8.0.1 (32-bit Microsoft Windows platform only) now ships with a FIPS 140-2 certified cryptographic library.  Described below are two scenarios for deploying FIPS 140-2 certified ID encryption and mail/document encryption.  

    Scenario 1: Deploying FIPS 140-2 certified Notes ID and document encryption for all users in a domain

    In this scenario, an agency of the US Federal Government has a mandate to use FIPS-certified cryptographic libraries for encryption of all user IDs and confidential e-mail and documents throughout a domain. The agency has Domino 7.0.3 servers and Notes 6.5.4 clients, all deployed on the 32-bit Windows platform. The agency will perform the following steps.
    1.        Upgrade all the Domino servers and Notes clients in the domain to release 8.0.1.  For more information, see the infocenter topic IBM Lotus Notes and Domino 8 Deployment Guide.
    2.        Use a Security Settings document and policy to use AES to encrypt the ID files of all users. Select "Mandated encryption standards" using 128-bit AES encryption, so that the IDs are automatically and silently encrypted with AES, and users are required to use AES when changing passwords. Accept the default key derivation strength, 5000. Although 256-bit AES encryption is available, 128-bit encryption is sufficiently strong for the foreseeable future, and 256-bit encryption can cause delays on lower-end clients, currently.  Assign the policy to all users in the domain.  For more information, see infocenter topic  Configuring encryption for ID files.
    3.        Rollover the IDs of all servers to the use of 1024-bit or 2048-bit keys. 1024-bit or greater keys are required to use a FIPS 140-2 approved algorithm for document and mail encryption. For more information, see the infocenter topic User and server key rollover.  
    4.        Rollover the IDs of all users to the use of 1024-bit or 2048-bit keys. The new keys are protected by the AES encryption mandated for the IDs in Step 2 above.
    5.        Use a Security Settings document and policy to configure all users to use AES for mail and document encryption by choosing the option "Use FIPS 140-2 algorithms for Notes encryption (requires 8.0.x or higher server and client)" in the Security Settings document. Note that the use of this option would prevent clients running release 8.0 or an earlier release from decrypting mail and documents, but this is not a concern because the agency has upgraded all servers and users to release 8.0.1. For more information, see the infocenter topic Configuring AES for mail and document encryption.

    Scenario 2: Deploying FIPS 140-2 certified Notes ID and document encryption for a subset of users in a domain

    In this scenario, an agency of the US Federal Government has a mandate to implement FIPS-certified cryptographic libraries for encryption of user ID files and confidential e-mail and documents over a period of time. As a first step, the agency will implement this capability for a subset of users in its domain. The agency currently has Domino 7.0.3 servers and Notes 6.5.4 clients, all deployed on the 32-bit Windows platform.  The agency will perform the following steps.
    1.        Upgrade the Domino home servers and Notes clients of the subset of users in the domain to release 8.0.1. For more information, see the IBM Lotus Notes and Domino 8 Deployment Guide.
    2.        Use a Security Settings document and policy to use AES to encrypt the ID files of the subset of users. Select "Mandated encryption standards" using 128-bit AES encryption, and accept the default key derivation strength, 5000. Although 256-bit AES encryption is available, 128-bit encryption is sufficiently strong for the foreseeable future, and 256-bit encryption can cause delays on lower-end clients, currently.   Assign the policy only to the subset of users in the domain.  For more information, see the infocenter topic  Configuring encryption for ID files.
    3.        Rollover the IDs of the home servers of the subset of users to the use of 1024-bit or 2048-bit keys. 1024-bit or greater keys are required to use a FIPS 140-2 approved algorithm for document and mail encryption. For more information, see the infocenter topic User and server key rollover.  
    4.        Rollover the IDs of the subset of users to the use of 1024-bit or 2048-bit keys. The new keys are protected by the AES encryption mandated for the IDs in Step 2 above.
    5.        Use the "Encryption Capabilities" tool in the Domino Administrator to select "Capable of decrypting FIPS 140-2" for the subset of users. When these users encrypt mail or documents, AES is used only if the Person documents of all of the recipients specify "Capable of decrypting FIPS 140-2."  For more information, see the infocenter topic Configuring AES for mail and document encryption.

    Comments

    1) Deploying FIPS 140-2 certified ID and document encryption
    | 5/22/2008 3:58:01 PM ET

    You need to specify the certified module and its cert. #