13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

FIPS<strong>Support</strong>ed algorithmsThe cryptographic module supports <strong>the</strong> following algorithms in FIPS mode:Approved Algorithms:● RSA digital signature verification during firmware upgrades, and license file au<strong>the</strong>ntication.<strong>Support</strong> for RSA defined in PKCS#1 standard. RSA implementation, as defined byANSI X9.31, is not supported.●●●●●Triple-DES CBC (three key) for IKE encryption and IPSecAES (128bit) CBC for IPSec and IKE encryptionSHA-1 for hashing download image digest, license file digestHMAC SHA-1 for message au<strong>the</strong>ntication codes for IKE and IPSECDES CBC for encryption <strong>of</strong> IPSec, and IKE (only supported for communication with legacysystems)● TDES CBC Encryption <strong>of</strong> <strong>the</strong> serial number date for Voice feature activation controlled by<strong>the</strong> ICC CM server/external blade serverNon-Approved Algorithms:● Diffie-Hellman for IKE key exchanges● MD5 for Radius Client role and peer OSPF router au<strong>the</strong>nticationThe cryptographic module relies on <strong>the</strong> implemented deterministic random number generator(DRNG) that is compliant with X9.31 with 128-bit Key, 64bit Seed for generation <strong>of</strong> allcryptographic keys. The non-deterministic random seed generator is used for <strong>the</strong> periodicre-seeding <strong>of</strong> <strong>the</strong> PRNG.The cryptographic module may be configured for FIPS mode via execution <strong>of</strong> <strong>the</strong> configurationprocedure specified in <strong>Administration</strong> procedures on page 307.The user can determine if <strong>the</strong> cryptographic module is running in FIPS vs. non-FIPS mode via:● Execution <strong>of</strong> <strong>the</strong> show running-config command.●●Verification that <strong>the</strong> configuration meets <strong>the</strong> requirements specified in <strong>Administration</strong>procedures on page 307.Verification that <strong>the</strong> HW version and <strong>the</strong> firmware version <strong>of</strong> <strong>the</strong> module firmware code inbanks A and B are FIPS-approved versions.292 <strong>Administration</strong> <strong>of</strong> <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!