Device Adapter complies with Federal Information Processing Standards Publication (FIPS) 140-2, Security Requirements for Cryptographic Modules, which specifies the security requirements to be met by the cryptographic modules.
Device Adapter version 8.1.3 or later is compliant to FIPS 140-2. Device Adapter uses Avaya Breeze® platform utilities and FIPS mode must be enabled on Avaya Breeze® platform to use the fully FIPS compliant Device Adapter.
Device Adapter uses the following crypto modules:
-
TLS to connect to Avaya Aura® Session Manager. Avaya Breeze® (RedHat Enterprise Linux 7). FIPS 140-2 compliant provides the TLS module.
-
DTLS to secure Unistim traffic between TPS and Unistim phones. The built-in Mocana NanoSec library drives the DTLS.
-
IPSec to secure signaling traffic between the Device Adapter and the Media Gateways. Libreswan is FIPS compliant for RHEL 7 unless Avaya Breeze® operates in FIPS mode.
-
SSH protocol to push or pull files from the Media Gateways.
Note:
Media Gateway connections, such as IPSec and SSH are FIPS 140-2 compliant. Media Gateway stays non-FIPS compliant since it is a legacy product.