FIPS 140-2

Last Updated : Jun 23, 2022 |

CMS provides the option to turn on the Federal Information Processing Standard (FIPS) 140-2 compliant mode which implements stronger encryption for the following interfaces:

  • SSH communications used by the CMS Supervisor PC Client

  • HTTPS communications used by the CMS Supervisor Web Client

When FIPS 140-2 mode is enabled, CMS will only provide the FIPS-approved modules for SSH and HTTPS connections.

CMS does not adopt FIPS 140-2 encryption for ODBC or JDBC connections since these are considered optional. However, beginning with CMS Release 19.0, the ODBC or JDBC connection can be optionally encrypted.

Beginning with CMS Release 19.1, the connection between CMS and Communication Manager Release 8.1.2 or later is encrypted.

To activate FIPS 140-2, use the cmssvc command, choosing the security option to enable or disable the FIPS 140-2 mode. For more information about FIPS 140-2 mode, see Maintaining and Troubleshooting Avaya Call Management System.