What is the difference between FIPS 140-2 and 140-3?   | Cerberus FTP Server (2024)

The U.S. federal government’s transition to the FIPS 140-3 cryptography standard has begun, with NIST announcing that all FIPS 140-2 certificates will be retired in September 2026. Cerberus FTP Server versions 12.11 and higher have moved to OpenSSL 3, which will extend FIPS validation through the end of 140-2’s lifecycle, and future versions of Cerberus will include FIPS 140-3 validation.

This post will discuss the reasons behind NIST’s transition and the benefit of FIPS 140-3 validation for data transfer.

What’s new in FIPS 140-3?

Cryptography

FIPS 140-3 extends cryptography standards beyond hardware to include both firmware, software, and hybrid modules.

  • Block ciphers must use AES 128 or higher algorithms for encryption. Older algorithms such as TDEA and SKIP JACK may only be used for legacy decryption
  • Digital signatures must use security greater than or equal to 112 bits for any new signature generation
  • Hash functions have received further guidance on appropriate use cases in the FIPS 140-3 Transition Documentation

Additionally, FIPS 140-3 now includes a “Self-Initiated Cryptographic Output Capability,” which is an automated functioning module that can execute cryptographic operations or other approved security functions autonomously.

Roles & Authentication

Adherence to ISO 19790‘s authentication levels remains in place, but level 4 authentication must now be performed via multi-factor identify-based authentication. This requirement has changed due to the upgrade from 140-2’s trusted path to 140-3’s trusted channel and its effort to secure communications between the cryptographic module and the endpoint device.

140-3 also adds a fifth control output interface that will indicate the state of an operation, which can help troubleshoot.

The only required role in FIPS 140-3 is the crypto officer role, although the user and maintenance roles remain options.

Validation and Testing

Because hybrid modules (hybrid firmware, hybrid software, etc.) are included in FIPS 140-3, a wider variety of vendors and resources will be able to apply for validation beyond level 1. This should open up a more extensive toolset for secure transfer, which is always a positive.

Testing has changed as well:

  • FIPS 140-3 now requires a Pre-Operational Self-Test (POST) and the Conditional Algorithm Self-Test.
  • Known Answer Tests now only run prior to using an algorithm.
  • The POST now focuses on memory integrity.

Cryptography is complex, and we hope this blog has helped you understand what is changing in the transition to FIPS 140-3. Click here to learn more about FIPS 140 compliance with Cerberus FTP Server. To learn more about Cerberus FTP Server, visit cerberusftp.com.

What is the difference between FIPS 140-2 and 140-3?   | Cerberus FTP Server (2024)
Top Articles
Stay At Home Calculator: Can Your Household Get By On One Income?
ORICO 10400mah Power Bank - Aluminium - Micro USB Input - 5V 2A USB Output (LS) - Deals499
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Selly Medaline
Latest Posts
Article information

Author: Kieth Sipes

Last Updated:

Views: 5907

Rating: 4.7 / 5 (67 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Kieth Sipes

Birthday: 2001-04-14

Address: Suite 492 62479 Champlin Loop, South Catrice, MS 57271

Phone: +9663362133320

Job: District Sales Analyst

Hobby: Digital arts, Dance, Ghost hunting, Worldbuilding, Kayaking, Table tennis, 3D printing

Introduction: My name is Kieth Sipes, I am a zany, rich, courageous, powerful, faithful, jolly, excited person who loves writing and wants to share my knowledge and understanding with you.