Knowledge Transfer with Ipswitch File Transfer
Jul
02

MOVEit Crypto, the encryption component used to secure data and settings in MOVEit DMZ and MOVEit Central in mission-critical, Internet-exposed applications, has been revalidated under FIPS 140-2 and has been issued certificate #1363.   This certificate should be available on the Cryptographic Module Validation Program (CMVP)’s website (nist.gov) in 1-2 weeks.

The changes in MOVEit Crypto that required the revalidation were mainly related to the introduction of “SHA-2″ hashes such as as SHA-256.  As you may already be aware, use of unkeyed SHA-1 hashes will be disallowed in U.S. government applications by the end of the year.  (Weaker hashes such as MD5 and non-cryptographic quality integrity checks such as CRC are already disallowed.)  Fortunately, existing MOVEit products make use of keyed SHA-1 hashes (not the unkeyed hashes that will soon be disallowed), so use of existing MOVEit products with the older version of MOVEit Crypto will be allowed in U.S. government applications well beyond the end of the year.

About jlampe:

Jonathan Lampe is VP, Product Management, of Ipswitch File Transfer. He developed the first editions of the MOVEit managed file transfer software and continues to guide the File Transfer division as it continues to pursue its mission of moving your most valuable data. He holds a computer science degree and an operations degree from Northern Illinois University, an MBA from the University of Wisconsin-Madison and two security certifications: ISC2's CISSP and SANS' System and Network Auditor.

Find all posts by jlampe | Visit Website

You can leave a response, or trackback from your own site.

One Response to “MOVEit Crypto earns new FIPS 140-2 validation”

 
  1. [...] This post was mentioned on Twitter by IpswitchFileTransfer. IpswitchFileTransfer said: Update: MOVEit Crypto earns new FIPS 140-2 validation http://bit.ly/bIc51d [...]

 

Leave a Reply