(unknown)

[email protected] Thu, 27 May 2004 09:55:05 -0400 (EDT)
Newsgroups gmane.ietf.snmpv3
Message-ID <[email protected]>
[192.94.214.100])
	by lists.tislabs.com (8.11.6/8.11.6) with ESMTP id i4QKt1c20206
	for <[email protected]>; Wed, 26 May 2004 16:55:01 -0400 (EDT)
csmap (V6.0)
	id srcAAAO_aqbC; Wed, 26 May 04 16:54:03 -0400
To: "Sean Lawless" <[email protected]>
Cc: "Snmpv3-wg" <[email protected]>
Subject: Re: SNMPv3 and FIPS 140-1
References: <[email protected]>
From: Wes Hardaker <[email protected]>
Organization: Sparta
Date: Wed, 26 May 2004 13:56:22 -0700
In-Reply-To: <[email protected]> (Sean Lawless's message of
  "Wed, 26 May 2004 19:56:20 +0000")
Message-ID: <[email protected]>
User-Agent: Gnus/5.110002 (No Gnus v0.2) XEmacs/21.5 (celeriac, linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Sender: [email protected]
Precedence: bulk

 >>>>> On Wed, 26 May 2004 19:56:20 +0000, "Sean Lawless" 
<[email protected]> said:

Sean> Does anyone know how to extend SNMPv3 to be FIPS 140-1 Level 2
Sean> compliant?  Specifically, HMAC SHA-1 is not FIPS compliant to my
Sean> understanding.

Quick web searches led me to believe that SHA-1 with and without HMAC
is FIPS-2 compliant at least and I think FIPS-1 as well.  But I'm not
an expert.

Sean> Running SNMPv3 through a VPN seems to defeat its purpose.

It is fairly trivial to add other algorithms to USM if you needed to
use something different.

-- 
Wes Hardaker
Sparta