+

Search Tips   |   Advanced Search

Set up a Liberty profile to run in SP800-131a

We can set up a Liberty profile to meet the SP800-131a requirement that is originated by the National Institute of Standards and Technology (NIST).

SP800-131a requires longer key lengths and stronger cryptography. The specification also provides a transition configuration to enable users to move to a strict enforcement of SP800-131a. The transition configuration also enables users to run with a mixture of settings from both FIPS140-2 and SP800-131a. SP800-131a can be run in two modes, transition and strict. The transition mode is offered to give user a setting to move their environment to SP800-131a strict mode. In transition mode, it is optional to use the SP800-131a required certificates and to set the protocol to SP800-131a

Strict enforcement of SP800-131a requirements on the Liberty profile includes the following:

To configure a Liberty profile server to run in SP800-131a mode, users must be running with a level of the IBM JDK that supports SP800-131a. The minimal levels of the IBM JDK include Java 6 sr 10, Java 6.0.1 sr 2, or Java 7.

For more information about the SP800-131a standard, see the National Institute of Standards and Technology.

We can configure the Liberty profile to run in SP800-131a strict mode or transition mode as following:


Parent topic: Secure communications with the Liberty profile

Tasks:

  • Customize the Liberty profile environment
  • Enable SSL communication

    Reference:
    National Institute of Standards and Technology
    Validated FIPS 140-1 and FIPS 140-2 Cryptographic Modules

  • SSL configuration attributes