2016 Symantec Corporation This document may be freely reproduced & distributed whole & intact including this copyright
notice.
34
SV3800, SV3800B, and SV3800B-20 Security Policy
Algorithm
Details
EC Diffie-Hellman
Used for SSL/TLS sessions during SSL inspection.
Key size range: 224 - 571 bits
All NIST defined B, K, and P curves
Key agreement; key establishment methodology provides
between 112 and 256 bits of encryption strength.
True RNG (TRNG)
Implemented in hardware. Used to provide additional
entropy to NDRNG.
Non-deterministic RNG (NDRNG)
Used to seed SP 800-90A DRBG.
RSA PKCS #1 wrap/unwrap
Used for SSL/TLS sessions.
The key wrapping methodology provides between 112 and
256 bits of encryption strength.
Diffie-Hellman
Used for SSL/TLS sessions during SSL inspection.
Diffie-Hellman public key size range: 2048 - 15360 bits
Diffie-Hellman private key size range: 112 - 512 bits
Table 2
–13b SV3800/SV3800B/SV3800B-20 Non-FIPS 140-2 Approved and non-compliant Security Functions
Algorithm
Details
RSA
SSL/TLS Interception
RSA key sizes between 512 and less than 2048-bits may
be used for session negotiation during SSL/TLS
interception, resigning server certificates during SSL/TLS
interception, making policy decisions for SSL/TLS
interception, and SSL/TLS decryption and inspection.
EC Diffie-Hellman
Used for SSL/TLS sessions during SSL inspection.
Key size range: 163
–
less than 224 bits
All NIST defined B, K, and P curves
Curve25519 (128 bits of encryption strength)
MD5
Used for SSL/TLS sessions during SSL inspection.
RC4
Used for SSL/TLS sessions during SSL inspection.
Camelia
Used for SSL/TLS sessions during SSL inspection.
Key sizes: 128, 256 bit keys
Mode: CBC
DES
Used for SSL/TLS sessions during SSL inspection.
Mode: CBC