2016 Symantec Corporation This document may be freely reproduced & distributed whole & intact including this copyright
notice.
38
SV3800, SV3800B, and SV3800B-20 Security Policy
Key
Key Type
Generation/
Input
Output
Storage
Use
Resigning CA
private key
RSA 2048 bits
only for
internally
generated
RSA 2048,
3072, 4096,
8192 bits can
be imported
Internally
generated
using DRBG
Can be
imported in
encrypted
(PEM or
PKCS12 or
PKCS8) or
plaintext, or
from
encrypted
backup
Exported in
encrypted
backup
Encrypted with
associated object
encryption key
and stored on
internal disk
Resigning
server
certificates
during
SSL/TLS
interception
Trusted
certificate
public key
RSA 2048,
4096 bits
Imported in
plaintext or
encrypted form
(PEM or
PKCS12 or
PKCS8), or from
encrypted
backup
Exported in
encrypted
backup
Encrypted with
associated
object
encryption key
and stored on
internal disk
Making policy
decisions for
SSL/TLS
interception
Known public
key
RSA 2048,
4096, 8192
bits, ECDSA
all NIST
defined B, K,
P curves 224
bits and
higher
Imported in
plaintext or
encrypted
form (PEM or
PKCS12 or
PKCS8), or
from an
encrypted
backup
Exported in
encrypted
backup
Encrypted with
associated
object
encryption key
and stored on
internal disk
SSL/TLS
decryption and
inspection
Known private
key
RSA 2048,
4096, 8192
bits, ECDSA
all NIST
defined B, K,
P curves 224
bits and
higher
Imported in
plaintext or
encrypted
form (PEM or
PKCS12 or
PKCS8), or
from an
encrypted
backup
Exported in
encrypted
backup
Encrypted with
associated
object
encryption key
and stored on
internal disk
SSL/TLS
decryption and
inspection