About FIPS with Riverbed Systems : FIPS cryptography compliance behavior
  
FIPS cryptography compliance behavior
The following table provides details about the behavior of features while the Riverbed appliance is in FIPS mode. Some of these features use FIPS-compliant cryptography. Some of the features are not FIPS compliant and generate a warning if they are enabled or if you try to configure them. The system does not prevent you from using these features, but it does warn you that they are not FIPS compliant.
Feature
Compliant
Warning
Blocked
Account passwords
Yes, when local user passwords and local authentication use SHA256-based or SHA512-based hash
Yes
Yes, when MD5 is used
Automatic licensing
No
Yes
No
Blockstore
Yes, when configured with AES_128, AES_192, or AES_256
No
No
Citrix
No
Yes
No
Delta software upgrade
Yes
No
No
File transfers
Yes
No
No
HTTP Kerberos
No
Yes
No
Image integrity checks for RiOS
Yes
No
No
IPsec secure peering
See IPsec.
No
Yes
No
iSCSI with CHAPs
No
No
No
Lotus Notes encryption
No
Yes
No
MAPI-RPC encryption
No
Yes
Yes
MAPI-OA encryption (RC4 or AES)
No
Yes
No
Mobile Controller cluster communications in FIPS mode using SHA-1 based hash.
Clusters with a mix of Mobile Controllers running in FIPS and non-FIPS mode clusters are supported but not recommended.
Yes
No
No
Network web proxy
No
Yes
No
NTP with SHA authentication
See NTP.
Yes, when not configured to use MD5
Yes
No
RADIUS
No
Yes
No
SCC Auto-Registration
No
Yes
No
Secure peering
Yes
No
No
Secure transport
No
No
No
Secure vault
Yes
No
No
SMBv1/CIFS signing
No
Yes
Yes
SMBv2/SMBv3 signing with client using NTLM authentication
No
Yes
No
SMBv2/SMBv3 signing with client using Kerberos authentication
Yes
No
No
SMBv3 signing/encryption
No
Yes
Yes
Snapshots
See SNMP.
Yes, when a third party uses FIPS-approved ciphers.
No
No
SNMP
See SNMP.
Yes, when configured to not use MD5 or DES for user passwords
Yes
No
SSH
See SSH.
Yes, when configured with FIPS ciphers
Yes
No
SSL optimization
Yes
Yes
No
SSL secure peering
Yes
Yes
No
SSL web UI
Yes, when using certificates generated with a size greater than 1024
Yes
Yes
TACACS+
No
Yes
No
Telnet
No
Yes
Yes
Virtual services platform
See WCCP.
No
No
No
WCCP
See WCCP.
No
Yes
No
Web interface (Apache web server)
Yes
No
No
Windows AD authority
No
Yes
Yes