HOME > I NEED TO > COMPLY WITH FIPS 140-2
Send us a question or comment

...get a commercially supported UNIX Secure Shell server.

...remotely access machines over the Internet.

...replace nonsecure Telnet.

...replace nonsecure FTP.

...download and upload files securely with simple drag and drop.

...connect from the road to check e-mail.

...allow users to transfer files with limited access.

...lock down my firewall.

...automate or script secure file transfers.

...protect my private data.

...connect to hosts with a variety of terminal emulations.



I need to comply with FIPS 140-2

VanDyke Software has partnered with RSA Security, Inc. to use the BSAFE Crypto-C Micro Edition cryptography module which has been tested by Atlan Laboratories, an accredited testing laboratory for FIPS compliance. This module has met all Level 1 requirements for FIPS 140-2 compliance when operated in FIPS Mode. The FIPS Validation certificate is available for review (PDF file).

SecureCRT® 5.1 and later, SecureFX® 3.1 and later, and VShell® Server for Windows* 2.6 and later can run in FIPS mode. If you need to protect data in transit as outlined by FIPS 140-2 or NIST 800-53, these products now have an administrator option to run in "FIPS Mode". When this option is set, SecureCRT and SecureFX will use a FIPS 140-2 validated cryptographic library and only allow FIPS-approved algorithms.

* The 64-bit edition of VShell for Windows does not support FIPS mode.

FIPS-approved algortihms: The following FIPS-approved Cryptographic algorithms are used: DSA (Cert. #143); Triple-DES (Cert. #378); AES (Cert, #303); RSA (Cert. #96); SHA-1; Diffie-Helman (used for key exchange in SSH2 is allowed in FIPS Mode but not approved).

The following algorithms are not available in FIPS Mode: MD5; Twofish; Blowfish; RC4.

VanDyke Software products are a secure replacement for Telnet and FTP that provide end-to-end protection for data in transit that meets Federal recommendations. VShell server combines strong security with simple configuration. SecureCRT and SecureFX clients provide an excellent balance between strong security, capacity for customization, and ease of use.

SecureCRT is an extremely customizable terminal emulator with support for Secure Shell (SSH1 and SSH2) as well as Telnet and rlogin protocols. SecureCRT is ideal for connecting to remote systems running Windows, UNIX, and VMS.

SecureFX is a high-security file transfer client with great flexibility in configuration and transfer protocols. SecureFX includes a command-line utility for scripting batch jobs to perform secure unattended file transfers and also supports "relentless" file transfers that automatically reconnect and resume when connections are broken.

VShell server, a secure alternative to Telnet and FTP with additional data tunneling services, is a secure portal to a Windows or UNIX server's resources and the network. VShell provides secure authentication, strong encryption, and data integrity using the open Secure Shell protocol (SSH2).

VanDyke Software helps you achieve the right balance between strong security and easy access to the network from anywhere... at any time. Take the next step right now:

  1. Download evaluation copies of VanDyke Software products.
  2. Read our Secure Shell white papers.
  3. Contact us for assistance in designing the right solution for your organization.