<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Splunk support FIPS 140-2 in Security</title>
    <link>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25579#M834</link>
    <description>&lt;P&gt;Hi Araitz,&lt;BR /&gt;
 could you explain more detail about "we do not anticipate moving to the OpenSSL FIPS Object Model because of &lt;STRONG&gt;compatibility&lt;/STRONG&gt; and &lt;STRONG&gt;portability&lt;/STRONG&gt; reasons" ? thanks&lt;/P&gt;</description>
    <pubDate>Thu, 12 May 2011 08:19:32 GMT</pubDate>
    <dc:creator>dmlee</dc:creator>
    <dc:date>2011-05-12T08:19:32Z</dc:date>
    <item>
      <title>Does Splunk support FIPS 140-2</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25577#M832</link>
      <description>&lt;P&gt;Is splunk FIPS 140-2 compliant? &lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2011 03:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25577#M832</guid>
      <dc:creator>matt</dc:creator>
      <dc:date>2011-01-13T03:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk support FIPS 140-2</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25578#M833</link>
      <description>&lt;P&gt;Splunk (the software) has not been submitted for FIPS 140-2 accreditation.  At this time, there are no plans that I am aware of to engage in the accreditation process.&lt;/P&gt;

&lt;P&gt;Splunk uses OpenSSL shared libraries for all encryption, and according to openssl.org, OpenSSL will never be FIPS-140-2 validated/accredited:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.openssl.org/docs/fips/fipsnotes.html" rel="nofollow"&gt;http://www.openssl.org/docs/fips/fipsnotes.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Furthermore, Splunk does not use the OpenSSL FIPS Object Model, which has been uniquely validated as FIPS-140-2 compliant.  At this time, we do not anticipate moving to the OpenSSL FIPS Object Model because of compatibility and portability reasons.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2011 04:23:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25578#M833</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-01-13T04:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk support FIPS 140-2</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25579#M834</link>
      <description>&lt;P&gt;Hi Araitz,&lt;BR /&gt;
 could you explain more detail about "we do not anticipate moving to the OpenSSL FIPS Object Model because of &lt;STRONG&gt;compatibility&lt;/STRONG&gt; and &lt;STRONG&gt;portability&lt;/STRONG&gt; reasons" ? thanks&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2011 08:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25579#M834</guid>
      <dc:creator>dmlee</dc:creator>
      <dc:date>2011-05-12T08:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk support FIPS 140-2</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25580#M835</link>
      <description>&lt;P&gt;Splunk Enterprise 6 includes an OpenSSL FIPS module; see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Security/AboutusingSSLtoolsinWindowsandLinux#About_FIPS"&gt;About FIPS&lt;/A&gt; in the Securing Splunk manual.&lt;/P&gt;

&lt;P&gt;Note that upgrading a non-FIPS install to FIPS is not supported by Splunk – you must decide to use FIPS when your first install the product.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2013 19:35:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25580#M835</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2013-10-16T19:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk support FIPS 140-2</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25581#M836</link>
      <description>&lt;P&gt;This answer was indeed correct when provided in 2011 for Splunk 4.x.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2014 01:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25581#M836</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2014-06-10T01:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk support FIPS 140-2</title>
      <link>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25582#M837</link>
      <description>&lt;P&gt;As of version 6.3.0 of Splunk and Splunkforwarder, has Splunk Inc, gotten accreditation from NIST?&lt;/P&gt;

&lt;P&gt;On the latest version of Splunk 6.3.0 I do see that Splunk Inc. integrated the openssl FIPS object Model for the openssl that is included with splunk, and I see that there are still statements that you cannot migrate an existing non-fips splunk to a fips-complaint splunk can someone elaborate on the details of why that migration path is NOT supported (IE: are the indexes encrypted with non fips algrorythms?, or is it just a matter of ssl cert creations that meet FIPS standards?)&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 02:35:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-Splunk-support-FIPS-140-2/m-p/25582#M837</guid>
      <dc:creator>tf_jbassford</dc:creator>
      <dc:date>2015-11-03T02:35:39Z</dc:date>
    </item>
  </channel>
</rss>

