August 31, 2012

NIST seeking comments on FIPS 140-3 draft

Here is the link to the latest FIPS 140-3 draft:   http://csrc.nist.gov/news_events/index.html#august30

Comments are requested on or before October 1, 2012.

NIST plans to address all public comments in the 2nd Quarter of 2013.  The updated FIPS 140-3 Development Status information is here:  http://csrc.nist.gov/groups/ST/FIPS140_3/


August 30, 2012

CMVP review times currently in the 4-6 month range

InfoGard's Quality Manager informed me that CMVP review times have slipped to the 4 to 6 month range for FIPS reports this summer.  We believe the reasons for the summer slow-down are due to CMVP vacations, new Implementation Guidance, and a surge in report submissions by Labs in the spring.

When selecting a FIPS Laboratory for your next FIPS project, make sure to ask about the Lab's report review process prior to submission.  InfoGard has a deliberate review process involving an independent technical review by a FIPS Security Engineer, a Quality review, a Signatory review, and then a final quick Quality check at the end.  This is our secret sauce for delivering high-quality reports to the CMVP.  Clear, consistent, and compliant reports are easily reviewed by the CMVP allowing you to reach your product sales goals sooner.

August 29, 2012

InfoGard first to reach 500 FIPS certs!

We like reasons to celebrate at InfoGard and we thank our customers for allowing us to achieve this milestone.

Earlier this month, InfoGard became the first FIPS 140-2 testing laboratory to pass the 500 FIPS Certificates mark!  That's 28% of the total during the lifetime of the program.  Thank you, InfoGard Customers, for trusting us with your FIPS 140-2 projects.

May 3, 2012

FIPS 140-2 Implementation Guidance updated (again)


The CMVP has been busy updating the FIPS 140-2 Implementation Guidance.  If you delayed reviewing the April update, then delay no further.  The May update deserves your attention.

See the May 2, 2012 document and changes here:  http://csrc.nist.gov/groups/STM/cmvp/announcements.html

Note:  You may need to clear your browser's cache to open the latest IG document.

March 26, 2012

InfoGard featured in local newspaper

InfoGard Laboratories was featured in San Luis Obispo's local newspaper.  The Tribune published the article on Saturday, March 24.  A short version of the article may be read here:

http://www.sanluisobispo.com/2012/03/23/2002514/infogard-laboratories.html

March 6, 2012

FIPS 180-4 published

NIST published FIPS 180-4 Secure Hash Standard (SHS).

The updates from FIPS 180-3 are listed in Appendix C of the new FIPS 180-4 publication.  In short, the changes are:
  1. FIPS 180-4 relaxes the padding restriction described in FIPS 180-3
  2. SHA-512/224 and SHA-512/256 were added to the standard

January 20, 2012

FIPS 140-2 Consolidated Validation Certificates

Q:  How long does it take for a recently validated cryptographic module to appear on a FIPS 140-2 Consolidated Validation Certificate?

A:  At the end of each month, the CMVP generates a list of cryptographic modules that were issued new FIPS 140-2 certificates.  The Consolidated Validation Certificate is signed by a NIST representative in the United States and then routed to Canada for signature by a CSEC representative.  The signature and posting process takes about two weeks. 

For example, modules that received a certificate number in the month of January will appear on the FIPS 140-2 Consolidated Validation Certificate that gets posted mid-February.