Refine your search:

Is splunk FIPS 140-2 compliant?

asked 12 Jan '11, 19:27

matt's gravatar image

matt ♦♦
3.9k161947
accept rate: 79%


2 Answers:

Splunk Enterprise 6 includes an OpenSSL FIPS module; see About FIPS in the Securing Splunk manual.

Note that upgrading a non-FIPS install to FIPS is not supported by Splunk – you must decide to use FIPS when your first install the product.

link

answered 16 Oct '13, 12:35

ChrisG's gravatar image

ChrisG ♦
5.4k58
accept rate: 25%

Splunk (the software) has not been submitted for FIPS 140-2 accreditation. At this time, there are no plans that I am aware of to engage in the accreditation process.

Splunk uses OpenSSL shared libraries for all encryption, and according to openssl.org, OpenSSL will never be FIPS-140-2 validated/accredited:

http://www.openssl.org/docs/fips/fipsnotes.html

Furthermore, Splunk does not use the OpenSSL FIPS Object Model, which has been uniquely validated as FIPS-140-2 compliant. At this time, we do not anticipate moving to the OpenSSL FIPS Object Model because of compatibility and portability reasons.

link

answered 12 Jan '11, 20:23

araitz's gravatar image

araitz ♦
8.3k51030
accept rate: 45%

edited 13 Jan '11, 00:02

Hi Araitz, could you explain more detail about "we do not anticipate moving to the OpenSSL FIPS Object Model because of compatibility and portability reasons" ? thanks

(12 May '11, 01:19) dmlee
1

This answer was indeed correct when provided in 2011 for Splunk 4.x.

(09 Jun, 18:08) jrodman ♦
Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×184
×1

Asked: 12 Jan '11, 19:27

Seen: 1,835 times

Last updated: 09 Jun, 18:08

Copyright © 2005-2014 Splunk Inc. All rights reserved.