microsoft-365-docs icon indicating copy to clipboard operation
microsoft-365-docs copied to clipboard

Needs specifics - list the FIPS validation certificate numbers

Open npherson opened this issue 2 years ago • 5 comments

Any customer with compliance requirements for FIPS encryption will have to demonstrate to an auditor that FIPS verified cryptographic modules are used. While this article lists 'Yes', it doesn't list the FIPS validation certificate number, and the Microsoft and NIST webpages listing all the certificates can't be mapped back to these features (like Office 365 Message Encryption).

Please update the FIPS validation column to include the specific certificate numbers used by that particular service.

Thanks!


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

npherson avatar Oct 06 '21 15:10 npherson

@KCCross Please help us in resolving this issue. Thanks

yogkumgit avatar Oct 11 '21 06:10 yogkumgit

Looking for the right internal owner for this.

KCCross avatar Dec 06 '21 22:12 KCCross

Any luck finding an owner? I had 2 different internal escalation threads that have failed to get an answer. While we get that there are LOTs of encryption points in connecting to exchange and whatnot, my customer is specifically looking at the FIPS number for the encryption for the message itself that we are referring to by that column.

npherson avatar Dec 14 '21 16:12 npherson

@KCCross Please update. Thanks

yogkumgit avatar Feb 18 '22 07:02 yogkumgit

@KCCross Any update I have client going thru CJIS Audit and simply showing it in the product information will not suffice for the auditor. He needs the actual certificate numbers. @npherson Did you find any info on this ?

derekateam avatar Jul 27 '22 20:07 derekateam