إشعار
يتطلب الوصول إلى هذه الصفحة تخويلاً. يمكنك محاولة تسجيل الدخول أو تغيير الدلائل.
يتطلب الوصول إلى هذه الصفحة تخويلاً. يمكنك محاولة تغيير الدلائل.
You can configure Microsoft Information Protection SDK version 1.14 and later to use the FIPS-validated version of OpenSSL 3.0. To use the FIPS-validated OpenSSL 3.0 module, install and load the FIPS module.
FIPS 140-2 compliance
The Microsoft Information Protection SDK uses OpenSSL to implement all cryptographic operations. OpenSSL isn't FIPS compliant without more configuration by the developer. To develop a FIPS 140-2 compliant application, configure OpenSSL in the MIP SDK to load the FIPS module to perform cryptographic operations instead of the default OpenSSL ciphers.
Install and configure the FIPS module
Applications that use OpenSSL can install and load the FIPS module with the following procedure published by OpenSSL:
- Install the FIPS module by following Appendix A: Installation and Usage Guidance.
- Load the FIPS module in MIP SDK by making all applications use the FIPS module by default. Configure the OpenSSL_MODULES environment variable to the directory containing
fips.dll. - (Optional) Configure the FIPS module for some applications only by selectively making applications use the FIPS module by default.
When the FIPS module is successfully loaded, the MIP SDK log declares FIPS as the OpenSSL provider.
"OpenSSL provider loaded: [fips]"
If installation fails, the OpenSSL provider remains default.
"OpenSSL provider loaded: [default]"
Limitations of MIP SDK with FIPS 140-2 validated ciphers:
- Android and iOS are not supported. The FIPS module is available on Windows, Linux, and Mac.
TLS requirements
MIP SDK prohibits TLS versions before 1.2 unless the connection is made to an Active Directory Rights Management server.
Cryptographic algorithms in MIP SDK
| Algorithm | Key length | Mode | Comment |
|---|---|---|---|
| AES | 128, 192, 256-bit | ECB, CBC | MIP SDK protects content with AES256 CBC by default. Legacy versions of Office (2010) require AES 128 ECB, and Office apps still protect Office documents this way. |
| RSA | 2048-bit | n/a | Signs and protects the session key that protects a symmetric key blob. |
| SHA-1 | n/a | n/a | Validates signatures for legacy publishing licenses. |
| SHA-256 | n/a | n/a | Validates data and signatures and functions as database keys. |
Next steps
For details on the internals and specifics of how Microsoft Purview Information Protection protects content, see the following documentation: