How is data secured in Unified Workspace

How is data secured in Unified Workspace

Some customers have asked if Unified Workspace is FIPS Certified and specifically FIPS 140-2.  Being FIPS  certified means that your software uses FIPS  certified cryptographic modules and has been verified by one of the approved NIST laboratories.  UW uses many different packages from many different companies and open source groups and each customer had different needs and configurations which may or may not need certain ciphers and protocols enabled/disabled that may go against the FIPS certification / compliancy.  Some packages that UW implements is FIPS compliant, for example,  OPENSSL 


We are providing information on the various parts of the product and what type of encryption is used.
  1. Customer to Unified Workspace Relay - SSL/TLS (when SSL is enabled)
  2. UW Relay to UW Server - SSL/TLS
  3. Lockboxes - AES-256
  4. UW Server to Directory Services - SSL/TLS (when configured to use SSL)
  5. UW Data stored in Directory Services - AES-256
  6. StonewareLoader.xml - Blowfish
  7. 8090 Conole - SSL/TLS (when SSL is enabled)
  8. PipeLine - SSL/TLS
  9. UW Relay to 3rd party web service - Uses whatever encryption the 3rd part web service uses/requires
  10. Session Information - AES-256
  11. Relay Central - Not currently encrypted between UW Relay to UW Relay