Support for NIST SP 800-131A features and directory server topologies

You must identify the behavior of directory servers in a topology that are configured to support the transition to NIST SP 800-131A.

When you use IBM® Security Verify Directory, Version 10.0.3 servers in a topology for secure communications, the following behavior is observed:

Replication topology:
In a replication topology, the supplier server and the consumer server use the most secure protocol that is set on the consumer server. For secure communications, a cipher with the highest priority in the configuration file of the consumer server that is supported by the protocol is used.
If you configure the TLS 1.2 signature and hash algorithm restrictions, the certificates on the supplier server must be signed by the signature and hash algorithm that is configured on the consumer server.
In a replication topology, you must configure the supplier server and the consumer server with the same Suite B cryptographic security level.
Distributed directory:
In a distributed directory topology, the proxy server and back-end server use the most secure protocol that is set on the back-end server. For secure communications, a cipher with the highest priority in the configuration file of the back-end server that is supported by the protocol is used.
If you configure the TLS 1.2 signature and hash algorithm restrictions, the certificates on the proxy server must be signed by the signature and hash algorithm that is configured on the back-end server.
In a distributed directory setup, you must configure the proxy server and the back-end server with the same Suite B cryptographic security level.
Pass-through authentication:
In a pass-through authentication setup, the authenticating server and pass-through server use the most secure protocol that is set on the pass-through server. For secure communications, a cipher with the highest priority in the configuration file of the pass-through server that is supported by the protocol is used.
If you configure the TLS 1.2 signature and hash algorithm restrictions, the certificates on the authenticating server must be signed by the signature and hash algorithm that is configured on the pass-through server.
In a pass-through authentication, you must configure the authenticating server and the pass-through server with the same Suite B cryptographic security level.