The purpose of this policy is to provide guidance that limits the use of encryption to those algorithms that have received substantial public review and have been proven to work effectively. Additionally, this policy provides direction to ensure that federal regulations are followed and legal authority is granted for the dissemination and use of encryption technologies outside of the United States.
This policy applies to all McNeese State University employees and affiliates.
| Algorithm | Key Length (min) | Additional Comment |
| ECDSA | P-256 | Consider RFC6090 to avoid patent infringement. |
| RSA | 2048 | Must use a secure padding scheme. PKCS#7 padding scheme is recommended. Message hashing required. |
| LDWM | SHA256 | Refer to LDWM Hash-based Signatures Draft |
In general, McNeese State University adheres to the NIST Policy on Hash Functions.
The Office of Information Technology will verify compliance to this policy through various methods, including but not limited to, business tool reports, internal and external audits, and feedback to the policy owner.
Any exception to the policy must be approved by the Office of Information Technology in advance.
An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
This policy is distributed via Senior Staff and the University Policies webpage.