<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Canada on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/canada/</link><description>Recent content in Canada on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><lastBuildDate>Sat, 26 Oct 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://lesitedefrancois.be/en/tags/canada/index.xml" rel="self" type="application/rss+xml"/><item><title>Montréal &amp; Ottawa</title><link>https://lesitedefrancois.be/en/voyages/amerique/montreal-ottawa/</link><pubDate>Sat, 26 Oct 2024 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/voyages/amerique/montreal-ottawa/</guid><description>A city trip between two Canadian capitals: the cobblestone streets of Old Montréal, the train to Ottawa and Parliament Hill. Bonus: a giant spider and a UNESCO-listed canal.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://lesitedefrancois.be/voyages/amerique/montreal-ottawa/featured.jpeg"/></item><item><title>FIPS 140-2 / FIPS 140-3</title><link>https://lesitedefrancois.be/en/compliance/fips-140/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/fips-140/</guid><description>&lt;p&gt;&lt;strong&gt;FIPS 140&lt;/strong&gt; (Federal Information Processing Standard, Publication 140) is the US and Canadian government standard that defines security requirements for cryptographic modules — the hardware, software, or firmware components that perform cryptographic operations (encryption, decryption, hashing, signing, key management). It is published by &lt;strong&gt;NIST&lt;/strong&gt; (National Institute of Standards and Technology) and jointly administered with &lt;strong&gt;CCCS&lt;/strong&gt; (Canadian Centre for Cyber Security) through the &lt;strong&gt;Cryptographic Module Validation Program (CMVP)&lt;/strong&gt;. The standard has two active versions: &lt;strong&gt;FIPS 140-2&lt;/strong&gt; (published 2001, no longer accepting new submissions since April 2022) and &lt;strong&gt;FIPS 140-3&lt;/strong&gt; (effective September 2020, the current standard for all new validations). FIPS 140-2 certificates remain valid until &lt;strong&gt;21 September 2026&lt;/strong&gt;, after which they move to the Historical list — meaning only FIPS 140-3 validated modules will be accepted for new federal procurements. FIPS 140 defines four security levels (Level 1 through Level 4), with Level 1 being the baseline for software modules and Level 4 requiring physical tamper-active hardware. Compliance is &lt;strong&gt;mandatory&lt;/strong&gt; for all US federal agencies and their contractors under FISMA, for Canadian federal systems, and is widely adopted by regulated industries (finance, healthcare, critical infrastructure) globally. Non-validated cryptography is treated as providing &lt;strong&gt;no protection&lt;/strong&gt; — effectively plaintext — regardless of the algorithm strength. Validation is a formal, lab-based process: vendors submit modules to accredited Cryptographic and Security Testing (CST) laboratories, which test against the standard and submit results to CMVP for certificate issuance.&lt;/p&gt;</description></item></channel></rss>