Entering Common Criteria Administrative Mode
Use the following command to enter Common Criteria mode.
device(config)# fips enable common-criteria
Syntax: [no] fips enable common-criteria
The following example includes the detailed banner that is displayed after you enter the command.
device(config)# fips enable common-criteria
All keys incompatible with FIPS 140-2 standard will be deleted.
RSA Key pair not found
RSA Client Key pair is successfully deleted
This device is now running in CC administrative mode.
At this time you can alter this system's CC default security policy
and then enter CC operational mode.
Note: Making changes to the default policy makes the device non-compliant
with CC and FIPS 140-2 Level 1
The default security policy defined in the FIPS
Security Policy Document ensures that the device complies with all
FIPS 140-2 specifications. Commands to alter the default security policy
are available to the crypto-officer; however, Ruckus does not recommend
making changes to the default security policy at any time.
=====================================
To enter CC mode, complete the following steps:
1. Optionally, configure FIPS policy commands that meets your network
requirements. You must explicitly configure the following services if you want to use them when the device is operational in CC mode:
Note: ip ssl client continues to be in enabled mode if enabled
FIPS: SCP is already enabled
- Allow TFTP access.
Current status: Enabled
- Allow SNMP Access to the Critical Security Parameter (CSP) MIB objects.
Current status : Disabled
- Allow access to all commands within the monitor mode.
Current status: Enabled
- Retention of shared secret keys for all protocols and the host passwords.
Current status: Clear
- Retention of SSH DSA host keys.
Current status: Clear
- Retention of SSH RSA host keys and HTTPS certificate.
Current status: Clear
2. Enter the "fips zeroize all" command, which zeroes out the shared secrets
used by various networking protocols, including the host access passwords,
SSH and HTTPS host-keys with the digital signature based on the configured
FIPS Security Policy. If SSH ReKey Exchange value was not configured then
the default value of 30Mins and 500MB will be configured
3. Save the running configuration.
4. Reload the device.
5. Do not press "b" during reload, else FIPS or CC will not be enabled properly.
6. Enter the "fips show" command to verify that the device entered
FIPS or CC operational mode.
=====================================
The system will disable the following services or commands after reload:
1. Telnet server will be disabled. The "telnet server" command will be removed.
2. SCP will be enabled. The "ip ssh scp disable" command will be removed.
3. HTTP server will be disabled. The "web-management http" command will be removed.
4. HTTPS server will be disabled. The "web-management https" command will be removed.
Passwords/Keys which dont comply FIPS standards will be removed on reload.
aaa authentication method must be configured.
Disabling user when invalid password is entered is default in FIPS and above modes.
Default value of login recovery time is 3 secs.
No command sets the login recovery time to 3 secs and disables the user after 3 invalid attempts.
Default values of 3 attempts and 3 secs are not displayed in running config.
Please see FIPS config guide for complete details.
=====================================
Additionally, in CC mode, the system will disable the following
services or commands after reload:
UDP Syslog servers will be deleted from configuration(only in the CC operational mode).
DSA keys will be deleted from configuration, and will be disabled .
RSA key sizes will be restricted to 2048 and above in the configuration.
Non-TLS TACACS+ servers will be disabled from configuration.
For SSH Key Exchange, only diffie-hellman-group14 algorithm is allowed.
Note: ip ssl client continues to be in enabled mode if enabled All keys incompatible with FIPS 140-2 standard will be deleted. RSA Key pair not found RSA client Key pair not found This device is now running in CC administrative mode. At this time you can alter this system's CC default security policy and then enter CC operational mode. Note: Making changes to the default policy makes the device non-compliant with CC and FIPS 140-2 Level 2, design assurance Level 3 The default security policy defined in the FIPS Security Policy Document ensures that the device complies with all FIPS 140-2 specifications. Commands to alter the default security policy are available to the crypto-officer; however, Ruckus does not recommend making changes to the default security policy at any time. ===================================== To enter CC mode, complete the following steps: 1. Optionally, configure FIPS policy commands that meets your network requirements. You must explicitly configure the following services if you want to use them when the device is operational in CC mode: FIPS: SCP is already enabled - Allow TFTP access. Current status: Disabled - Allow SNMP Access to the Critical Security Parameter (CSP) MIB objects. Current status : Disabled - Allow access to all commands within the monitor mode. Current status: Disabled - Retention of shared secret keys for all protocols and the host passwords. Current status: Clear - Retention of SSH DSA host keys. Current status: Clear - Retention of SSH RSA host keys and HTTPS certificate. Current status: Clear 2. Enter the "fips zeroize all" command, which zeroes out the shared secrets used by various networking protocols, including the host access passwords, SSH and HTTPS host-keys with the digital signature based on the configured FIPS Security Policy. 3. Save the running configuration. 4. Reload the device. 5. Do not press "b" during reload, else FIPS or CC will not be enabled properly. 6. Enter the "fips show" command to verify that the device entered FIPS or CC operational mode. ===================================== The system will disable the following services or commands after reload: 1. Telnet server will be disabled. The "telnet server" command will be removed. 2. SCP will be enabled. The "ip ssh scp disable" command will be removed. 3. HTTP server will be disabled. The "web-management http" command will be removed. 4. HTTPS server will be disabled. ************************************* ************************************* 5. aaa authentication method must be configured. 6. Disabling user when invalid password is entered is default in FIPS and above modes. 7. Default value of login recovery time is 3 secs. No command sets the login recovery time to 3 secs and disables the user after 3 invalid attempts. Default values of 3 attempts and 3 secs are not displayed in running config. ************************************ ************************************ ===================================== Additionally, in CC mode, the system will disable the following services or commands after reload: UDP Syslog servers will be deleted from configuration(only in the CC operational mode). DSA keys will be deleted from configuration, and will be disabled . RSA key sizes will be restricted to 2048 and above in the configuration. Non-TLS TACACS+ servers will be disabled from configuration.