Features Unavailable in Common Criteria Mode

Some of the security features that are allowed in FIPS mode are disabled in Common Criteria mode:
  • SSHv2: Host and client key generation methods using DSA and the RSA-1024 key size are not supported (only RSA 2048 and higher key sizes are supported). Therefore, the following commands are not supported:
    • crypto key generation dsa
    • crypto key client generation dsa
    • crypto key zero dsa
    • crypto key client zero dsa
    • crypto key gen rsa modulus 1024
    • crypto key zero rsa modulus 1024
  • TLS and HTTPS: The RSA 1024 key size for SSL or TLS private key generation is not supported (FastIron devices support only 2048 and above key sizes).
  • SSH key exchange: The SSH key exchange method DiffieHellmanGroup1Sha1 is not supported. Only DiffieHellmanGroup14Sha1 is supported.
  • Web Management: Web Management is not supported.