Features Unavailable in FIPS and Common Criteria Mode
Some of the security features are disabled
in FIPS/CC mode:
- SSHv2: Host and client key generation methods using DSA and the RSA-1024 key size are not supported (only RSA 2048 and higher key sizes are supported). Therefore, the following commands are not supported:
- TLS: The RSA 1024 key size for SSL or TLS private key generation is not supported. (FastIron devices support only 2048 and above key sizes.)
- SSH key exchange: The SSH key exchange method diffie-hellman-group1-sha1 and diffie-hellman-group14-sha1 are not supported. Only the following SSH key exchange methods are supported: