Modifying the Common Criteria Policies to Use Non-encrypted AAA Servers
If required, you can modify the Common Criteria policies to allow AAA servers that
do not use TLS encryption to be configured, such as RADIUS servers. When non-encrypted
AAA servers are allowed, you cannot configure TLS-encrypted TACACS+ servers on the
device.
Note: Modifying the default Common Criteria policy makes the device noncompliant with Common
Criteria standards.
To allow any AAA server to work with the device in Common Criteria mode, enter the following command:
device# fips policy allow common-criteria aaa-server-any
Syntax: [no] fips policy allow common-criteria aaa-server-any
Use the
[no] form of the command to remove non-encrypted AAA servers. If any non-encrypted AAA
servers were available on the device, they are removed when Common Criteria mode is
enabled on the device.