Image Verification in Korean CC Mode

For a Korean CC-enabled device running FastIron 10.0.10g_cd1 or later, uploading flash or boot code triggers a Validation test that performs a digital signature verification of the flash or boot code using a signature file.

Korean CC devices running FastIron 10.0.10g_cd1 or later support the digital signature files generated using the SHA-256/RSA-2048 algorithm.

After you have enabled Korean Common Criteria operational mode by reloading the device, enter the fips show command to verify the operational mode status:

device# fips show
Cryptographic Module Version: FI-IP-CRYPTO
FIPS mode: Administrative status ON: Operational status ON
Common-Criteria: Administrative status ON: Operational status ON
Korean CC: Administrative status ON: Operational status ON
SW Version: 10.0.10

System Specific:
OS monitor access status is: Disabled

Management Protocol Specific:
Telnet server: Disabled
Telnet client: Disabled
TFTP client: Disabled
SNMP Access to security objects: Disabled

Critical security Parameter updates across FIPS boundary:
Protocol Shared secret and host passwords: Clear
Password Display: Disabled

Certificate Specific:
HTTPS RSA Host Keys and Signature: Clear
SSH DSA Host keys: Clear
SSH RSA Host keys: Clear
CC Enable AAA Server Any: Clear
Korean CC UDP RADIUS Server Access: Clear

Verifying the Currently Active Software Version

Use the show version command to check the active FastIron software version on a RUCKUS ICX device. The following example displays the current software version of an ICX 7550 as version 10.0.10g and provides additional details on the image file and the modules installed in the device.

device# show version
  Copyright (c) Ruckus Networks, Inc. All rights reserved.
    UNIT 1: compiled on Apr  3 2025 at 02:57:29 labeled as TNR10010g_kcc639
      (66823948 bytes) from Primary TNR10010g_cd1_kcc63.bin (UFI)
        SW: Version 10.0.10g_cd1_kcc639T233
      Compressed Primary Boot Code size = 1573376, Version:10.2.11T235 (tnu10211)
       Compiled on Tue Mar 18 06:13:22 2025

  HW: Stackable ICX7550-HPOE
==========================================================================
UNIT 1: SL 1: ICX7550-L3-BASE POE 48-port Management Module
      Serial  #:EZD3341M01H
      Software Package: ICX7550_L3_SOFT_PACKAGE
      Current License: l3-prem
      P-ASIC  0: type B567, rev 11  Chip BCM56567_B0
==========================================================================
UNIT 1: SL 2: ICX7500-2X40GQ 2-port 80G Module
      Serial  #:EZG3339M004
==========================================================================
UNIT 1: SL 3: ICX7550-2X100G 2-port 200G Module
==========================================================================
 1600 MHz ARMv8 Cortex-A57 processor 88 MHz bus
    8 MB boot flash memory
    2 GB code flash memory
    4 GB DRAM
STACKID 1  system uptime is 2 day(s) 22 hour(s) 9 minute(s) 57 second(s)
The system started at 06:03:22 GMT+00 Fri Apr 04 2025

The system : started=warm start   reloaded=by "reload"
  

Checking the Inactive Software Version in Secondary Storage

Use the show flash command to verify the version of the inactive image loaded in secondary flash. The show flash command displays the image version for both primary and secondary flash partitions as shown in the following example.

device# show flash
Stack unit 1:
  Compressed Pri Code size = 66823948, Version:10.0.10gT233 (TNR10010g_cd1_kcc63.bin)
  Compressed Sec Code size = 69719480, Version:10.0.10gT233 (TNR10010g_cd1dev.bin)
  Compressed Pri Boot Code size = 1573376, Version:10.2.11T235 (tnu10211)
  Compressed Sec Boot Code size = 1573376, Version:10.2.11T235 (tnu10211)
  Code Flash Free Space = 1812471808