Commands Disabled in FIPS Mode

The device in FIPS mode does not support the following commands:
  • enable password-display
  • enable strict-password-enforcement
    Note: Strict password enforcement is enabled by default when the device is in FIPS mode and it cannot be disabled. The password must be at least eight characters long.
  • web-management allow-no-password
  • telnet server
  • ip ssh scp disable
  • ip ssh key-authentication no
  • ip ssh permit-empty-passwd yes
  • web-management http
  • ip ssh encryption disable-aes-cbc

A device in FIPS mode does not support TFTP commands, including:

  • copy tftp flash ip
  • boot system tftp ip file
  • ip ssh pub-key-file tftp ip {file | pubkey}
  • ip ssl certificate-data-file tftp ip file
  • ip ssl private-key file tftp tftp ip file

The following JITC command is not supported because JITC is disabled by default in FIPS mode:

  • jitc enable