Downgrading from Common Criteria Mode to Non-FIPS Mode
Downgrading a device from Common Criteria mode either to FIPS mode or to non-FIPS
mode uses the same command. You cannot directly downgrade to FIPS mode. You must first
downgrade to non-FIPS mode and then enable FIPS mode using the procedures detailed
in the previous chapter.
After the device is placed in non-FIPS mode, you can use SCP to download and initialize an older image. Use the following steps to revert to a non-FIPS-compliant image.
- Log in to the device by entering your username and password.
- Disable Common Criteria mode by entering the
no fips enableorno fips enable common-criteriacommand. - Regenerate SSH host keys or other shared secrets as needed for access after reload.
- To replace the startup configuration with the
no fips enableconfiguration, enter thewrite memorycommand. - Reload the configuration by entering the
reloadcommand.