Downgrading from FIPS to Non-FIPS Mode

While a FIPS-supported image is running on the device, at any time the image can be running in FIPS or non-FIPS operational mode. To change from FIPS mode to non-FIPS mode, you must copy the signature file.
Downgrading from FIPS mode to non-FIPS mode clears all shared secrets, host passwords, SSH and HTTPS host keys and HTTPS certificates.
Note: Before upgrading or downgrading a major software version, zeroize the keys by executing the crypto key zeroize command.
Note: Once FIPS mode is enabled on the system, even if the mode is disabled later, a firmware integrity test will always be carried out on the device when the image is copied.

To place a device in non-FIPS mode, complete the following steps.

  1. Log in to the device by entering your user name and password.
  2. Zeroize all the keys by executing crypto key zeroize command.
    device# crypto key zeroize
    
  3. Disable FIPS by entering the no fips enable or no fips enable common-criteria command at the prompt.
    device# no fips enable
    
  4. Copy the desired application image and signature file with TFPT or SCP copy.
    The following example uses TFTP to copy the FastIron 08.0.95 UFI image and signature files to primary flash.
    $ copy tftp flash 10.1.1.11 TNR08095ufi.bin primary
    $ copy tftp flash 10.1.1.11 TNR08095ufi.sig fips-primary-sig
    
    Syntax:copy tftp flaship-addrimage-nameprimary |secondary

    Syntax:copy tftp flaship-addrsignature-namefips-primary-sig|fips-secondary-sig

    The following example uses SCP to copy the FastIron 08.0.95 UFI image and signature files to primary flash.
    $ scp TNR08095ufi.bin test@10.1.1.11:flash:primary:TNR08095ufi.bin
    $ scp TNR08095ufi.sig test@10.1.1.11:file:primary.sig
    
    Syntax:scpsource-image-name@ip-addr:flash:primary |secondary:target-image-name

    Syntax:scpsource-signature-name@ip-addr:file:target-signature-name

  5. Enter the write memory command to save the changes.
    device# write memory
  6. Reload the configuration by entering the reload command.
    device# reload

Once the switch is rebooted, refer to Placing the device in FIPS mode to enable FIPS.