Enabling FIPS Mode
- Attach a management station (PC or terminal) to the management module serial (console)
port using a serial cable.
When the device is not in a console session, FIPS-related commands return errors.
- Verify that the device is in non-FIPS mode by using the
fips showcommand.device(config)# fips show
The
fips showcommand lists the current configuration of the device and can be run in both FIPS mode and non-FIPS modes to establish whether the device is truly in FIPS mode.The output of the
fips showcommand confirms that the device is in FIPS mode and identifies the device as either administratively or operationally in FIPS mode.Note: If the FastIron device is in JITC mode, then you cannot enable FIPS on the device.The following example shows the output of the
fips showcommand before thefips enablecommand is entered. Administrative status and operational status are off.device(config)# fips show FIPS mode: Administrative Status: OFF, Operational Status: OFF
If the device is already in administrative FIPS mode, you can modify the FIPS policy. Refer to Modifying the FIPS policy.
- Use the
fips enablecommand to place the device administratively in FIPS mode.device(config)# fips enable
The following example shows sample output of the
fips enablecommand.Note: Beginning with FastIron 08.0.20a, the RSA key pair is deleted when the FIPS mode is enabled. Use thecrypto key generatecommand to generate the RSA key once the device is in FIPS mode.device(config)# fips enable All keys incompatible with FIPS 140-2 standard will be deleted. RSA Key pair not found RSA client Key pair not found This device is now running in FIPS administrative mode. At this time you can alter this system's FIPS default security policy and then enter FIPS operational mode. Note: Making changes to the default FIPS security policy weakens the security of the device and makes the device non-compliant with FIPS 140-2 Level 1 The default security policy defined in the FIPS Security Policy Document ensures that the device complies with all FIPS 140-2 specifications. Commands to alter the default security policy are available to the crypto-officer; however, Ruckus does not recommend making changes to the default security policy at any time. ===================================== To enter FIPS mode, complete the following steps: 1. Install the signature file now if not already done. Failure to install signature or wrong signature file can cause continuous resets. Also, optionally, configure FIPS policy commands that meets your network requirements. You must explicitly configure the following services if you want to use them when the device is operational in FIPS mode: FIPS: SCP is already enabled - Allow TFTP access. Current status: Enabled - Allow SNMP Access to the Critical Security Parameter (CSP) MIB objects. Current status : Disabled - Allow access to all commands within the monitor mode. Current status: Enabled - Retention of shared secret keys for all protocols and the host passwords. Current status: Clear - Retention of SSH DSA host keys. Current status: Clear - Retention of SSH RSA host keys and HTTPS certificate. Current status: Clear 2. Enter the "fips zeroize all" command, which zeroes out the shared secrets used by various networking protocols, including the host access passwords, SSH and HTTPS host-keys with the digital signature based on the configured FIPS Security Policy. 3. Save the running configuration. 4. Reload the device. 5. Do not press "b" during reload, else FIPS or CC will not be enabled properly. 6. Enter the "fips show" command to verify that the device entered FIPS or CC operational mode. ===================================== The system will disable the following services or commands after reload: 1. Telnet server will be disabled. The "telnet server" command will be removed. 2. SCP will be enabled. The "ip ssh scp disable" command will be removed. 3. HTTP server will be disabled. The "web-management http" command will be removed. 4. HTTPS server will change as follows: -SSL 3.0 will be disabled. -TLS version 1.0 and greater will be used. -RC4 cipher will be disabled. -Passwords will be required; the "web-management allow-no-password" command will be removed. 5. SNMP server will change as follows: -SNMP support for v1 and v2 versions will be disabled. -For SNMPv3 version md5 key and DES privacy password will be disabled. 6. NTP md5 authentication will be diabled. Passwords/Keys which dont comply FIPS standards will be removed on reload. Please see FIPS config guide for complete details.
- You can verify the status of the device as administratively in FIPS mode by using
the
fips showcommand.The following example shows the output of thefips showcommand on a FastIron device after thefips enablecommand is entered and administrative status is on and operational status is off:The following example shows the output of the
fips showcommand on a CER devices after the fips enable command is entered and administrative status is on and operational status is off:device# fips show Cryptographic Module Version: BRCD-IP-CRYPTO-VER-4.0 FIPS mode: Administrative status ON: Operational status OFF Common-Criteria: Administrative status OFF: Operational status OFF System Specific OS monitor access status is: Disabled Management Protocol Specific: Telnet server: Disabled Telnet client: Disabled TFTP client: Disabled HTTPS SSL 3.0: Disabled SNMP Access to security objects: Disabled Critical security Parameter updates across FIPS boundary: Protocol Shared secret and host passwords: Clear Password Display: Disabled HTTPS RSA Host Keys and Signature: Clear SSH DSA Host keys: Clear SSH RSA Host keys: Clear