Image Verification in FIPS or CC Mode

For a FIPS- or CC-enabled device running FastIron 08.0.10 or later, uploading a flash or boot code triggers a FIPS Integrity Qualification test that performs a digital signature verification of the flash or boot code using a signature file. In earlier FastIron versions, the test is triggered only when the FIPS- or CC-enabled device boots.
  • FIPS devices running FastIron 08.0.10 or later support the digital signature files generated using the SHA-256/RSA-2048 algorithm.
  • FastIron versions earlier than 08.0.10 in FIPS or CC mode support the digital signature files generated using the SHA-1/DSA-1024 algorithm.

Verifying the Currently Active Software Version

Use the show version command to check the active software version on a FastIron device. The following example displays the current software version of an ICX 7850 as version 08.0.95 and provides additional details on the image file and the modules installed in the device.

  Copyright (c) Ruckus Networks, Inc. All rights reserved.
    UNIT 1: compiled on Aug 13 2020 at 03:40:24 labeled as TNR08095
      (63863960 bytes) from Primary TNR08095.bin (UFI)
        SW: Version 08.0.95T233 
      Compressed Primary Boot Code size = 1573376, Version:10.1.18T235 (tnu10118)
       Compiled on Mon Jul 13 08:53:53 2020

  HW: Stackable ICX7650-48F
==========================================================================
UNIT 1: SL 1: ICX7650-48F-L3-PREM 48-port Management Module
      Serial  #:EZE3324N011
      Software Package: ICX7650_L3_SOFT_PACKAGE   (LID: gbgIIHJpFGG)
      Current License: l3-prem  
      P-ASIC  0: type B568, rev 11  Chip BCM56568_B0
==========================================================================
UNIT 1: SL 2: ICX7600-2X40GQ 2-port 80G Module
      Serial  #:EZG3320N04M
==========================================================================
UNIT 1: SL 3: ICX7650-2X100G 2-port 200G Module
==========================================================================
 2000 MHz ARMv8 Cortex-A57 processor 88 MHz bus
    8 MB boot flash memory
    2 GB code flash memory
--More--, next page: Space, next line: Return key, quit: Control-c
SYSLOG: <14> Jan 12 18:57:08 CLI CMD: "show version" by un-authenticated user from console 
    4 GB DRAM
STACKID 1  system uptime is 151 day(s) 23 hour(s) 46 minute(s) 45 second(s) 
The system started at 09:37:31 GMT+00 Fri Aug 14 2020

The system : started=warm start   reloaded=by "reload"

Checking the Inactive Software Version in Secondary Storage

Use the show flash command to verify the version of the inactive image loaded in secondary flash. The show flash command displays the image version for both primary and secondary flash partitions as shown in the following example.

Device# show flash
Stack unit 1:
  Compressed Pri Code size = 63863960, Version:08.0.95T233 (TNR08095.bin)
  Compressed Sec Code size = 63865696, Version:08.0.95T233 (TNR08095.bin)
  Compressed Pri Boot Code size = 1573376, Version:10.1.18T235 (tnu10118)
  Compressed Sec Boot Code size = 1573376, Version:10.1.18T235 (tnu10118)
  Code Flash Free Space = 2637774848