Modifying the Common Criteria Policies to Use Non-encrypted AAA Servers

If required, you can modify the Common Criteria policies to allow AAA servers that do not use TLS encryption to be configured, such as RADIUS servers. When non-encrypted AAA servers are allowed, you cannot configure TLS-encrypted TACACS+ servers on the device.
Note: Modifying the default Common Criteria policy makes the device noncompliant with Common Criteria standards.

To allow any AAA server to work with the device in Common Criteria mode, enter the following command:

device# fips policy allow common-criteria aaa-server-any

Syntax: [no] fips policy allow common-criteria aaa-server-any

Use the [no] form of the command to remove non-encrypted AAA servers. If any non-encrypted AAA servers were available on the device, they are removed when Common Criteria mode is enabled on the device.