Performing a FIPS Self-test

Use the FIPS self-test to verify the sanity of FIPS software.

For more information on the FIPS self-test, refer to Running FIPS self-test.

Note: During FIPS self-test, the CPU usage is high. The fips self-tests command should only be used prior to the device being placed into FIPS operational or administrative modes. Using the fips self-tests command in FIPS operational or administrative mode may result in the device rebooting as per the FIPS criteria.
  • From the Privileged EXEC level of the CLI on the console, use the fips self-tests command to verify that the FIPS Software and Firmware Integrity Test passes.

    Syntax: fips self-tests

  • The following example shows the FIPS Software and Firmware Integrity Test as passed:
device# fips self-tests
Running FIPS Power On Self Tests and Software/Firmware Integrity Test.
FIPS Power On Self Tests and Software/Firmware Integrity tests successful.
.....<output truncated>.......

If the test fails, make sure that the correct signature file was copied for the correct image file and version, and recopy as needed.

Note: The FIPS self-test must pass before the configuration is saved and the device is reloaded.