Reloading the Device

Note: Before upgrading to a new image in FIPS mode, ensure that the corresponding signature file is available in the flash memory.

After you have saved the configuration, reload the device using the reload command:

device# reload

Various tests, including Power-On Self Tests (POSTs) and Known Answer Tests (KATs), are run by the FastIron device during reload, during the transition between non-FIPS mode and FIPS mode.

POSTs check for the consistency of the FIPS-approved algorithms implemented on the device.

KATs are used to exercise various features of FIPS-approved algorithms.

All interfaces on the device are down until the tests are completed successfully.

Possible POST failure messages indicating that the device did not pass the tests successfully include the following messages:

Crypto module initialization and KNown Answer Test (KAT) failed with reason:(Error
Code 0x80000000)’CKR_VENDOR_DEFINED’

FIPS: Primary image verification failed

FIPS: Secondary image verification failed

If there is a failure while the POSTs are being run, the device reboots. Monitor mode can be accessed to troubleshoot the issue.

After all tests are completed successfully, the device reloads in FIPS mode and FIPS mode is successfully enabled and operational on the FastIron device.

You can verify the status of the device as operationally in FIPS mode by using the fips show command.

device(config)# fips show

The following example shows fips show command after the device reloads successfully in the default strict FIPS mode. Administrative status and operational status are on.

device# fips show
Cryptographic Module Version: BRCD-IP-CRYPTO-VER-4.0 
FIPS mode: Administrative status ON: Operational status ON
Common-Criteria: Administrative status OFF: Operational status OFF
System Specific
OS monitor access status is: Disabled

Management Protocol Specific:
Telnet server: Disabled
Telnet client: Disabled
TFTP client: Disabled
HTTPS SSL 3.0: Disabled
SNMP Access to security objects: Disabled

Critical security Parameter updates across FIPS boundary:
Protocol Shared secret and host passwords: Clear
Password Display: Disabled

HTTPS RSA Host Keys and Signature: Clear
SSH DSA Host keys: Clear
SSH RSA Host keys: Clear