SSHv2
Secure Shell version 2 (SSHv2) is allowed in FIPS mode.
The following SSH commands are affected when the FastIron device is in FIPS mode:
- The
ip ssh encryption aes-onlycommand is disabled. - The
ip ssh key-authentication nocommand is disabled. - The
ip ssh permit-empty-passwdcommand is disabled. - The
ip ssh pub-key-file tftpcommand is disabled. - The
ip ssh scpcommand ensures that SCP is enabled to run in FIPS mode. SCP is needed for file communication and theip ssh scp disablecommand is disabled in FIPS mode and displays the following message:FIPS Compliance: SCP needs to be enabled
- The
crypto key zeroizecommand removes configured SSH keys.
Use the
show ip ssh config command to display SSH configuration information.
SSH key generation time is affected by the increased security of authentication and encryption algorithms both in and out of FIPS mode.