RUCKUS FastIron FIPS and Common Criteria Configuration Guide, 08.0.90
- 1 Copyright Statement
- Preface Ruckus
- 4 About This Document
- 5 Federal Information Processing Standards
- 5.1 FIPS Overview
- 5.2 How FIPS Works
- Upgrading Software on FIPS-enabled devices
- 7 FIPS Configuration
- 7.1 User Roles in FIPS Mode
- 7.2 Commands Disabled in FIPS Mode
- 7.3 Hidden Files in FIPS Mode
- 7.4 Cryptographic Algorithms in FIPS Mode
- 7.5 SSH
- 7.6 SSH Clients
- 7.7 Usernames and SSH Public Key Authentication
- 7.7.1 Implementation
- 7.7.2 Restrictions
- 7.8 Protocol Changes in FIPS Mode
- 7.8.1 BGP
- 7.8.2 HTTP
- 7.8.3 HTTPS
- 7.8.4 IKEv2/IPsec
- 7.8.5 OSPFv2
- 7.8.6 OSPFv3
- 7.8.7 PKI
- 7.8.8 Proprietary 2-way Encryption Algorithms
- 7.8.9 RADIUS Protocol in FIPS Mode
- 7.8.10 SCP
- 7.8.11 SNMP
- 7.8.12 SSHv2
- 7.8.13 Telnet
- 7.8.14 TFTP
- 7.8.15 NTP
- 7.9 System Reset and Boot up in FIPS Mode
- 7.10 Debugging in FIPS Mode
- 7.11 Placing the Device in FIPS Mode
- 7.11.1 General Steps to Place the Device in FIPS Mode
- 7.11.2 Enabling FIPS Mode
- 7.11.3 Zeroizing Shared Secrets and Host Keys
- 7.11.4 Configuring User Authentication
- 7.11.5 Saving the Configuration
- 7.11.6 Reloading the Device
- 7.11.7 Performing a FIPS Self-test
- 7.11.8 Modifying the FIPS Policy
- 7.12 Disabling FIPS Mode
- 7.13 Running FIPS Self-tests
- 8 Common Criteria Certification
- 8.1 Common Criteria Overview
- 8.2 Enabling Common Criteria Mode
- 8.3 Encrypted Syslog Servers in Common Criteria Mode
- 8.4 AAA Servers in Common Criteria Mode
- 8.5 Downgrading from Common Criteria Mode to Non-FIPS Mode
- 8.6 Commercial Solutions for Classified program
- 8.7 Configuring NTP
- 8.8 Configuring PKI
- 8.9 Network Device Collaborative Protection Profile with VPN Gateway
- 8.10 IPsec Configuration
- 8.10.1 Configuring an IKEv2 Proposal and Policy
- 8.10.2 Configuring an IKEv2 Authentication Proposal for Use in an IPsec Profile
- 8.10.3 Configuring IPv4 and IPv6 IPsec Tunnels
- 8.10.4 IPsec SPD Rules
- 8.10.5 ACL Rules
- 8.10.5.1 Logging ACL Rules
- 9 Configuring Logging and RADIUS Server Hosts
- Syslog messages
- OpenSSL license