Downgrading from FIPS to Non-FIPS Mode
While a FIPS-supported image is running on the device, at any time the image can be
running in FIPS or non-FIPS operational mode. To change from FIPS mode to non-FIPS
mode, you must copy the signature file.
Note: Before upgrading or downgrading a major software version, zeroize the keys by executing
the
crypto key zeroize command.
Note: Once FIPS mode is enabled on the system, even if the mode is disabled later, a firmware
integrity test will always be carried out on the device when the image is copied.
To place a device in non-FIPS mode, complete the following steps.
- Log in to the device by entering your user name and password.
- Zeroize all the keys by executing
crypto key zeroizecommand. - Disable FIPS by entering the
no fips enableorno fips enable common-criteriacommand at the prompt. - Copy the desired application image and signature file with TFPT or SCP copy.
The following example uses TFTP to copy the FastIron 08.0.95 UFI image and signature files to primary flash.
$ copy tftp flash 10.1.1.11 TNR08095ufi.bin primary $ copy tftp flash 10.1.1.11 TNR08095ufi.sig fips-primary-sig
Syntax:copy tftp flaship-addrimage-nameprimary |secondarySyntax:
copy tftp flaship-addrsignature-namefips-primary-sig|fips-secondary-sigThe following example uses SCP to copy the FastIron 08.0.95 UFI image and signature files to primary flash.$ scp TNR08095ufi.bin test@10.1.1.11:flash:primary:TNR08095ufi.bin $ scp TNR08095ufi.sig test@10.1.1.11:file:primary.sig
- Enter the
write memorycommand to save the changes. - Reload the configuration by entering the
reloadcommand.
Once the switch is rebooted, refer to Placing the device in FIPS mode to enable FIPS.