Disabling FIPS Mode
Note: Even after disabling FIPS mode, you should always load the signature file before loading
the software image file.
Note: If you disable FIPS mode, all local users are
removed. Removal of the last local user triggers the removal of AAA configuration
specific to local authentication.
Use the
no fips enable command to disable FIPS mode on the FastIron device.
device(config)# no fips enable
After you enter the command, a warning displays that FIPS mode will be disabled.
This command performs the following policy-related operations:
- Enables TFTP access.
- Re-enables SNMP access to critical security parameter (CSP) MIB objects.
- Re-enables SNMPv3 encryption protocol DES for future SNMPv3 user configuration.
- Re-enables access to monitor mode.
- Zeroizes shared secrets, SSH and TLS host keys, and the TLS certificate based on the configured FIPS policy.
Changes to the running configuration are not saved to the startup configuration; therefore, when the device reloads, it returns to FIPS mode.
Use the
write memory command to save the running configuration.