Downgrading from FIPS to Non-FIPS Mode

Once the ICX device is enabled for FIPS, it remains enabled internally, so that the signature file must be copied first whenever the image is copied.

Once you have downgraded to non-FIPS mode, you must still load the relevant signature (.sig) file before the image (.bin) file every time you upgrade or downgrade an image in the future. This prevents the ICX device from looping.

Downgrading from FIPS mode to non-FIPS mode clears all shared secrets, host passwords, SSH and TLS host keys, and TLS certificates.

Note: Before upgrading or downgrading a major software version, zeroize the keys by executing the crypto key zeroize command.
Note: Once FIPS mode is enabled on the system, even if the mode is disabled later, a firmware integrity test will always be carried out on the device when the image is copied.

The steps to place a device in non-FIPS mode can be summarized as follows.

Downgrade to non-FIPS Mode Using the Existing Image:

  1. Zeroize all keys using the crypto key zeroize command.
  2. Disable FIPS with the no fips enable command.
  3. Save the configuration with the write memory command.
  4. Reload the configuration with the reload command.

Downgrade to non-FIPS Mode with SCP Using a New Image

  1. While in FIPS mode, copy the signature file and image file using SCP.
  2. Zeroize all keys using the crypto key zeroize command.
  3. Disable FIPS with the no fips enable command.
  4. Save the configuration with the write memory command.
  5. Reload the configuration with the reload command.

Downgrade to non-FIPS Mode with FTP Using a New Image

  1. Zeroize all keys using the crypto key zeroize command.
  2. Disable FIPS with the no fips enable command.
  3. Enable TFTP with the no tftp disable command.
  4. Copy the signature file and image file using TFTP.

    The following example uses TFTP to copy the FastIron 10.0.10d UFI signature file to the primary and secondary flash of an ICX 7150 device.

    ICX7150# copy tftp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-primary-sig
    ICX7150# copy tftp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-secondary-sig

    The following example uses TFTP to copy the FastIron 10.0.10d UFI image file to the primary and secondary flash of an ICX 7150 device.

    ICX7150# copy tftp flash 1.1.1.1 SPR10010dufi.bin primary
    ICX7150# copy tftp flash 1.1.1.1 SPR10010dufi.bin secondary
  5. Save the configuration with the write memory command.
  6. Reload the configuration with the reload command.

The following task uses SCP to downgrade from FIPS to non-FIPS using a new image.

  1. Log in to the device by entering your user name and password.
  2. While still in FIPS mode, copy the desired application image and signature file with SCP.
    The following example uses SCP to copy the FastIron 10.0.10d UFI signature file to the primary and secondary flash of an ICX 7150 device.
    ICX7150# copy scp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-primary-sig
    ICX7150# copy scp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-secondary-sig
    The following example uses SCP to copy the FastIron 10.0.10d UFI image file to the primary and secondary flash of an ICX 7150 device.
    ICX7150# copy scp flash 1.1.1.1 SPR10010dufi.bin primary
    ICX7150# copy scp flash 1.1.1.1 SPR10010dufi.bin secondary
    Syntax: copy scp flash source-ip-address signaturefileufi.sig { fips-ufi-primary-sig | fips-ufi-secondary-sig }
    Syntax: copy scp flash source-ip-address image-nameufi.bin [ primary | secondary ]
  3. Zeroize all the keys by executing crypto key zeroize command.
    device# configure terminal
    device(config)# crypto key zeroize
    
  4. Disable FIPS by entering the no fips enable or no fips enable common-criteria command at the prompt.
    device(config)# no fips enable
    device(config)# exit
    
  5. Enter the write memory command to save the changes.
    device# write memory
  6. Reload the configuration by entering the reload command.
    device# reload

Once the switch is rebooted, refer to Placing the device in FIPS mode if you want to re-enable FIPS.