Downgrading from FIPS to Non-FIPS Mode
Once you have downgraded to non-FIPS mode, you must still load the relevant signature (.sig) file before the image (.bin) file every time you upgrade or downgrade an image in the future. This prevents the ICX device from looping.
Downgrading from FIPS mode to non-FIPS mode clears all shared secrets, host passwords, SSH and TLS host keys, and TLS certificates.
crypto key zeroize
command. The steps to place a device in non-FIPS mode can be summarized as follows.
Downgrade to non-FIPS Mode Using the Existing Image:
- Zeroize all keys using the
crypto key zeroizecommand. - Disable FIPS with the
no fips enablecommand. - Save the configuration with the
write memorycommand. - Reload the configuration with the
reloadcommand.
Downgrade to non-FIPS Mode with SCP Using a New Image
- While in FIPS mode, copy the signature file and image file using SCP.
- Zeroize all keys using the
crypto key zeroizecommand. - Disable FIPS with the
no fips enablecommand. - Save the configuration with the
write memorycommand. - Reload the configuration with the
reloadcommand.
Downgrade to non-FIPS Mode with FTP Using a New Image
- Zeroize all keys using the
crypto key zeroizecommand. - Disable FIPS with the
no fips enablecommand. - Enable TFTP with the
no tftp disablecommand. - Copy the signature file and image file using
TFTP.
The following example uses TFTP to copy the FastIron 10.0.10d UFI signature file to the primary and secondary flash of an ICX 7150 device.
ICX7150# copy tftp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-primary-sig ICX7150# copy tftp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-secondary-sig
The following example uses TFTP to copy the FastIron 10.0.10d UFI image file to the primary and secondary flash of an ICX 7150 device.
ICX7150# copy tftp flash 1.1.1.1 SPR10010dufi.bin primary ICX7150# copy tftp flash 1.1.1.1 SPR10010dufi.bin secondary
- Save the configuration with the
write memorycommand. - Reload the configuration with the
reloadcommand.
The following task uses SCP to downgrade from FIPS to non-FIPS using a new image.
- Log in to the device by entering your user name and password.
- While still in FIPS mode, copy
the desired application image and signature file with SCP. The following example uses SCP to copy the FastIron 10.0.10d UFI signature file to the primary and secondary flash of an ICX 7150 device.
ICX7150# copy scp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-primary-sig ICX7150# copy scp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-secondary-sig
The following example uses SCP to copy the FastIron 10.0.10d UFI image file to the primary and secondary flash of an ICX 7150 device.ICX7150# copy scp flash 1.1.1.1 SPR10010dufi.bin primary ICX7150# copy scp flash 1.1.1.1 SPR10010dufi.bin secondary
Syntax:copy scp flashsource-ip-address signaturefileufi.sig { fips-ufi-primary-sig | fips-ufi-secondary-sig } - Zeroize all the keys by executing
crypto key zeroizecommand. - Disable FIPS by entering the
no fips enableorno fips enable common-criteriacommand at the prompt. - Enter the
write memorycommand to save the changes. - Reload the configuration by entering the
reloadcommand.
Once the switch is rebooted, refer to Placing the device in FIPS mode if you want to re-enable FIPS.