Enabling FIPS Mode

Perform the following steps to enable FIPS mode.
  1. Attach a management station (PC or terminal) to the management module serial (console) port using a serial cable.
    When the device is not in a console session, FIPS-related commands return errors.
  2. Verify that the device is in non-FIPS mode by using the fips show command.
    device(config)# fips show

    Syntax: fips show

    The fips show command lists the current configuration of the device and can be run in both FIPS mode and non-FIPS modes to establish whether the device is truly in FIPS mode.

    The output of the fips show command confirms that the device is in FIPS mode and identifies the device as either administratively or operationally in FIPS mode.

    Note: If the FastIron device is in JITC mode, then you cannot enable FIPS on the device.

    The following example shows the output of the fips show command before the fips enable command is entered. Administrative status and operational status are off.

    device(config)# fips show
    FIPS mode: Administrative Status: OFF, Operational Status: OFF

    If the device is already in administrative FIPS mode, you can modify the FIPS policy. Refer to Modifying the FIPS policy.

  3. Use the fips enable command to place the device administratively in FIPS mode.
    device(config)# fips enable

    Syntax: [no] fips enable

    The following example shows sample output of the fips enable command.

    Note: Beginning with FastIron 08.0.20a, the RSA key pair is deleted when the FIPS mode is enabled. Use the crypto key generate command to generate the RSA key once the device is in FIPS mode.

    device(config)# fips enable
    
    FIPS: Deleting SSH Keys..RSA Key pair not found
    
    FIPS: Disabling HTTP..HTTP already disabled
    
    FIPS: Disabling Telnet..
    
    FIPS: Disabling NTP..
    FIPS: Disabling Tftp..
    tftp disable set already.
    This device is now running in FIPS administrative mode.
    At this time you can alter this system's FIPS default security policy
    and then enter FIPS operational mode.
    
    Note: Making changes to the default FIPS security policy weakens
    the security of the device and makes the device non-compliant with
    FIPS 140-3 Level 1, design assurance Level 1
    The default security policy defined in the FIPS
    Security Policy Document ensures that the device complies with all
    FIPS 140-3 specifications. Commands to alter the default security policy
    are available to the crypto-officer; however, Ruckus Wireless does not recommend
    making changes to the default security policy at any time.
    =====================================
    
    To enter FIPS mode, complete the following steps:
    1. Install the signature file now if not already done. Failure to install
    signature or wrong signature file can cause continuous resets.
    Also, optionally, configure FIPS policy commands that meets your network
    requirements. You must explicitly configure the following services if you want
    to use them when the device is operational in FIPS mode:
    2. Enter the "fips zeroize all" command, which zeroes out the shared secrets
    used by various networking protocols, including the host access passwords,
    SSH and HTTPS host-keys with the digital signature based on the configured
    FIPS Security Policy. If SSH ReKey Exchange value was not configured then
    the default value of 30Mins and 500MB will be configured
    3. Save the running configuration.
    4. Reload the device.
    5. Do not press "b" during reload, else FIPS or CC will not be enabled properly.
    6. Enter the "fips show" command to verify that the device entered
    FIPS or CC operational mode.
    =====================================
    
    The system will disable the following services or commands after reload:
    1. Telnet server will be disabled. The "telnet server" command will be removed.
    2. SCP will be enabled. The "ip ssh scp disable" command will be removed.
    3. HTTP server will be disabled. The "web-management http" command will be removed.
    4. SNMP server will change as follows:
    -SNMP support for v1 and v2 versions will be disabled.
    -For SNMPv3 version md5 key and DES privacy password will be disabled.
    5. NTP will be disabled.
    Passwords/Keys which dont comply FIPS standards will be removed on reload.
    aaa authentication method must be configured.
    Disabling user when invalid password is entered is default in FIPS and above modes.
    Default value of login recovery time is 3 secs.
    No command sets the login recovery time to 3 secs and disables the user after 3 invalid attempts.
    Default values of 3 attempts and 3 secs are not displayed in running config.
    Please see FIPS config guide for complete details.
  4. You can verify the status of the device as administratively in FIPS mode by using the fips show command.
    The following example shows the output of the fips show command on a FastIron device after the fips enable command is entered and administrative status is on and operational status is off:

    The following example shows the output of the fips show command on a CER devices after the fips enable command is entered and administrative status is on and operational status is off:

    device# fips show 
    Cryptographic Module Version: FI-IP-CRYPTO
    FIPS mode: Administrative status ON: Operational status OFF
    Common-Criteria: Administrative status OFF: Operational status OFF
    --------------------------------------------------------------
     Some shared secrets inherited from non-fips mode may
     not be fips compliant and must be zeroized
     The system needs to be reloaded to operationally enter FIPS mode.
    --------------------------------------------------------------
    
    System Specific:
    OS monitor access status is: Disabled
    
    Management Protocol Specific:
    Telnet server: Disabled
    Telnet client: Disabled
    TFTP client: Disabled
    SNMP Access to security objects: Disabled
    
    Critical security Parameter updates across FIPS boundary:
    Protocol Shared secret and host passwords: Clear
    Password Display: Disabled
    
    
    Certificate Specific:
    HTTPS RSA Host Keys and Signature: Clear                          
    SSH DSA Host keys: Clear
    SSH RSA Host keys: Clear
    CC Enable AAA Server Any: Clear