FIPS Configuration
In this section:
- User Roles in FIPS Mode
- Commands Disabled in FIPS ModeThe device in FIPS mode does not support the following commands:
- Hidden Files in FIPS ModeHidden files are not displayed when the device is in FIPS mode. Hidden files are displayed only when the device is in non-FIPS mode.
- Cryptographic Algorithms in FIPS ModeThe device in FIPS mode supports the following FIPS 140-3-approved cryptographic algorithms:
- SSH
- SSH Clients
- Usernames and SSH Public Key AuthenticationThe device stores or uses the username that is provided by the SSH client when public-key authentication is used. Therefore, the username is mentioned in the login and logout syslogs.
- Protocol Changes in FIPS ModeThe following table lists the protocols that undergo changes while the device is in FIPS mode with the default policy applied.
- System Reset and Boot up in FIPS ModePOST testing takes place as the device progresses through the boot sequence.
- Debugging in FIPS ModeThe device reloads automatically when it encounters a system reset and enters FIPS failure state. The cause of failure logs on the console and the device performs a self-reboot.
- Placing the Device in FIPS ModePlacing the device in FIPS mode is a multiple-step process that begins with enabling FIPS mode on the device.
- Disabling FIPS Mode
- Running FIPS Self-tests