Features Unavailable in FIPS and Common Criteria Mode

Some of the security features are disabled in FIPS/CC mode:
  • SSHv2: Host and client key generation methods using DSA and the RSA-1024 key size are not supported (only RSA 2048 and higher key sizes are supported). Therefore, the following commands are not supported:
    • crypto key gen rsa modulus 1024
    • crypto key zero rsa modulus 1024
  • TLS: The RSA 1024 key size for SSL or TLS private key generation is not supported. (FastIron devices support only 2048 and above key sizes.)
  • SSH key exchange: The SSH key exchange method diffie-hellman-group1-sha1 and diffie-hellman-group14-sha1 are not supported. Only the following SSH key exchange methods are supported:
    • diffie-hellman-group14-sha256
    • diffie-hellman-group16-sha512
    • diffie-hellman-group18-sha512
    • ecdh-sha2-nistp256
    • ecdh-sha2-nistp384
    • ecdh-sha2-nistp521