Image Verification in FIPS or CC Mode

For a FIPS- or CC-enabled device running FastIron 08.0.10 or later, uploading a flash or boot code triggers a FIPS Load Qualification test that performs a digital signature verification of the flash or boot code using a signature file. In earlier FastIron versions, the test is triggered only when the FIPS- or CC-enabled device boots.
  • FIPS devices running FastIron 08.0.10 or later support the digital signature files generated using the SHA-256/RSA-2048 algorithm.
  • FIPS devices running FastIron 10.0.10j05 or later support the digital signature files generated using the SHA-512/RSA-3072 algorithm.
  • FastIron versions earlier than 08.0.10 in FIPS or CC mode support the digital signature files generated using the SHA-1/DSA-1024 algorithm.
  • FastIron versions earlier than 10.0.10j05 in FIPS or CC mode support the digital signature files generated using the SHA-256/RSA-2048 algorithm.

Verifying the Currently Active Software Version

Use the show version command to check the active software version on a FastIron device. The following example displays the current software version of an ICX 7150 as version 10.0.10d and provides additional details on the image file and the modules installed in the device.

ICX7150-48 Router# show version
  Copyright (c) Ruckus Networks, Inc. All rights reserved.
    UNIT 1: compiled on Apr 11 2024 at 05:52:57 labeled as SPR10010d
      (33554432 bytes) from Primary SPR10010d.bin (UFI)
        SW: Version 10.0.10dT213
      Compressed Primary Boot Code size = 786944, Version:10.2.06T225 (mnz1026)
       Compiled on Thu Apr  4 05:57:28 2024

  HW: Stackable ICX7150-48
==========================================================================
UNIT 1: SL 1: ICX7150-48-2X10G_2X1G 48-port Management Module
      Serial  #:FEH3208N003
      Software Package: ICX7150_L3_SOFT_PACKAGE
      Current License: 4X10GR
      P-ASIC  0: type B160, rev 11  Chip BCM56160_B0
==========================================================================
UNIT 1: SL 2: ICX7150-2X1GC 2-port 2G Module
==========================================================================
UNIT 1: SL 3: ICX7150-4X10GF 4-port 40G Module
==========================================================================
 1000 MHz ARMv7 Cortex-A9 processor 88 MHz bus
    8 MB boot flash memory
    2 GB code flash memory
    1 GB DRAM
STACKID 1  system uptime is 10 minute(s) 29 second(s)
The system started at 12:46:57 GMT+00 Tue Apr 16 2024

The system : started=warm start   reloaded=by "reload"

Checking the Inactive Software Version in Secondary Storage

Use the show flash command to verify the version of the inactive image loaded in secondary flash. The show flash command displays the image version for both primary and secondary flash partitions as shown in the following example.

ICX7150-48 Router# show flash
           Stack unit 1:
             NAND Type: Micron NAND 2GiB (x 1)
             Compressed Pri Code size = 33554432, Version:10.0.10d (SPR10010d.bin)
             Compressed Sec Code size = 33554432, Version:10.0.10d (SPR10010d.bin)
             Compressed Pri Boot Code size = 786944, Version:10.2.06T225 (mnz1026)
             Compressed Sec Boot Code size = 786944, Version:10.2.06T225 (mnz1026)
             Code Flash Free Space = 896172032