Modifying the FIPS Policy
The output of the
fips enable command displays which protocols that constitute the FIPS policy are set in compliance
with FIPS standards by default and can be adjusted to set a more flexible policy.
The remaining protocols that constitute the FIPS policy are set to the appropriate
status automatically during reload due to the
fips enable command. The default FIPS policy is detailed in
How FIPS works.
When you make no changes to the FIPS policy, the default FIPS policy is applied on the device and the device operates in strict FIPS mode upon reload, in full compliance with FIPS 140-3 specifications.
To set a more flexible FIPS policy on the FastIron device, use the following commands as desired to modify the default FIPS policy.
- Allow TFTP access:
device(config)# fips policy allow tftp-access
- Allow SNMP access to the critical security parameter
(CSP) MIB objects:
device(config)# fips policy allow snmp-csp-access
- Allow access to monitor mode for debugging both from
application and boot prompts:
device (config)# fips policy allow monitor-full-access
Syntax:
[no] fips policy allow monitor-full-accessNote: During an application reset, monitor access is restored to allow debugging. - Retain the shared secret keys for all protocols and the
host passwords:
device(config)# fips policy retain shared-secrets
- Retain the SSH DSA host keys:
device(config)# fips policy retain dsa-host-keys
- Retain the TLS RSA host keys and the TLS server digital
certificate:
device(config)# fips policy retain rsa-host-keys