SSHv2

Secure Shell version 2 (SSHv2) is allowed in FIPS mode.

The following SSH commands are affected when the FastIron device is in FIPS mode:

Verify latest changes

  • In FIPS mode, the aes192-ctr, aes192-cbc, and 3des-cbc options are not supported in the ip ssh encryption command.
  • ip ssh encryption aes256-cbc
  • ip ssh encryption aes128-cbc
  • ip ssh encryption aes256-ctr
  • ip ssh encryption aes128-ctr
  • The ip ssh key-authentication no command is disabled.
  • The ip ssh scp command ensures that SCP is enabled to run in FIPS mode. SCP is needed for file communication, and the ip ssh scp disable command is disabled in FIPS mode and displays the following message:
    FIPS Compliance: SCP needs to be enabled
  • The crypto key zeroize command removes configured SSH keys.

Note: The following encryption methods are supported in FIPS mode:
  • aes256-ctr
  • aes128-ctr
  • aes256-cbc
  • aes128-cbc

Note: The following public key algorithms are supported in FIPS mode:

Add ecdsa-sha2-nistp256, ecdsa-sha2-nistp521 (SSHV2 section)
  1. ssh-rsa
  2. rsa-sha2-256
  3. rsa-sha2-512
  4. ecdsa-sha2-nistp384
  5. ecdsa-sha2-nistp256
  6. ecdsa-sha2-nistp521

Note: The following MAC algorithms are supported in FIPS mode:

  1. hmac-sha1
  2. hmac-sha2-256
  3. hmac-sha2-512
    Verify what you wanted included in the list.

Note: The following key exchange methods are supported in FIPS mode:

Add ecdh-sha2-nistp521 (SSHv2 section)
  1. ecdh-sha2-nistp256
  2. diffie-hellman-group14-sha256
  3. diffie-hellman-group16-sha512
  4. diffie-hellmangroup18-sha512
  5. ecdh-sha2-nistp384
  6. ecdh-sha2-nistp521

Use the show ip ssh config command to display SSH configuration information.

SSH key generation time is affected by the increased security of authentication and encryption algorithms both in and out of FIPS mode.