RUCKUS FastIron FIPS and Common Criteria Configuration Guide, 10.0.10
- 1 CommScope Legal Statements
- Preface Ruckus
- 4 About This Document
- 5 Federal Information Processing Standards
- 5.1 FIPS Overview
- 5.2 How FIPS Works
- Upgrading Software on FIPS-enabled devices
- 7 FIPS Configuration
- 7.1 User Roles in FIPS Mode
- 7.2 Commands Disabled in FIPS Mode
- 7.3 Hidden Files in FIPS Mode
- 7.4 Cryptographic Algorithms in FIPS Mode
- 7.5 SSH
- 7.6 SSH Clients
- 7.7 Usernames and SSH Public Key Authentication
- 7.7.1 Implementation
- 7.7.2 Restrictions
- 7.8 Protocol Changes in FIPS Mode
- 7.8.1 BGP
- 7.8.2 HTTP / HTTPS
- 7.8.3 TLS
- 7.8.4 PKI
- 7.8.5 Proprietary 2-way Encryption Algorithms
- 7.8.6 RADIUS Protocol in FIPS Mode
- 7.8.7 SCP
- 7.8.9 SSHv2
- 7.8.10 Telnet
- 7.8.11 TFTP
- 7.9 System Reset and Boot up in FIPS Mode
- 7.10 Debugging in FIPS Mode
- 7.11 Placing the Device in FIPS Mode
- 7.11.1 General Steps to Place the Device in FIPS Mode
- 7.11.2 Enabling FIPS Mode
- 7.11.3 Zeroizing Shared Secrets and Host Keys
- 7.11.4 Configuring User Authentication
- 7.11.5 Saving the Configuration
- 7.11.6 Reloading the Device
- 7.11.7 Performing a FIPS Self-test
- 7.11.8 Modifying the FIPS Policy
- 7.12 Disabling FIPS Mode
- 7.13 Running FIPS Self-tests
- 8 Common Criteria Certification
- 8.1 Common Criteria Overview
- 8.2 Enabling Common Criteria Mode
- 8.3 Encrypted Syslog Servers in Common Criteria Mode
- 8.4 AAA Servers in Common Criteria Mode
- 8.5 Downgrading from Common Criteria Mode to Non-FIPS Mode
- 8.6 Commercial Solutions for Classified program
- 8.7 Configuring NTP
- 8.7.1 Enabling NTP
- 8.7.2 Disabling NTP
- 8.7.3 Enabling NTP Authentication
- 8.7.4 Defining an Authentication Key
- 8.7.5 Configuring the NTP Client
- 8.7.6 Displaying NTP Status
- 8.7.7 Displaying NTP Association Information
- 8.7.8 Displaying NTP Association Details
- 8.7.9 NTP Client Mode Configuration Example
- 8.7.10 NTP Strict Authentication Configuration Example
- 8.8 Configuring PKI
- 8.9 Network Device Collaborative Protection Profile
- 8.10 MACsec Configuration
- 8.10.1 MACsec Overview
- 8.10.2 Configuring MACsec
- 8.10.3 Enabling MACsec and Configuring Group Parameters
- 8.10.3.1 Configuring MACsec Key-Server Priority
- 8.10.3.2 Configuring MACsec Integrity and Encryption
- 8.10.3.3 Configuring MACsec Frame Validation
- 8.10.3.4 Configuring Replay Protection
- 8.10.3.5 Configuring Data-Delay Protection
- 8.10.4 MKA Keychain Overview and Considerations
- 8.10.5 Enabling and Configuring Group Interfaces for MACsec
- 8.10.5.1 Configuring the Pre-shared Key
- 8.10.6 Sample MACsec Configuration
- 8.10.7 Displaying MACsec Information
- 9 Configuring Logging and RADIUS Server Hosts
- Syslog messages
- OpenSSL license