How Korean Common Criteria Works

To configure a device to operate in Korean CC mode, download the appropriate software version onto the management station while connected to the device's console port using a serial cable.

A software build specifically supporting Korean CC is provided, which includes the fips enable common-criteria command and other essential requirements for Korean CC, all of which are activated by default upon bootup. To enable Korean CC mode of operation, you must load this specific build at least once. There are no alternative methods to enable Korean CC on the device.

Once the software is installed, which includes the signature and the UFI images, the device will be in Korean CC mode of operation. It is important to ensure that both the signature and UFI files are loaded correctly. Failure to copy the signature file may result in image validation errors, and the device cannot be recovered. To recover the device, contact the RUCKUS Support team.

Note: Device stacking is not supported in Korean Common Criteria.

Note: When you execute the command to reload the device, validation of the software image is triggered. If verification fails, the device continuously reboots.

While the device is booting, the following actions are performed per the default security policy:

  • Disable Telnet
  • Disable TFTP (but TFTP can be re-enabled using the fips policy allow tftp-access command)
  • Enable SCP access
  • Disable the HTTPS server and client
  • Disable HTTP server and client
  • Set login recovery time to the default value of 3 minutes (180 seconds)
  • Disable the user account after three invalid or wrong password attempts (the user may try again after the login recovery timer has expired [3 minutes])
  • Disable SNMP access to critical security parameter (CSP) MIB objects (SNMP v2 configuration is blocked in the configuration)
  • The UDP logging feature is not enabled by default. You can enable it using the fips policy allow udp-logging command.
  • Non-TLS UDP RADIUS server is not enabled by default. You can enable it using the fips policy allow udp-radius-server command.
  • Non-TLS TACACS+ feature is not enabled by default. You can enable it using the fips policy allow common-criteria aaa-server-any command.
  • Disable the encrypted Syslog Server

While the device is booting, several tests are performed to ensure compliance with Korean CC standards:

  • Firmware Integrity Tests
  • Package Checksum Verification
  • uboot Checksum Validation
  • Power-On Self Tests (POSTs)
  • Known Answer Tests (KATs)

After these tests are successfully completed, and upon loading the correct signature file and image, the device reloads and becomes operational in Korean CC mode of operation. SNMPv3 user configurations are not included in the startup configuration.

Note: In Korean CC mode, ensure that the cloud management is disabled by entering the manager disable command.
Note: The Web UI is not supported in Korean CC mode. Ensure that no other web-management configuration is present on the ICX device. Then enter the web-management disable command. This closes ports 8081 and 443.