Performing a Korean CC Self Test

(Optional) Use the self-test to verify the sanity of Korean CC software.

Once the Korean CC image is installed, which includes the signature and the UFI images, the device will always be in Korean CC mode of operation. Once the device is reloaded, it will automatically perform a self-test.

  • From the Privileged EXEC level of the CLI on the console, use the fips self-tests command to verify that the Korean Software and Firmware Integrity Test passes.

    Use the fips self-tests command in Korean CC mode to run the Known Answer Tests (KATs) and conditional tests on demand.

    Syntax: fips self-tests

  • The following log message is generated when the KAT is completed.

    “Crypto module initialization and Known Answer Test (KAT) passed”.

  • The following example shows the Korean Software and Firmware Integrity Test as passed:
device# fips self-tests
Apr 10 10:20:10:274388:info:fi_debug:debug_logs:1:0: FIPS Power On Self Tests and KAT tests successful.
Apr 10 10:20:10:274516:info:fi_debug:debug_logs:1:0: Running continuous DRBG check.
Apr 10 10:20:10:274631:info:fi_debug:debug_logs:1:0: Running continuous DRBG check successful.
Apr 10 10:20:12:542529:info:fi_debug:debug_logs:1:0: Pairwise consistency check successful.
Apr 10 10:20:12:584305:info:fi_debug:debug_logs:1:0: fips crypto drbg health check tests ran successful.
Apr 10 10:20:12:585688:info:fi_debug:debug_logs:1:0: Crypto module initialization and Known Answer Test (KAT) Passed
Apr 10 10:20:15:038656:info:fi_debug:debug_logs:1:0: FIPS: Image verification passed
Apr 10 10:20:15:038747:info:fi_debug:debug_logs:1:0: FIPS Firmware Integrity Tests successful.
Apr 10 10:20:15:038802:info:fi_debug:debug_logs:1:0: Message Digest Used for verification     : SHA-256
Apr 10 10:20:15:038855:info:fi_debug:debug_logs:1:0: Encryption method used for Private key   : RSA-2048

If the software integrity test fails, make sure that the correct signature file was copied for the correct image file and version, and recopy as needed. If the problem persists, contact the RUCKUS Support team.

Note: The self-test must pass before the configuration is saved and the device is reloaded.
Note: The RUCKUS ICX device will cease operation and force a reboot if the self-test fails.