Zeroizing Shared Secrets and Host Keys

After you have reviewed the Korean CC policy, use the fips zeroize command to zeroize the shared secrets and host keys used by various networking protocols.
device# fips zeroize all

Syntax: fips zeroize { all | shared-secret | host-keys | pki-certs }

The all option zeroizes all shared secrets and host keys. The shared-secret option zeroizes shared secret keys only. The host-keys option zeroizes host keys only.

For example, entering fips zeroize shared-secret zeroizes only the shared secret keys of various networking protocols and host access passwords.

Note: The fips zeroize command may cause operational failure within networking protocols using shared secrets and should be used with careful consideration.

The default policy calls for the zeroization of all keys using the fips zeroize all command option. When you apply a less strict policy than the default, zeroize at your discretion.

Note: The fips zeroize all command zeroizes all keys irrespective of the configured security policy.

The following table lists the various keys used in the system that are zeroized in compliance with Korean CC.

Key Zeroization

Keys Used

Command Option Handling

DH private keys

Host-keys

FCSP Challenge Handshake Authentication Protocol (CHAP) secret

Host-keys

SSH session key

Host-keys

SSH RSA private key

Host-keys

RNG seed key

N/A

Passwords

Shared-secret

Authentication passwords for various networking protocols

Shared-secret