Configuring Fips; Enabling Fips Mode; Triggering A Self-Test - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

Configuring FIPS

After you enable FIPS mode, the system has strict security requirements, and performs self-test on
cryptography modules to make sure that they work normally. For Common Criteria (CC) evaluation in
FIPS mode, the switch also works in a working mode that complies with the CC standard.
Before enabling FIPS mode, complete the following tasks:
Configure the login username and password.
The password must comprise no less than 8 characters and must contain uppercase and lowercase
letters, digits, and special characters.
Delete all MD5-based digital certificates.
Delete all key pairs.
To configure FIPS, complete the following tasks:
Enable the FIPS mode.
1.
Enable the password control function.
2.
Configure local user attributes (including local username, service type, and password) on the
3.
switch.
Save the configuration.
4.
Restart the switch to enter FIPS mode.
5.

Enabling FIPS mode

Step
1.
Enter system view.
2.
Enable FIPS mode.
After you enable FIPS mode and restart the switch, the following changes occur:
FTP/TFTP is disabled.
Telnet is disabled.
HTTP is disabled.
SNMP v1 and SNMP v2c are disabled. Only SNMP v3 is available.
SSL only supports TLS1.0.
SSH does not support SSHv1 clients.
SSH only supports RSA.
Generated RSA key pairs must have a modulus length of 2048 bits. Generated DSA key pairs must
have a modulus of at least 1024 bits.
SSH, SNMPv3, IPsec and SSL do not support DES, 3DES, RC4, or MD5.

Triggering a self-test

Step
1.
Enter system view.
Command
system-view
fips mode enable
Command
system-view
320
Remarks
N/A
Not enabled by default.
Remarks
N/A

Advertisement

Table of Contents
loading

Table of Contents