Configuring Fips Mode; Entering Fips Mode - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

If a device enters FIPS or non-FIPS mode through automatic reboot, the startup configuration file
does not support configuration rollback. To support configuration rollback, you must execute the
save command before making other configurations.

Configuring FIPS mode

Entering FIPS mode

After you enable FIPS mode and reboot the device, the device operates in FIPS mode, which has strict
security requirements, and performs self-tests on cryptography modules to verify that they operate
correctly.
A FIPS device can meet the requirements defined in Network Device Protection Profile (NDPP) of
Common Criteria (CC).
The system provides two methods to enter FIPS mode: automatic reboot and manual reboot.
Automatic reboot
To use automatic reboot to enter FIPS mode, follow these steps:
1.
Enable FIPS mode.
2.
Select the automatic reboot method.
The system automatically creates a default FIPS configuration file named fips-startup.cfg, specifies
this file as the startup configuration file, and prompts you to configure the username and password
for next login.
You can press Ctrl+C to exit the configuring process. Then, the fips mode enable command will not
be executed.
3.
Configure a username and password used to log in to the device in FIPS mode.
The password must include at least 15 characters that must contain uppercase and lowercase
letters, digits, and special characters.
Then, the system automatically uses the startup configuration file to reboot the device and enters
FIPS mode. You can only use the configured username and password to log in to the FIPS device.
After login, you are assigned a user role of crypto officer.
Manual reboot
To use manual reboot to enter FIPS mode, follow these steps:
1.
Enable the password control function globally.
2.
Set the number of character types a password must contain to 4, and set the minimum number of
characters for each type to one character.
3.
Set the minimum length of user passwords to 15 characters.
4.
Add a local user account for device management, including a username, a password that must
comply with the password control policies, a user role of network-admin, and a service type of
terminal.
5.
Delete the FIPS-incompliant local user service types Telnet, HTTP, and FTP.
6.
Enable FIPS mode.
7.
Select the manual reboot method.
8.
Save the configuration file and specify it as the startup configuration file.
337

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents