Fips Self-Tests - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

Automatic reboot
Select the automatic reboot method. The system automatically creates a default non-FIPS configuration
file named non-fips-startup.cfg, and specifies the file as the startup configuration file. Then, the system
reboots the device by using the default non-FIPS configuration file. After the reboot, you are directly
logged into the device.
Manual reboot
This method requires that you manually complete the configurations for entering non-FIPS mode, and
then reboot the device. After the reboot, you must enter user information according to the authentication
mode to log in to the device. The following shows the default authentication modes for different ports or
lines (you can modify the default mode as needed):
The default authentication mode is password for VTY lines.
The default authentication mode is none for the console port.
After you disable FIPS mode, follow these restrictions and guidelines before you manually reboot the
device:
If you are logged into the device through Telnet, you must set the authentication mode to scheme
without exiting the current user line, and then configure the username and password. You can also
use the current username and password.
If you are logged into the device through a console port, configure one of the following
authentication modes as needed:
Configure the password authentication mode and a password.
Configure the scheme authentication mode and configure a new username and password (you
can also use the current username and password).
Configure the none authentication mode.
To disable FIPS mode:
Step
1.
Enter system view.
2.
Disable FIPS mode.

FIPS self-tests

FIPS provides self-test mechanisms, including power-up self-test and conditional self-test, to ensure the
normal operation of cryptography modules. You can also trigger a self-test. If the power-up self-test fails,
the device where the self-test process exists reboots. If the conditional self-test fails, the system outputs
self-test failure information.
NOTE:
If a self-test fails, contact HP Support.
Command
system-view
undo fips mode enable
339
Remarks
N/A
By default, the FIPS mode is
disabled.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents