Configuring Fips; Overview; Feature And Hardware Compatibility; Configuration Restrictions And Guidelines - HP MSR Series Configuration Manual

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Configuring FIPS

The device that provides low encryption does not support FIPS.

Overview

Federal Information Processing Standards (FIPS) was developed by the National Institute of
Standards and Technology (NIST) of the United States. FIPS specifies the requirements for
cryptographic modules. FIPS 140-2 defines four levels of security, named Level 1 to Level 4, from
low to high. The device supports Level 2.
Unless otherwise noted, in this document the term FIPS refers to FIPS 140-2.

Feature and hardware compatibility

Hardware
MSR954(JH296A/JH297A/JH299A)
MSR1002-4/1003-8S
MSR2003
MSR2004-24/2004-48
MSR3012/3024/3044/3064
MSR4060/4080

Configuration restrictions and guidelines

When you configure FIPS, follow these restrictions and guidelines:
After the fips mode enable command is executed, the system prompts you to choose a reboot
method. If you do not make a choice within 30 seconds, the system uses the manual reboot
method.
Before you reboot the device to enter FIPS mode, the system automatically removes all key
pairs configured in non-FIPS mode and all FIPS-incompliant digital certificates.
FIPS-incompliant digital certificates are MD5-based certificates with the modulus length of key
pairs less than 2048 bits. You cannot log in to the device through SSH after the device enters
FIPS mode. To log in to the device in FIPS mode through SSH, first log in to the device through
a console/AUX/Async port, and then create a key pair for the SSH server.
The password for entering the device in FIPS mode must comply with the password control
policies, such as password length, complexity, and aging policy. When the aging timer for a
password expires, the system prompts you to change the password. If you adjust the system
time after the device enters FIPS mode, the login password might expire before the next login,
because the original system time is typically much earlier than the actual time.
If you choose the automatic reboot method, set the system time before executing the fips
mode enable command.
If you choose the manual reboot method, set the system time before configuring the local
username and password.
To use the manual reboot method, you must perform the following tasks:
a. Save the current configuration file.
FIPS compatibility
No
Yes
Yes
Yes
Yes
Yes
557

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents