Boot Strict Mode - Lenovo CN4093 Application Manual

10gb converged scalable switch
Hide thumbs Also See for CN4093:
Table of Contents

Advertisement

Boot Strict Mode

© Copyright Lenovo 2015
The implementations specified in this section are compliant with National Institute
of Standards and Technology (NIST) Special Publication (SP) 800-131A.
The CN4093 10Gb Converged Scalable Switch can operate in two boot modes:
Compatibility mode (default): This is the default switch boot mode. This mode
may use algorithms and key lengths that may not be allowed/acceptable by
NIST SP 800-131A specification. This mode is useful in maintaining
compatibility with previous releases and in environments that have lesser data
security requirements.
Strict mode: Encryption algorithms, protocols, and key lengths in strict mode
are compliant with NIST SP 800-131A specification.
When in boot strict mode, the switch uses Secure Sockets Layer (SSL)/Transport
Layer Security (TLS) 1.2 protocols to ensure confidentiality of the data to and from
the switch.
By default, HTTP, Telnet, and SNMPv1 and SNMPv2 are disabled on the CN4093.
Before enabling strict mode, ensure the following:
The software version on all connected switches is Lenovo N/OS 8.3.
NIST Strict compliance is enabled on the Chassis Management Module.
The supported protocol versions and cryptographic cipher suites between
clients and servers are compatible. For example: if using SSH to connect to the
switch, ensure that the SSH client supports SSHv2 and a strong cipher suite that
is compliant with the NIST standard.
Compliant Web server certificate is installed on the switch, if using BBI.
A new self-signed certificate is generated for the switch
(CN 4093(config)# access https generate-certificate). The new
certificate is generated using 2048-bit RSA key and SHA-256 digest.
Protocols that are not NIST SP 800-131A compliant must be disabled or not
used.
Only SSHv2 or higher is used.
The current configuration, if any, must be saved in a location external to the
switch. When the switch reboots, both the startup and running configuration are
lost.
Chapter 1: Switch Administration
43

Advertisement

Table of Contents
loading

Table of Contents