Configuration Changes In Fips Mode - HP MSR2000 Configuration Manual

Hide thumbs Also See for MSR2000:
Table of Contents

Advertisement

2.
Set the number of character types a password must contain to 4, and set the minimum number of
characters for each type to 1.
3.
Set the minimum length of user passwords to 15 characters.
4.
Add a local user account for device management, including the following items:
A username.
A password that complies with the password control policies as described in step
A user role of network-admin.
A service type of terminal.
5.
Delete the FIPS-incompliant local user service types Telnet and FTP.
6.
Enable FIPS mode.
7.
Select the manual reboot method.
8.
Save the configuration file and specify it as the startup configuration file.
9.
Delete the startup configuration file in binary format.
Reboot the device.
10.
The system enters FIPS mode. You can use the configured username and password to log in to the
device in FIPS mode.
Before you enable FIPS mode, perform the following tasks:
If you choose manual reboot, complete configurations such as password control settings and a local
user account. For more information, see
If you choose automatic reboot, and saving the current configuration is required, execute the save
command.
To enable FIPS mode:
Step
1.
Enter system view.
2.
Enable FIPS mode.

Configuration changes in FIPS mode

When the system enters FIPS mode, the following system changes occur:
The user login authentication mode can only be scheme.
The FTP/TFTP server and client are disabled.
The Telnet server and client are disabled.
SNMPv1 and SNMPv2c are disabled. Only SNMPv3 is available.
The SSH server does not support SSHv1 clients and DSA key pairs.
The generated RSA and DSA key pairs must have a modulus length of 2048 bits.
When the device acts as a server to authenticate a client through public keys, the key pairs for the
client must also have a modulus length of 2048 bits.
SSH, SNMPv3, and IPsec do not support DES, 3DES, RC4, and MD5.
"Manual
Command
system-view
fips mode enable
340
reboot."
Remarks
N/A
By default, the FIPS mode is
disabled.
2
and step 3.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr3000Msr4000

Table of Contents