Triggering A Self-Test; Displaying And Maintaining Fips; Fips Configuration Example; Network Requirements - HP 5120 SI Series Security Configuration Manual

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

Triggering a self-test

To examine whether the cryptography modules operate normally, you can use a command to trigger a
self-test on the cryptographic algorithms. The triggered self-test is the same as the power-up self-test.
If the self-test fails, the device automatically reboots.
To trigger a self-test:
Step
1.
Enter system view.
2.
Trigger a self-test.

Displaying and maintaining FIPS

Task
Display FIPS mode state.

FIPS configuration example

Network requirements

PC connects to Switch through a console port. Configure Switch to operate in FIPS mode and create a
local user for PC so that PC can log in to the switch.
Figure 116 Network diagram

Configuration procedure

# Enable the FIPS mode.
<Sysname> system-view
[Sysname] fips mode enable
FIPS mode change requires a device reboot. Continue?[Y/N]:y
Change the configuration to meet FIPS mode requirements, save the configuration to the
next-startup configuration file, and then reboot to enter FIPS mode.
# Enable the password control function.
[Sysname] password-control enable
# Create a local user named test, and set its service type as terminal, privilege level as 3, and password
as AAbbcc1234%. The password is a string of at least 10 characters by default and must contain both
uppercase and lowercase letters, digits, and special characters.
[Sysname] local-user test
Command
system-view
fips self-test
Command
display fips status
337
Remarks
Available in any view.

Advertisement

Table of Contents
loading

Table of Contents