Creating A Server In Fips Mode - Cisco CSS11501S-C-K9 Configuration Manual

Secure content accelerator
Table of Contents

Advertisement

Chapter 6
FIPS Operation

Creating a Server in FIPS Mode

78-13124-06
Creating and configuring server operations in FIPS Mode are nearly identical to
those in normal operational modes. The differences are the following:
Only the FIPS security policy and security policies containing FIPS-approved
algorithms can be used
Only FIPS-compliant servers can be used for data transfer
(non-FIPS-compliant servers can be edited for FIPS compliance)
Follow the steps below to create a FIPS-compliant server.
Connect to the Secure Content Accelerator using a serial management
1.
session, and enter Privileged, Configuration, and SSL Modes. Create a secure
server named mySecServ.
[FIPS] SCA> enable
[FIPS] SCA# config
[FIPS] config[SCA]# ssl
[FIPS] ssl-config[SCA]# server mySecServ create
[FIPS] ssl-server[mySecServ]#>
2.
Assign an IP address, key, certificate, and FIPS-compliant security policy.
[FIPS] ssl-server[mySecServ]#> ip address 10.1.114.30
[FIPS] ssl-server[mySecServ]#> key myOwnKey
[FIPS] ssl-server[mySecServ]#> cert myOwnCert
[FIPS] ssl-server[mySecServ]#> secpolicy fips
[FIPS] ssl-server[mySecServ]#>
3.
Exit to Top Level Mode.
[FIPS] ssl-server[mySecServ]#> finished
[FIPS] SCA#
Cisco 11000 Series Secure Content Accelerator Configuration Guide
Using FIPS Mode
6-5

Advertisement

Table of Contents
loading

This manual is also suitable for:

Css-11154-ac11000 series

Table of Contents