Fips Mode Configuration - Brocade Communications Systems 1606 Administrator's Manual

Brocade fabric os administrator's guide v6.3.0 (53-1001336-01, july 2009)
Hide thumbs Also See for 1606:
Table of Contents

Advertisement

FIPS mode configuration

By default, the switch comes up in non-FIPS mode. You can run the fipsCfg
to enable FIPS mode, but you need to configure the switch first. Self-tests mode must be enabled
before FIPS mode can be enabled. A set of prerequisites as mentioned in the table below must be
satisfied for the system to enter FIPS mode. To be FIPS-compliant, the switch must be rebooted.
KATs are run on the reboot. If the KATs are successful, the switch enters FIPS mode. If KATs fail,
then the switch reboots until the KATs succeed. If the switch cannot enter FIPS mode and
continues to reboot, you must access the switch in single-user mode to break the reboot cycle. For
more information on how to fix this issue, refer to the Fabric OS Troubleshooting and Diagnostics
Guide
Only FIPS-compliant algorithms are run at this stage.
TABLE 98
Features
Root account
Telnet/SSH access
SSH algorithms
HTTP/HTTPS access
HTTPS
protocol/algorithms
RPC/secure RPC access
Secure RPC protocols
SNMP
DH-CHAP/FCAP hashing
algorithms
Signed firmware
Configupload/
download/
supportsave/
firmwaredownload
IPsec
Radius auth protocols
Fabric OS Administrator's Guide
53-1001336-01
FIPS mode restrictions
FIPS mode
Disabled
Only SSH
HMAC-SHA1 (mac)
3DES-CBC, AES128-CBC, AES192-CBC,
AES256-CBC (cipher suites)
HTTPS only
TLS/AES128 cipher suite
Secure RPC only
TLS - AES128 cipher suite
Read-only operations
SHA-1
Mandatory firmware signature validation.
SCP only
For FCIP IPSec the DH group 1 is
FIPS-compliant and is not blocked. Usage of
AES-XCBC, MD5 and DH group 0 and 1 are
blocked.
For IPSec (Ethernet), only MD5 is blocked in
FIPS mode.
PEAP-MSCHAPv2
FIPS mode configuration
enable fips command
--
Non-FIPS mode
Enabled
Telnet and SSH
No restrictions
HTTP and HTTPS
TLS/AES128 cipher suite
(SSL will no longer be supported)
RPC and secure RPC
SSL and TLS – all cipher suites
Read and write operations
MD5 and SHA-1
Optional firmware signature
validation
FTP and SCP
No restrictions
CHAP, PAP, PEAP-MSCHAPv2
D
525

Advertisement

Table of Contents
loading

Table of Contents