Enabling Fips Mode; Checking For Fips Status; Fips Self-Tests - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

Enabling FIPS Mode

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Enabling FIPS Mode
To enable FIPS mode, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# fips mode enable
switch(config)# no fips mode enable

Checking for FIPS Status

To view FIPS status, enter the show fips status command.

FIPS Self-Tests

A cryptographic module must perform power-up self-tests and conditional self-tests to ensure that it is
functional.
Note
FIPS power-up self-tests automatically run when FIPS mode is enabledby entering the fips mode enable
command. A switch is in FIPS mode only after all self-tests are successfully completed. If any of the
self-tests fail, then the switch is rebooted.
Power-up self-tests run immediately after FIPS mode is enabled. A cryptographic algorithm test using a
known answer must be run for all cryptographic functions for each FIPS 140-2-approved cryptographic
algorithm implemented on the Cisco MDS 9000 Family.
Using a known-answer test (KAT), a cryptographic algorithm is run on data for which the correct output
is already known, and then the calculated output is compared to the previously generated output. If the
calculated output does not equal the known answer, the known-answer test fails.
Conditional self-tests must be run when an applicable security function or operation is invoked. Unlike
the power-up self-tests, conditional self-tests are executed each time their associated function is
accessed.
Conditional self-tests include the following:
Both of these tests automatically run when a switch is in FIPS mode.
Cisco MDS 9000 Family CLI Configuration Guide
31-2
Pair-wise consistency test—This test is run when a public-private key-pair is generated.
Continuous random number generator test—This test is run when a random number is generated.
Chapter 31
Purpose
Enters configuration mode.
Enables FIPS mode.
Disables FIPS mode.
OL-18084-01, Cisco MDS NX-OS Release 4.x
Configuring FIPS

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents