Fips Mode Configuration; Table 86 Fips Mode Restrictions - HP SN3000B Administrator's Manual

Brocade fabric os administrator's guide - supporting fabric os v7.0.1 (53-1002446-01, march 2012)
Hide thumbs Also See for SN3000B:
Table of Contents

Advertisement

The results of the POST and conditional tests are recorded in the system log or are output to the
local console. This action includes logging both passing and failing results. Refer to the Fabric OS
Troubleshooting and Diagnostics Guide for instructions on how to recover if your system cannot get
out of the conditional test mode.

FIPS mode configuration

By default, the switch comes up in non-FIPS mode. You can run the fipsCfg
command to enable FIPS mode, but you must configure the switch first. Self-test mode must be
enabled before FIPS mode can be enabled. A set of prerequisites (as shown in
satisfied for the system to enter FIPS mode. To be FIPS-compliant, the switch must be rebooted. For
Backbones, either reboot both CPs, or power the chassis down and then up again. KATs are run on
the reboot. If the KATs are successful, the switch enters FIPS mode. If the KATs fail, then the switch
reboots until the KATs succeed. If the switch cannot enter FIPS mode and continues to reboot, you
must return the switch to your switch service provider. For information about how to prepare a
service provider case, refer to the Fabric OS Troubleshooting and Diagnostics Guide
When the switch successfully reboots in FIPS mode, only FIPS-compliant algorithms are run.
Table 86
TABLE 86
Features
Configupload/ download/
supportsave/ firmwaredownload
DH-CHAP/FCAP hashing
algorithms
HTTP/HTTPS access
HTTPS algorithms
IPsec
LDAP CA
Radius auth protocols
Root account
Signed firmware
SNMP
SSH algorithms
SSH public keys
Telnet/SSH access
Fabric OS Administrator's Guide
53-1002446-01
lists Fabric OS features and their behaviors in FIPS and non-FIPS mode.
FIPS mode restrictions
FIPS mode
SCP/SFTP only
SHA-1
HTTPS only
TLS/AES128 cipher suite
Disabled
CA certificate must be available.
PEAP-MSCHAPv2
Disabled
Mandatory firmware signature validation
Read-only operations
HMAC-SHA1 (MAC)
3DES-CBC, AES128-CBC, AES192-CBC,
AES256-CBC (cipher suites)
RSA 1024 bit keys and RSA 2048 bit keys
Only SSH
FIPS mode configuration
enable fips
--
Table
86) must be
Non-FIPS mode
FTP and SCP/SFTP
MD5 and SHA-1
HTTP and HTTPS
TLS AES 128 cipher suite
No restrictions
CA certificate is optional.
CHAP, PAP, PEAP-MSCHAPv2
Enabled
Optional firmware signature
validation
Read and write operations
No restrictions
RSA 1024 bit keys, RSA 2048
bit keys, and DSA 1024 bit keys
Telnet and SSH
C
523

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os v7.0.1

Table of Contents