Services; Crypto Officer Services - Dell PowerConnect W-Series FIPS Manual

Fips 140-2 non-proprietary security policy
Hide thumbs Also See for PowerConnect W-Series FIPS:
Table of Contents

Advertisement

4.2 Services

The module provides various services depending on role. These are described below.

4.2.1 Crypto Officer Services

The CO role in each of FIPS modes defined in section 3.3 has the same services
Service
FIPS mode enable/disable
Key Management
Remotely reboot module
Self-test triggered by CO/User
reboot
Update module firmware
Configure non-security related
module parameters
Description
The CO selects/de-selects FIPS
mode as a configuration option.
The CO can configure/modify the
IKEv1/IKEv2 shared secret (The
RSA private key is protected by
non-volatile memory and cannot
be modified) and the WPA2 PSK
(used in advanced Remote AP
configuration). Also, the CO/User
implicitly uses the KEK to
read/write configuration to non-
volatile memory.
The CO can remotely trigger a
reboot
The CO can trigger a
programmatic reset leading to
self-test and initialization
The CO can trigger a module
firmware update
CO can configure various
operational parameters that do not
relate to security
35
CSPs Accessed
(see section 6
below for complete description of
CSPs)
None.
IKEv1/IKEv2 shared
secret
WPA2 PSK
KEK
KEK is accessed when
configuration is read during
reboot. The firmware verification
key and firmware verification CA
key are accessed to validate
firmware prior to boot.
KEK is accessed when
configuration is read during
reboot. The firmware verification
key and firmware verification CA
key are accessed to validate
firmware prior to boot.
The firmware verification key
and firmware verification CA key
are accessed to validate firmware
prior to writing to flash.
None.

Advertisement

Table of Contents
loading

Table of Contents