HP 6125XLG Command Reference Manual page 234

Blade switch security command reference
Table of Contents

Advertisement

After you execute the fips mode enable command, the system provides two methods to enter FIPS mode:
Automatic reboot
Select the automatic reboot method. The system automatically creates a default FIPS configuration
file named fips-startup.cfg, specifies this file as the startup configuration file, and requires you to
configure the username and password for next login. You can press Ctrl+C to exit the configuring
process so the fips mode enable command will not be executed.
The system automatically uses the specified startup configuration file to reboot the device after you
configure the administrator's s username and password.
Manual reboot
This method requires that you manually complete the configurations for entering FIPS mode, and
then reboot the device.
To use manual reboot to enter the FIPS mode, follow these steps:
a.
Enable the password control function globally.
b.
Set the number of character types a password must contain to 4, and set the minimum number
of characters for each type to one character.
c.
Set the minimum length of user passwords to 15 characters.
d.
Add a local user account for device management, including a username, a password that must
comply with the password control policies, a user role of network-admin, and a service type
of terminal.
e.
Delete the FIPS-incompatible local user service types Telnet and FTP.
f.
Save the configuration file, specify it as the startup configuration file, delete the original startup
configuration file in binary format, and reboot the device.
After the fips mode enable command is executed, the system prompts you to choose a reboot method. If
you do not make a choice within 30 seconds, the system uses the manual reboot method by default.
To switch to non-FIPS mode, execute the undo fips mode enable command in system view, save the
configuration, and reboot the device.
Examples
# Enable FIPS mode, and choose the automatic reboot method to enter FIPS mode.
<Sysname> system-view
[Sysname] fips mode enable
Create a new start-up configuration file named fips-startup.cfg used for FIPS mode. After
setting the username and password for logging in the device of FIPS mode, the device will
be rebooted automatically. Are you sure? [Y/N]:y
Enter username(1~55 characters): root
Enter password(15~63 characters):
Confirm:
Waiting for reboot ...After reboot, the device will enter fips mode.
# Enable FIPS mode, and choose the manual reboot method to enter FIPS mode.
<Sysname> system-view
[Sysname] fips mode enable
Create a new start-up configuration file named fips-startup.cfg used for FIPS mode. After
setting the username and password for logging in the device of FIPS mode, the device will
be rebooted automatically. Are you sure? [Y/N]:n
[Sysname]
225

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents