HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 201

Configuring FIPS mode, Automatic reboot, Manual reboot

Page 201 highlights

reboot the device. The new configuration takes effect after the reboot. During this process, do not exit the system or perform other operations. • To make sure the rollback between FIPS mode (entered by using the manual reboot method) and non-FIPS mode succeeds, save the configuration when the device enters FIPS mode before performing other operations. • Do not use FIPS and non-FIPS devices to create an IRF fabric. • To enable FIPS mode for an IRF fabric, you must reboot the whole IRF fabric. Configuring FIPS mode Entering FIPS mode After you enable FIPS mode and reboot the switch, the switch operates in FIPS mode, which has strict security requirements, and performs self-tests on cryptography modules to verify that they operate properly. A FIPS device can meet the requirements defined in Network Device Protection Profile (NDPP) of Common Criteria (CC). The system provides two methods to enter FIPS mode: automatic reboot and manual reboot. Automatic reboot To use automatic reboot to enter FIPS mode, follow these steps: 1. Enable FIPS mode. 2. Select the automatic reboot method. The system automatically creates a default FIPS configuration file named fips-startup.cfg, specifies this file as the startup configuration file, and prompts you to configure the username and password for next login. You can press Ctrl+C to exit the configuration process. Then, the fips mode enable command will not be executed. 3. Configure a username and password used to log in to the device in FIPS mode. The password must include at least 15 characters and must contain uppercase and lowercase letters, digits, and special characters. Then, the system automatically uses the startup configuration file to reboot the device and enters FIPS mode. You can only use the configured username and password to log in to the FIPS device. After login, you are assigned a user role of crypto officer. Manual reboot To use manual reboot to enter FIPS mode, follow these steps: 1. Enable the password control function globally. 2. Set the number of character types a password must contain to 4 and set the minimum number of characters for each type to one character. 3. Set the minimum length of user passwords to 15 characters. 4. Add a local user account for device management, including a user name, a password that must comply with the password control policies, a user role of network-admin, and a service type of terminal. 192

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

192
reboot the device. The new configuration takes effect after the reboot. During this process, do not
exit the system or perform other operations.
To make sure the rollback between FIPS mode (entered by using the manual reboot method) and
non-FIPS mode succeeds, save the configuration when the device enters FIPS mode before
performing other operations.
Do not use FIPS and non-FIPS devices to create an IRF fabric.
To enable FIPS mode for an IRF fabric, you must reboot the whole IRF fabric.
Configuring FIPS mode
Entering FIPS mode
After you enable FIPS mode and reboot the switch, the switch operates in FIPS mode, which has strict
security requirements, and performs self-tests on cryptography modules to verify that they operate
properly.
A FIPS device can meet the requirements defined in Network Device Protection Profile (NDPP) of
Common Criteria (CC).
The system provides two methods to enter FIPS mode: automatic reboot and manual reboot.
Automatic reboot
To use automatic reboot to enter FIPS mode, follow these steps:
1.
Enable FIPS mode.
2.
Select the automatic reboot method.
The system automatically creates a default FIPS configuration file named
fips-startup.cfg
, specifies
this file as the startup configuration file, and prompts you to configure the username and password
for next login.
You can press
Ctrl+C
to exit the configuration process. Then, the
fips mode enable
command will
not be executed.
3.
Configure a username and password used to log in to the device in FIPS mode.
The password must include at least 15 characters and must contain uppercase and lowercase
letters, digits, and special characters.
Then, the system automatically uses the startup configuration file to reboot the device and enters
FIPS mode. You can only use the configured username and password to log in to the FIPS device.
After login, you are assigned a user role of
crypto officer
.
Manual reboot
To use manual reboot to enter FIPS mode, follow these steps:
1.
Enable the password control function globally.
2.
Set the number of character types a password must contain to 4 and set the minimum number of
characters for each type to one character.
3.
Set the minimum length of user passwords to 15 characters.
4.
Add a local user account for device management, including a user name, a password that must
comply with the password control policies, a user role of
network-admin
, and a service type of
terminal
.