Perform the following steps to place the
Extreme NetIron device in FIPS mode.
Procedure
-
Assume the Crypto-officer role.
-
Copy the needed signature files. Refer to
Copying the signature files.
-
Enable FIPS mode. Refer to
Enabling FIPS mode. The device enables FIPS administrative commands. The device is not in the FIPS approved mode yet. Do not change the default strict FIPS security policy, which is required for the FIPS approved mode.
-
Zeroize shared secrets and host keys. Refer to
Zeroizing shared secrets and host keys.
-
Configure all users of the module and the authentication methods. Refer to
Configuring user authentication
-
Save the configuration. Refer to
Saving the configuration.
-
Reload the device. Refer to
Reloading the device.
-
Enter the
fips show command. The device displays the FIPS-related status, which should confirm the security policy is the default security policy.
-
Perform a FIPS self-test to verify the correct signature files were copied. Refer to
Perform a FIPS self-test.
-
Inspect the physical security of the module including placement of tamper evident labels on the
Extreme NetIron device. Refer to the
Extreme FIPS Security Seal document for more information.