MACsec and software release upgrade

If the device has MACsec configuration (for example, using the dot1x-mka-enable command) and you are upgrading the software, the bypass test (also known as the FIPS Integrity Qualification test) is automatically executed when the device is in FIPS mode. This test generates the HMAC values based on the available MACsec configurations. The output of the show running command displays the fips bypass-test macsec config-integrity command along with the HMAC value.

device# show running
!
fips enable
fips bypass-test macsec config-integrity “8f67c6019f82b1657fc704c4d8e78f37c9c6aa73”
!
Note

Note

The fips bypass-test macsec config-integrity command is an auto-generated command. You cannot execute this command manually in the CLI.