Chapter 6 FIPS Operation
Using FIPS Mode
6-6
Cisco 11000 Series Secure Content Accelerator Configuration Guide
78-13124-05
You can create a security policy containing only the FIPS-approved algorithm you
want to use. The following example demonstrates creating a security policy
containing on the 3DES/SHA algorithm and editing a secure server to use the new
user-defined security policy rather than the FIPS security policy.
1.
Connect to the Secure Content Accelerator using a serial management
session, and enter Privileged, Configuration, and SSL Modes. Create a
security policy named myFIPS.
[FIPS] SCA> enable
[FIPS] SCA# config
[FIPS] config[SCA]# ssl
[FIPS] ssl-config[SCA]# secpolicy myFIPS create
[FIPS] ssl-secpolicy[myFIPS]#>
2.
Specify the 3DES/SHA cryptographic algorithm, and return to SSL
Configuration Mode.
[FIPS] ssl-secpolicy[myFIPS]#> crypto DES-CBC3-SHA
[FIPS] ssl-secpolicy[myFIPS]#> exit
[FIPS] ssl-config[SCA]#>
3.
Enter Server Configuration Mode to edit the configuration of the server
mySecServ to use the myFIPS security policy rather than the previously
specified FIPS security policy.
[FIPS] ssl-config[SCA]#> server mySecServ
[FIPS] ssl-server[mySecServ]#> secpolicy myFIPS
[FIPS] ssl-server[mySecServ]#>
4.
Exit to Top Level Mode.
[FIPS] ssl-server[mySecServ]# finished
[FIPS] SCA#
Содержание CSS11501 - 100Mbps Ethernet Load Balancing Device
Страница 4: ......
Страница 28: ...Figures xxviii Cisco 11000 Series Secure Content Accelerator Configuration Guide 78 13124 05 ...
Страница 30: ...Tables xxx Cisco 11000 Series Secure Content Accelerator Configuration Guide 78 13124 05 ...
Страница 422: ...Glossary 4 Cisco 11000 Series Secure Content Accelerator Configuration Guide 78 13124 05 ...
Страница 432: ...Index 10 Cisco 11000 Series Secure Content Accelerator Configuration Guide 78 13124 04 ...