Fabric OS Administrator’s Guide
615
53-1002745-02
Appendix
B
FIPS Support
In this appendix
•
FIPS overview. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 615
•
Zeroization functions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 615
•
FIPS mode configuration. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 617
•
Preparing a switch for FIPS. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 621
FIPS overview
Federal information processing standards (FIPS) specify the security standards to be satisfied by a
cryptographic module utilized in Fabric OS v6.0.0 and later to protect sensitive information in the
switch. As part of FIPS 140-2 level 2, compliance passwords, shared secrets, and the private keys
used in SSL, TLS, and system login need to be cleared out or
zeroized
. Before enabling FIPS
compliance mode, a power-on self-test (POST) is executed when the switch is powered on to check
for the consistency of the algorithms implemented in the switch. Known-answer tests (KATs) are
used to exercise various features of the algorithm and their results are displayed on the console for
your reference. Conditional tests are performed whenever an RSA key pair is generated. These
tests verify the randomness of the deterministic random number generator (DRNG) and the
non-deterministic random number generator (non-DRNG). They also verify the consistency of RSA
keys with regard to signing and verification and encryption and decryption.
ATTENTION
FIPS mode, when enabled, is a chassis-wide setting that affects all logical switches. Once enabled,
FIPS mode cannot be disabled.
Zeroization functions
Zeroization functions can be performed at the discretion of the security administrator. These
functions clear the passwords and the shared secrets. Core files and FFDC data are also removed
upon FIPS Zeroization.
Table 86
lists the various keys used in the system that will be zeroized in a
FIPS-compliant Fabric OS module.
TABLE 86
Zeroization behavior
Keys
Zeroization CLI
Description
DH private keys
No command required
Keys will be zeroized within code before they are
released from memory.
FCAP private key
secCertUtil delete
--
fcapall
-nowarn
The secCertUtil delete
--
fcapall -nowarn command
removes all FCAP certificates and FCAP private keys.
Содержание Fabric OS 7.1.0
Страница 1: ...53 1002745 02 25 March 2013 Fabric OS Administrator s Guide Supporting Fabric OS 7 1 0 ...
Страница 24: ...24 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 28: ...28 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 32: ...32 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 42: ...42 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 116: ...116 Fabric OS Administrator s Guide 53 1002745 02 Inter switch links 4 FIGURE 7 Virtual channels on a QoS enabled ISL ...
Страница 132: ...132 Fabric OS Administrator s Guide 53 1002745 02 Frame Redirection 4 ...
Страница 194: ...194 Fabric OS Administrator s Guide 53 1002745 02 Ports and applications used by switches 6 ...
Страница 254: ...254 Fabric OS Administrator s Guide 53 1002745 02 Brocade configuration form 8 ...
Страница 274: ...274 Fabric OS Administrator s Guide 53 1002745 02 Validating a firmware download 9 ...
Страница 302: ...302 Fabric OS Administrator s Guide 53 1002745 02 Creating a logical fabric using XISLs 10 ...
Страница 344: ...344 Fabric OS Administrator s Guide 53 1002745 02 Concurrent zone transactions 11 ...
Страница 374: ...374 Fabric OS Administrator s Guide 53 1002745 02 Setting up TI over FCR sample procedure 12 ...
Страница 432: ...432 Fabric OS Administrator s Guide 53 1002745 02 Access Gateway N_Port failover with FA PWWN 16 ...
Страница 462: ...462 Fabric OS Administrator s Guide 53 1002745 02 ...
Страница 490: ...490 Fabric OS Administrator s Guide 53 1002745 02 Ports on Demand 18 ...
Страница 498: ...498 Fabric OS Administrator s Guide 53 1002745 02 Supported topologies for ICL connections 19 ...
Страница 626: ...626 Fabric OS Administrator s Guide 53 1002745 02 Preparing a switch for FIPS B ...
Страница 630: ...630 Fabric OS Administrator s Guide 53 1002745 02 Hexadecimal Conversion C ...
Страница 666: ...666 Fabric OS Administrator s Guide 53 1002745 02 ...