
StreamCaster MIMO Radio User Manual
4/30/19
10017C000
Silvus Technologies Confidential
Page
131
6.
FIPS Mode
6.1
Enable FIPS Mode
The following steps are required to make the radio FIPS compliant.
1.
Enable FIPS mode under Security -> Encryption tab. This will require a reboot and will
erase all setting profiles, reset the encryption key, both SSH keys, the HTTPS certificate,
and the login passwords to their factory default. It will also turn on HTTPS and Login
Authentication.
2.
After the radio comes back online, you will need to login to continue. You must change
the default password of “HelloWorld,” for all three users. Do this by clicking “Change
Password,” and then follow the instructions in section 5
.1.13 Admin Settings.
3.
Next go to Security -> Key Management. You must change the SSH Login Key, SSH Host
Key, and HTTPS Certificate from their defaults. See section 5.1.10 under Key
Management for details.
4.
Now you must create an encryption key that will be shared amongst all radios on a
network. For initial setup, you must have a direct connection to each radio from your
laptop (since a mesh cannot be formed without a shared encryption key). On the first
radio, click Generate Random Key, then click Apply. For the rest of the radios, instead
of clicking Generate Random Key, copy/paste the first generated key to the rest of the
radios under the same section.
o
If you want to change the encryption key after initial setup, you must carefully
sequence the order i
n which you change the keys if you don’t have a direct
connection to all radios. First change the radios at the very edge of the network.
As soon as you do this, those radios will be disconnected from the network. Now
change the new radios at the edge of the network. After you have changed the
encryption key for all radios on the network, they will all reconnect again.
6.1.1
Potential User Errors
o
Do not use the same encryption key you were using in non FIPS mode because these may
have been broadcasted in plain text. Generate new ones once in FIPS mode.