Configuring fips, Prerequisites, Enabling fips mode – H3C Technologies H3C WX3000E Series Wireless Switches User Manual
Page 359: Triggering a self-test

345
Configuring FIPS
After you enable FIPS mode, the system has strict security requirements, and performs self-test on
cryptography modules to make sure that they work normally.
Prerequisites
Before enabling FIPS mode, complete the following tasks:
•
Configure the login username and password. The password must comprise no less than 6
characters and must contain uppercase and lowercase letters, digits, and special characters.
•
Delete all MD5-based digital certificates.
•
Delete the DSA key pairs that have a modulus length of less than 1024 bits and all RSA key pairs.
Enabling FIPS mode
IMPORTANT:
To enable both FIPS mode and password control, enable FIPS mode first and then password control. To
disable both of them, disable password control first and then FIPS mode. Otherwise, the router cannot
reboot.
After enabling FIPS mode, you must restart the device to validate the configuration.
To enable FIPS mode:
Step Command
Remarks
1.
Enter system view.
system-view N/A
2.
Enable FIPS mode.
fips mode enable
Required.
Not enabled by default.
After you enable FIPS mode and restart the device, the following changes occur:
•
The FTP/TFTP server is disabled.
•
The Telnet server is disabled.
•
The HTTP server is disabled.
•
SNMP v1 and SNMP v2c are disabled. Only SNMP v3 is available.
•
The SSL server only supports TLS1.0.
•
The SSH server does not support SSHv1 clients.
•
Generated RSA/DSA key pairs have a modulus length from 1024 to 2048 bits.
•
SSH, SNMPv3, IPsec and SSL do not support DES, RC4, or MD5.
Triggering a self-test
Task Command
Remarks
Trigger a self-test.
fips self-test
Required
- H3C WX5500E Series Access Controllers H3C WX3500E Series Access Controllers H3C WX2500E Series Access Controllers H3C WX6000 Series Access Controllers H3C WX5000 Series Access Controllers H3C LSWM1WCM10 Access Controller Module H3C LSUM3WCMD0 Access Controller Module H3C LSUM1WCME0 Access Controller Module H3C LSWM1WCM20 Access Controller Module H3C LSQM1WCMB0 Access Controller Module H3C LSRM1WCM2A1 Access Controller Module H3C LSBM1WCM2A0 Access Controller Module H3C WA3600 Series Access Points H3C WA2600 Series WLAN Access Points H3C S10500 Series Switches H3C S5800 Series Switches H3C S5820X Series Switches H3C S12500 Series Switches H3C S9500E Series Switches H3C MSR 5600 H3C MSR 50 H3C MSR 3600 H3C MSR 30 H3C MSR 2600 H3C MSR 20-2X[40] H3C MSR 20-1X H3C MSR 930 H3C MSR 900 H3C SR8800 H3C SR6600-X H3C SR6600 H3C SecPath F5020 H3C SecPath F5040 H3C VMSG VFW1000