
When the FIPS module is enabled, the Monitoring - FIPS mode page will show what service (SSHv2, HTTPS,
SNMPv3 and ADSAP2) is in FIPS mode. All security functions and cryptographic algorithms used by the service
are performed in FIPS 140-2 Approved mode.
To enable the FIPS module:
1. Select System - Security - FIPS140.
2. Check the box to Enable the FIPS140-2 Module and click Save.
The console server will automatically reboot. During the reboot, the console server will erase SSHkeys, update
the configuration of HTTPD, SSHD, ADSAP2d and SNMPD files and test the integrity of the FIPSObject
Module. Once the reboot is complete, the console server will accept SSH and HTTPSconnections using only
FIPS-approved ciphers.
When FIPS is enabled the following restrictions apply:
For SSH sessions:
• Protocol version 1 will be disabled.
• Triple-DES CBS and AES 128/192/256 CBSare the only encryption ciphers that will be accepted.
• HMAC-SHA1 and HMAC-SHA1-96 are the only message integrity algorithms that will be
accepted.
• Only RSAkeys 1024 to 16384 bits will be accepted.
HTTPSsessions will accept only the SSL v 3.1(TLSv1) protocol to establish the SSLtunnel with one of
the following encryption ciphers:
• AES-256-SHA
• AES-128-SHA
• Triple DESSHA (DES-CBC3-SHA)
SNMPversion 3 requests will be accepted when authentication is SHAand the encryption cipher is
AES.
HTTPS Certificate
You can generate a new self-signed certificate or download a signed certificate to the appliance from an FTP
server or from your desktop.
To generate a new self-signed certificate:
1. Select System – Security – HTTPS Certificate.
2. Check the radio button next to Generate Self-Signed Certificate.
3. Enter the desired information in the self-signed certificate fields: Country, State/Province, City/Locality,
Organization, Organization Unit, Common Name, Email Address and Netscape Comment.
4. Click Generate/Download. The generated certificate's information will be displayed.
5. Click Install. The certificate will be saved and the browser server will restart to use the new certificate.
To download a signed certificate:
1. Select System – Security – HTTPS Certificate.
20 Cyclades™ ACS 6000 Advanced Console Server
Comentarios a estos manuales