SV-269788r1051749_rule
V-269788
SRG-APP-000179-NDM-000265
OS10-NDM-000510
CAT I
10
Configure the network device to use FIPS 140-2 approved algorithms for authentication to a cryptographic module:
OS10(config)# crypto fips enable
WARNING: Upon committing this configuration, the system will regenerate SSH keys. Please consult documentation and toggle FIPS mode only if you know what you are doing!
Continue? [yes/no(default)]:yes
OS10(config)#
Determine if the network device uses FIPS 140-2 approved algorithms for authentication to a cryptographic module.
Review the FIPS status to verify that FIPS mode is enabled, as shown below:
OS10# show fips status
FIPS mode: Enabled
Crypto Library: OpenSSL 1.0.2zg-fips 7 Feb 2023
FIPS Object Module: DELL OpenSSL FIPS Crypto Module v2.6 July 2021
OS10#
If the network device is not configured to use a FIPS-approved authentication algorithm to a cryptographic module, this is a finding.
V-269788
False
OS10-NDM-000510
Determine if the network device uses FIPS 140-2 approved algorithms for authentication to a cryptographic module.
Review the FIPS status to verify that FIPS mode is enabled, as shown below:
OS10# show fips status
FIPS mode: Enabled
Crypto Library: OpenSSL 1.0.2zg-fips 7 Feb 2023
FIPS Object Module: DELL OpenSSL FIPS Crypto Module v2.6 July 2021
OS10#
If the network device is not configured to use a FIPS-approved authentication algorithm to a cryptographic module, this is a finding.
M
5666