STIGQter STIGQter: STIG Summary: Dell OS10 Switch NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must use FIPS 140-2 approved algorithms for authentication to a cryptographic module.

DISA Rule

SV-269788r1051749_rule

Vulnerability Number

V-269788

Group Title

SRG-APP-000179-NDM-000265

Rule Version

OS10-NDM-000510

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the network device to use FIPS 140-2 approved algorithms for authentication to a cryptographic module:

OS10(config)# crypto fips enable

WARNING: Upon committing this configuration, the system will regenerate SSH keys. Please consult documentation and toggle FIPS mode only if you know what you are doing!
Continue? [yes/no(default)]:yes
OS10(config)#

Check Contents

Determine if the network device uses FIPS 140-2 approved algorithms for authentication to a cryptographic module.

Review the FIPS status to verify that FIPS mode is enabled, as shown below:

OS10# show fips status

FIPS mode: Enabled
Crypto Library: OpenSSL 1.0.2zg-fips 7 Feb 2023
FIPS Object Module: DELL OpenSSL FIPS Crypto Module v2.6 July 2021
OS10#

If the network device is not configured to use a FIPS-approved authentication algorithm to a cryptographic module, this is a finding.

Vulnerability Number

V-269788

Documentable

False

Rule Version

OS10-NDM-000510

Severity Override Guidance

Determine if the network device uses FIPS 140-2 approved algorithms for authentication to a cryptographic module.

Review the FIPS status to verify that FIPS mode is enabled, as shown below:

OS10# show fips status

FIPS mode: Enabled
Crypto Library: OpenSSL 1.0.2zg-fips 7 Feb 2023
FIPS Object Module: DELL OpenSSL FIPS Crypto Module v2.6 July 2021
OS10#

If the network device is not configured to use a FIPS-approved authentication algorithm to a cryptographic module, this is a finding.

Check Content Reference

M

Target Key

5666