STIGQter STIGQter: STIG Summary: Dell OS10 Switch NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.

DISA Rule

SV-269796r1051773_rule

Vulnerability Number

V-269796

Group Title

SRG-APP-000411-NDM-000330

Rule Version

OS10-NDM-000780

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the OS10 Switch to use FIPS-validated HMAC to protect the integrity of nonlocal maintenance and diagnostic communications.

OS10(config)# crypto fips enable

WARNING: Upon committing this configuration, the system will regenerate SSH keys. Please consult documentation and toggle FIPS mode only if you know what you are doing!
Continue? [yes/no(default)]:yes
OS10(config)#

Disable telnet if it has been enabled:

OS10(config)# no ip telnet server enable

Enable SSH if it has been disabled:

OS10(config)# ip ssh server enable

Check Contents

Verify the OS10 Switch uses FIPS-validated HMAC to protect the integrity of nonlocal maintenance and diagnostic communications.

Review the FIPS status to verify that FIPS mode is enabled, as shown below:

OS10# show fips status

FIPS mode: Enabled
Crypto Library: OpenSSL 1.0.2zg-fips 7 Feb 2023
FIPS Object Module: DELL OpenSSL FIPS Crypto Module v2.6 July 2021
OS10#

Verify that SSH is enabled for network access by reviewing the SSH server status:

OS10# show ip ssh | grep "SSH Server:"
SSH Server: Enabled

Verify that telnet is disabled on the switch by verifying that the following is not in the running-configuration:
ip telnet server enable

If FIPS mode is not enabled or if the SSH is not enabled or if telnet is enabled in the OS10 Switch, this is a finding.

Vulnerability Number

V-269796

Documentable

False

Rule Version

OS10-NDM-000780

Severity Override Guidance

Verify the OS10 Switch uses FIPS-validated HMAC to protect the integrity of nonlocal maintenance and diagnostic communications.

Review the FIPS status to verify that FIPS mode is enabled, as shown below:

OS10# show fips status

FIPS mode: Enabled
Crypto Library: OpenSSL 1.0.2zg-fips 7 Feb 2023
FIPS Object Module: DELL OpenSSL FIPS Crypto Module v2.6 July 2021
OS10#

Verify that SSH is enabled for network access by reviewing the SSH server status:

OS10# show ip ssh | grep "SSH Server:"
SSH Server: Enabled

Verify that telnet is disabled on the switch by verifying that the following is not in the running-configuration:
ip telnet server enable

If FIPS mode is not enabled or if the SSH is not enabled or if telnet is enabled in the OS10 Switch, this is a finding.

Check Content Reference

M

Target Key

5666