SV-269797r1052421_rule
V-269797
SRG-APP-000412-NDM-000331
OS10-NDM-000790
CAT I
10
Configure the OS10 Switch to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions using a FIPS 140-2 approved algorithm:
OS10(config)# crypto fips enable
WARNING: Upon committing this configuration, the system will regenerate SSH keys. Please consult documentation and toggle FIPS mode only if you know what you are doing!
Continue? [yes/no(default)]:yes
OS10(config)#
Disable telnet if it has been enabled:
OS10(config)# no ip telnet server enable
Enable SSH if it has been disabled:
OS10(config)# ip ssh server enable
Review the OS10 Switch configuration to determine if cryptographic mechanisms are implemented using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions.
Review the FIPS status to verify that FIPS mode is enabled, as shown below:
OS10# show fips status
FIPS mode: Enabled
Crypto Library: OpenSSL 1.0.2zg-fips 7 Feb 2023
FIPS Object Module: DELL OpenSSL FIPS Crypto Module v2.6 July 2021
OS10#
Verify that SSH is enabled for network access by reviewing the SSH server status:
OS10# show ip ssh | grep "SSH Server:"
SSH Server: Enabled
Verify that telnet is disabled on the switch by verifying that the following is not in the running-configuration:
ip telnet server enable
If FIPS mode is not enabled, if the SSH is not enabled, or if telnet is enabled in the OS10 Switch, this is a finding.
V-269797
False
OS10-NDM-000790
Review the OS10 Switch configuration to determine if cryptographic mechanisms are implemented using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions.
Review the FIPS status to verify that FIPS mode is enabled, as shown below:
OS10# show fips status
FIPS mode: Enabled
Crypto Library: OpenSSL 1.0.2zg-fips 7 Feb 2023
FIPS Object Module: DELL OpenSSL FIPS Crypto Module v2.6 July 2021
OS10#
Verify that SSH is enabled for network access by reviewing the SSH server status:
OS10# show ip ssh | grep "SSH Server:"
SSH Server: Enabled
Verify that telnet is disabled on the switch by verifying that the following is not in the running-configuration:
ip telnet server enable
If FIPS mode is not enabled, if the SSH is not enabled, or if telnet is enabled in the OS10 Switch, this is a finding.
M
5666