SV-79693r1_rule
V-65203
SRG-NET-000062-ALG-000092
WSDP-AG-000017
CAT II
10
Configure FIPS 140-2 Level 1 in Firmware only.
Privileged account user log on to default domain >> In the search field type "crypto" >> Press "enter" >> From the search results, click "Crypto Tools" >> Click the "Set Cryptographic Mode" tab >> From the "Cryptographic Mode" list, select "FIPS 140-2 Level 1" >> Click the "Set Cryptographic Mode" button.
When prompted to confirm cryptographic mode change, click "confirm" >> When notified that the action completed successfully, click "Close" >> click "Save Configuration".
Restart the appliance >> Control Panel >> System Control >> Shutdown >> Select "Mode" from dropdown list: "Reboot System" >> Click "Shutdown" button >> Click "Confirm" >> Click "Close".
Configure FIPS 140-2 Level 3 Hardware Security module as follows:
Log on to the command line of the appliance.
Command Prompt >> "configure terminal"
Command Prompt >> "crypto"
Command Prompt >> "hsm-reinit hsm-domain datapower3" (see online documentation; "datapower3" refers to the name of the configured key-sharing domain)
Command Prompt >> prompt: "Do you want to continue ('yes' or 'no')"; enter "yes"
Command Prompt >> "shutdown reboot"
For FIPS 140-2 Level 1 Mode: Privileged account user log on to default domain via the WebGUI >> In the search field type "crypto" >> Press "enter".
From the search results, click "Cryptographic Mode Status"; the "Cryptographic Mode Status" table is displayed.
If the "Target" is not "FIPS 140-2 Level 1", this is a finding.
For FIPS 140-2 Level 1 Mode: Privileged account user log on to default domain via the CLI >> Enter "show crypto-engine" >> Confirm "Crypto Accelerator Type" is "hsm2" >> Confirm "Crypto Accelerator Status" is "fully operational" >> Confirm "Crypto Accelerator FIPS 140-2 Level" is "3".
If these three settings cannot be confirmed, this is a finding.
V-65203
False
WSDP-AG-000017
For FIPS 140-2 Level 1 Mode: Privileged account user log on to default domain via the WebGUI >> In the search field type "crypto" >> Press "enter".
From the search results, click "Cryptographic Mode Status"; the "Cryptographic Mode Status" table is displayed.
If the "Target" is not "FIPS 140-2 Level 1", this is a finding.
For FIPS 140-2 Level 1 Mode: Privileged account user log on to default domain via the CLI >> Enter "show crypto-engine" >> Confirm "Crypto Accelerator Type" is "hsm2" >> Confirm "Crypto Accelerator Status" is "fully operational" >> Confirm "Crypto Accelerator FIPS 140-2 Level" is "3".
If these three settings cannot be confirmed, this is a finding.
M
2859