Federal Information Processing Standard (FIPS) mode imposes requirements on system upgrades, passwords, protocols, cryptographic keys, and authentication methods.
When FIPS mode is enabled, its requirements apply throughout the Cisco Application Policy Infrastructure Controller (APIC) environment.
General requirements
-
Disable FIPS mode before downgrading to a release that does not support FIPS.
-
After upgrading to Cisco APIC release 6.1(1) or later, manually reload or power cycle the standby controllers to apply FIPS mode.
-
Passwords must contain at least eight characters.
-
Beginning with Cisco APIC release 5.3(1), disable Telnet. Secure Shell (SSH) is the only supported remote shell protocol.
-
Delete all SSH server RSA1 key pairs.
-
SSH and Simple Network Management Protocol (SNMP) are supported.
-
Disable SNMPv1 and SNMPv2. Configure SNMPv3 users with SHA authentication and Advanced Encryption Standard (AES) privacy.
-
Beginning with Cisco APIC release 2.3(1), FIPS mode can be configured at the switch level.
-
Beginning with Cisco APIC release 3.1(1), Network Time Protocol (NTP) operates in FIPS mode and supports HMAC-SHA1 authentication or no authentication.
Dual-supervisor spine switch requirements
The following requirements apply after enabling FIPS mode or replacing all supervisors on a dual-supervisor spine switch:
| Cisco APIC release | Required action |
|---|---|
| 5.2(3) and earlier | Reload the switch twice. |
| 5.2(4) and later | Reload the switch, and then power cycle it. |
Remote authentication requirements
| Cisco APIC release | Required configuration |
|---|---|
| 5.2(3) and earlier | Disable RADIUS and TACACS+. Only local and LDAP authentication are supported in FIPS mode. |
| 5.2(4) through 6.2(1) | Disable RADIUS, TACACS+, and RSA remote authentication. Only local, LDAP, OAuth 2.0, and SAML authentication are supported in FIPS mode. |
| 6.2(2) and later | Disable RADIUS, TACACS+ without TLS, and RSA remote authentication. TACACS+ with TLS, local, LDAP, OAuth 2.0, and SAML authentication are supported in FIPS mode. |