Describes the Power-on Self-Test (POST) Known Answer Test (KAT) mechanism, which verifies the cryptographic integrity of hardware components at startup to support compliance with security standards like FIPS.
A power-on self-test (POST) is a security mechanism that
-
verifies the cryptographic integrity of hardware components at system startup,
-
prevents network traffic flow if integrity checks fail, and
-
supports compliance with security standards such as Common Criteria and FIPS.
|
Feature Name |
Release Information |
Description |
|---|---|---|
|
FIPS 140-3 certification |
Release 26.3.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: K100])(select variants only*) FIPS 140-3 (Federal Information Processing Standard 140-3) certification provides extended cryptographic standards including software, firmware, and hybrid modules. FIPS 140-3 is used to approve cryptographic modules for the security of both hardware and software products. *This feature is supported on:
|
Power-on self-tests utilize Known Answer Tests (KATs) executed immediately after powering on the cipher module in MACsec-enabled Cisco 8000 series routers. These tests check cryptographic algorithms (e.g., SHA, DES) on each physical layer chip (PHY) with hardware crypto. If any PHY fails the test, the module enters an error state and does not allow traffic, ensuring only secure, verified hardware is operational.
The POST KAT feature is now available on Cisco 8800 48x100 GbE QSFP28 Line Card (8800-LC-48H), Cisco 8800 36x400GE QSFP56-DD Line Card with MACsec (8800-LC-36FH-M), and Cisco 8606 series routers.
-
On successful POST KAT execution, the system displays logs indicating KAT Test PASSED for each port, and the corresponding line card becomes operational.
-
If POST KAT fails on any PHY, the system logs a KAT Test FAILED message, the line card enters an ERROR state, and network traffic is blocked on that card.
Starting with Cisco IOS XR Release 26.3.1, FIPS 140-3, which is an extended security standard for hardware, software, and firmware cryptographic modules, is supported on Cisco 88-LC1-48Y8F-EM and Cisco 88-LC1-16H16F-EM line cards.
For information about FIPS 140-3, which releases are FIPS compliant, and to view FIPS certifications, see FIPS 140 Certifications.