Provides FIPS mode requirements and procedures for compliant cryptographic keys, key chains, certificates, OSPFv3, SNMPv3, and SSH services on Cisco IOS XR routers.
Use this chapter to prepare a Cisco IOS XR router for FIPS mode and configure supported cryptographic services.
The chapter covers these functional areas:
-
FIPS mode concepts, requirements, restrictions, enablement, and system reload
-
Cryptographic keys, key chains, and certificates
-
OSPFv3, SNMPv3, and SSH configurations that use approved algorithms
Review the requirements before enabling FIPS mode. Then configure the cryptographic material and services that the router requires.
FIPS mode
Explains the FIPS 140-2 cryptographic-module standard, the Cisco Common Cryptographic Module, and the Cisco IOS XR applications verified for FIPS compliance.
FIPS-compliant cryptographic keys
Explains when cryptographic key pairs require manual generation, how key purpose affects RSA generation, and which generated keys appear in the running configuration.
Cryptographic services in FIPS mode
Explains how key chains, certificates, OSPFv3, and SNMPv3 use documented cryptographic algorithms and key material after FIPS mode is enabled.
SSH clients and servers in FIPS mode
Explains how SSH clients select documented FIPS-approved ciphers and how SSH version 2 servers use supported key-exchange, cipher, and HMAC algorithms.