Explains how key chains, certificates, OSPFv3, and SNMPv3 use documented cryptographic algorithms and key material after FIPS mode is enabled.
Cryptographic services in FIPS mode are router functions that
-
use documented cryptographic algorithms and key material
-
protect authentication, certificate, routing, and management operations, and
-
must meet the applicable FIPS mode requirements before they can operate successfully.
Enable FIPS mode before configuring the service-specific key chain, certificate, OSPFv3, or SNMPv3 settings.
Uses of cryptographic services
|
Service or component |
Cryptographic use |
|---|---|
|
Key chain |
Authenticates application sessions with a configured hash or HMAC algorithm. |
|
Certificate |
Associates a certificate trustpoint with cryptographic keys and the required signature-hash or encryption type. |
|
OSPFv3 |
Uses IPsec authentication and encryption to protect routing packets. |
|
SNMPv3 |
Uses authentication and privacy algorithms to protect management access. |