System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

FIPS mode

Want to summarize with AI?

Log in

Explains the FIPS 140-2 cryptographic-module standard, the Cisco Common Cryptographic Module, and the Cisco IOS XR applications verified for FIPS compliance.


Federal Information Processing Standard (FIPS) 140-2 is a U.S. and Canadian government certification standard that

  • defines requirements for cryptographic modules

  • specifies practices for algorithms, key material, data buffers, and operating-system interaction, and

  • supports level 1 compliance in Cisco IOS XR software through the Cisco Common Cryptographic Module (C3M).

C3M provides FIPS-validated cryptographic primitives and functions that applications and protocols can use.

Applications verified for FIPS compliance

Cisco IOS XR software verifies these applications for FIPS compliance:

  • Secure Shell (SSH)

  • Secure Sockets Layer (SSL)

  • Transport Layer Security (TLS)

  • Internet Protocol Security (IPsec) for Open Shortest Path First version 3 (OSPFv3)

  • Simple Network Management Protocol version 3 (SNMPv3)

  • AAA password security

C3M also provides cryptographic services for protocols and applications such as RTP and 802.1X.


Guidelines and restrictions for FIPS mode

Requirements

Satisfy these requirements before you enable FIPS mode:

  • Use a user group whose associated task group includes the task IDs required by each command. Contact the AAA administrator if a user-group assignment prevents command access.

  • Configure sessions with FIPS-approved cryptographic algorithms.

    OSPF, BGP, RSVP, and IS-IS sessions do not operate in FIPS mode when they use MD5 or HMAC-MD5.

    The same restriction applies to key-chain applications and other applications that use nonapproved algorithms.

  • Use a key string with at least 14 characters for sessions that use an HMAC-SHA algorithm. A session with a shorter key string goes down in FIPS mode.

  • Stop new incoming SSH sessions while configuring or removing FIPS mode, and reload the router after the configuration change.

These requirements apply when you configure, remove, or operate Cisco IOS XR software in FIPS mode.

FIPS mode rejects nonapproved cryptographic operations and requires a reload to finalize a mode change.

Restrictions

Do not use these algorithms in a process that must remain FIPS compliant:

  • Rivest Cipher 4 (RC4)

  • Message Digest 5 (MD5)

  • Keyed-Hash Message Authentication Code MD5 (HMAC-MD5)

  • Data Encryption Standard (DES)

Telnet behavior

FIPS mode rejects new Telnet configuration and Telnet connections.

  • If FIPS mode is already enabled, the system rejects an attempted Telnet configuration.

  • If a Telnet configuration exists before FIPS mode is enabled, the system retains the configuration but rejects Telnet connections.

Recommendation: Enable FIPS mode in a separate commit

Configure crypto fips-mode first, and commit dependent FIPS configurations separately.

FIPS mode rejects configurations such as these examples:

  • key chain sample-keychain key 1 cryptographic-algorithm MD5

  • key chain sample-keychain key 1 cryptographic-algorithm HMAC-MD5

  • router ospfv3 1 authentication ipsec spi 256 md5 sample-md5-value

  • router ospfv3 1 encryption ipsec spi 256 esp des sample-des-value

  • router ospfv3 1 encryption ipsec spi 256 esp des sample-des-value authentication md5 sample-md5-value

  • snmp-server user sample-user sample-group v3 auth md5 priv des56

  • ssh server algorithms key-exchange diffie-hellman-group1-sha1

  • telnet vrf default ipv4 server max-servers 100


Enable FIPS mode

Place the router in FIPS mode so that its cryptographic services enforce approved configurations.

Enabling or removing FIPS mode changes system-wide cryptographic behavior and requires a router reload.

Before you begin

  • Satisfy the access, algorithm, key-string, and Telnet requirements for FIPS mode.

  • Stop new incoming SSH sessions.

Procedure

  1. Enable FIPS mode in global configuration mode, and commit the change.

    Example:

    RP/0/RP0/CPU0:router# configure
    Router(config)# crypto fips-mode
    Router(config)# commit
  2. Verify that the system log reports the FIPS mode change.

    Example:

    Router# show logging
    Syslog logging: enabled (0 messages dropped, 0 flushes, 0 overruns)
         Console logging: level debugging, 60 messages logged
         Monitor logging: level debugging, 0 messages logged
         Trap logging: level informational, 0 messages logged
         Buffer logging: level debugging, 3 messages logged
    
    Log Buffer (9000000 bytes):
    <output omitted>
    The configuration setting for FIPS mode has been modified. The system must be reloaded to finalize this configuration change.

    Use show logging | i fips to filter FIPS-specific logging messages.

  3. Reload all locations.

    Example:

    Router# reload location all

    The router reloads all nodes on the single-chassis or multishelf system.

The router starts in FIPS mode and enforces the applicable cryptographic requirements.