Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Understanding Zeroization to Clear System Data for FIPS Mode

 

Zeroization completely erases all configuration information on the Routing Engines, including all plain-text passwords, secrets, and private keys for SSH, local encryption, and local authentication.

The Security Administrator initiates the zeroization process by entering the request system zeroize operational command from the CLI after enabling FIPS mode. Use of this command is restricted to the Security Administrator.

In reference to cryptographic key destruction, TOE does not support delayed key destruction.

Caution

Perform system zeroization with care. After the zeroization process is complete, no data is left on the Routing Engine. The switch is returned to the factory default state, without any configured users or configuration files.

Zeroization can be time-consuming. Although all configurations are removed in a few seconds, the zeroization process goes on to overwrite all media, which can take considerable time depending on the size of the media.

Why Zeroize?

Your switch is not considered a valid FIPS cryptographic module until all critical security parameters (CSPs) have been entered—or reentered—while the switch is in FIPS mode. You must zeroize the system to remove sensitive information before disabling FIPS mode on the device.

When to Zeroize?

As Security Administrator, perform zeroization in the following situations:

  • Before Enabling FIPS mode of operation: To prepare your switch for operation as a FIPS cryptographic module, perform zeroization before enabling FIPS mode.

  • Before repurposing to non-FIPS mode of operation: To begin repurposing your switch for non-FIPS mode of operation, perform zeroization before disabling FIPS mode on the switch.

    Note

    Juniper Networks does not support installing non-FIPS software in a FIPS environment, but doing so might be necessary in certain test environments. Be sure to zeroize the system first.