Verifying That FIPS Self-Tests Are Taking Place
Purpose
Verify that FIPS self-tests are taking place on the switch.
Action
You can run FIPS self-tests manually by issuing the request system reboot command.
After a self-test is run on the switch, the system log (syslog) file is updated to display the known answer tests (KATs) that are executed. To view the system log file, issue the command file show /var/log/messages:
user@switch:fips> file show /var/log/messages
Oct 25 22:28:50 host kernel_kats[5358]: DES3-CBC Known Answer Test: Passed Oct 25 22:28:50 host kernel_kats[5358]: HMAC-SHA1 Known Answer Test: Passed Oct 25 22:28:50 host kernel_kats[5358]: HMAC-SHA2-256 Known Answer Test: Passed Oct 25 22:28:50 host kernel_kats[5358]: SHA-2 Known Answer Test: Passed Oct 25 22:28:50 host kernel_kats[5358]: AES128-CMAC Known Answer Test: Passed Oct 25 22:28:50 host kernel_kats[5358]: AES-CBC Known Answer Test: Passed Oct 25 22:28:50 host kernel_kats[5358]: FIPS Known Answer Tests passed Oct 25 22:28:50 host md_kats[5360]: HMAC-SHA1 Known Answer Test: Passed Oct 25 22:28:50 host md_kats[5360]: HMAC-SHA2-256 Known Answer Test: Passed Oct 25 22:28:50 host md_kats[5360]: FIPS Known Answer Tests passed Oct 25 22:28:50 host openssl_kats[5362]: FIPS RNG Known Answer Test: Passed Oct 25 22:28:57 host openssl_kats[5362]: FIPS DSA Known Answer Test: Passed Oct 25 22:28:57 host openssl_kats[5362]: FIPS ECDSA Known Answer Test: Passed Oct 25 22:28:58 host openssl_kats[5362]: FIPS ECDH Known Answer Test: Passed Oct 25 22:29:00 host openssl_kats[5362]: FIPS RSA Known Answer Test: Passed Oct 25 22:29:00 host openssl_kats[5362]: DES3-CBC Known Answer Test: Passed Oct 25 22:29:00 host openssl_kats[5362]: HMAC-SHA1 Known Answer Test: Passed Oct 25 22:29:00 host openssl_kats[5362]: SHA-2 Known Answer Test: Passed Oct 25 22:29:00 host openssl_kats[5362]: AES-CBC Known Answer Test: Passed Oct 25 22:29:00 host openssl_kats[5362]: ECDSA-SIGN Known Answer Test: Passed Oct 25 22:29:00 host openssl_kats[5362]: KDF-IKE-V1 Known Answer Test: Passed Oct 25 22:29:00 host openssl_kats[5362]: FIPS Known Answer Tests passed Oct 25 22:29:00 host ssh_ipsec_kats[5364]: DES3-CBC Known Answer Test: Passed Oct 25 22:29:00 host ssh_ipsec_kats[5364]: HMAC-SHA1 Known Answer Test: Passed Oct 25 22:29:00 host ssh_ipsec_kats[5364]: HMAC-SHA2-256 Known Answer Test: Passed Oct 25 22:29:00 host ssh_ipsec_kats[5364]: SHA-2 Known Answer Test: Passed Oct 25 22:29:00 host ssh_ipsec_kats[5364]: AES-CBC Known Answer Test: Passed Oct 25 22:29:01 host ssh_ipsec_kats[5364]: SSH-RSA-ENC Known Answer Test: Passed Oct 25 22:29:03 host ssh_ipsec_kats[5364]: SSH-RSA-SIGN Known Answer Test: Passed Oct 25 22:29:03 host ssh_ipsec_kats[5364]: KDF-IKE-V1 Known Answer Test: Passed Oct 25 22:29:03 host ssh_ipsec_kats[5364]: FIPS Known Answer Tests passed
Meaning
The system log file displays the date and time at which each KAT was executed, the name of the test, and its status.