Enabling FIPS mode
You, as Crypto Officer, can enable and configure Junos OS in FIPS mode on your router or switch.
Before you begin enabling and configuring FIPS mode on the router or switch:
Verify the secure delivery of your router or switch. See Identifying Secure Delivery.
To enable and configure Junos OS in FIPS mode, perform the following tasks. Follow the links for instructions.
- Connect to console port and zeroize the device to delete all CSPs before entering FIPS mode.
- After the device comes up in ’Amnesiac mode’,
login using username root and password "" (blank).FreeBSD/amd64 (Amnesiac) (ttyu0)login: root
--- JUNOS 17.3R2 Kernel 64-bit JNPR-10.3-20171116.170330_fbsd-
At least one package installed on this device has limited support.
Run 'file show /etc/notices/unsupported.txt' for details.root@:~ #
- Configure root authentication.root> edit
Entering configuration mode
root# set system root-authentication plain-text-password
Retype new password:
- Load configuration onto device and commit new configuration.
- Configure Crypto Officer authentication and login using Crypto Officer credentials.
- Install fips-mode package needed for Routing Engine KATS.crypto-officer@hostname> request system software add optional://fips-mode.tgz
Verified fips-mode signed by PackageDevelopmentEc_2017 method ECDSA256+SHA256
- Configure fips level 1 and commit.crypto-officer@hostname>edit
Entering configuration modecrypto-officer@hostname# set system fips level 1
Device might display Encrypted-password must be re-configured to use FIPS compliant hash warning to delete older CSP in loaded configuration.
- After deleting and reconfiguring CSPs, commit will go
through and device needs reboot to enter FIPS mode.crypto-officer@hostname# commit
Generating RSA key /etc/ssh/fips_ssh_host_key Generating ECDSA key /etc/ssh/fips_ssh_host_ecdsa_key
reboot is required to transition to FIPS level 1
- After rebooting the device, FIPS self-tests will run and
device enters FIPS mode.crypto-officer@hostname>
After you as the Crypto Officer complete Junos OS in FIPS mode configuration, you can connect the router or switch to the network and proceed with normal configuration.