Understanding Zeroization to Clear System Data for FIPS Mode
Zeroization completely erases all configuration information on the Routing Engines, including all plain-text passwords, secrets, and private keys for SSH, local encryption, local authentication, and IPsec.
The Crypto Officer initiates the zeroization process by entering the request system zeroize operational command from the CLI after enabling FIPS mode. Use of this command is restricted to the Crypto Officer. (To zeroize the system before enabling FIPS mode, use the request system zeroize command.)
Perform system zeroization with care. After the zeroization process is complete, no data is left on the Routing Engine. The router is returned to the factory default state, without any configured users or configuration files.
Zeroization can be time-consuming. Although all configurations are removed in a few seconds, the zeroization process goes on to overwrite all media, which can take considerable time depending on the size of the media.
Your router is not considered a valid FIPS cryptographic module until all critical security parameters (CSPs) have been entered—or reentered—while the router is in FIPS mode.
For FIPS 140-2 compliance, you must zeroize the system to remove sensitive information before disabling FIPS mode on the router.
When to Zeroize?
As Crypto Officer, perform zeroization in the following situations:
Before FIPS operation. To prepare your router for operation as a FIPS cryptographic module, perform zeroization before enabling FIPS mode on the router.
Before non-FIPS operation. To begin repurposing your router for non-FIPS operation, perform zeroization before disabling FIPS mode on the router.
Juniper Networks does not support installing non-FIPS software in a FIPS environment, but doing so might be necessary in certain test environments. Be sure to zeroize the system first.
How to Zeroize?
To zeroize the system before enabling FIPS mode, use the below command:
warning: System will be rebooted and may not boot without configuration Erase all data, including configuration and log files? [yes,no] (no) yes warning: zeroizing re0