FIPS 자체 테스트 이해
암호화 모듈은 FIPS 작동 모드에서 주니퍼 네트웍스 Junos 운영체제(Junos OS)를 실행하는 디바이스가 FIPS 140-3 레벨 2의 보안 요구 사항을 충족하도록 보안 규칙을 적용합니다. FIPS에 대해 승인된 암호화 알고리즘의 출력을 검증하고 일부 시스템 모듈의 무결성을 테스트하기 위해 디바이스는 다음과 같은 일련의 알려진 응답 테스트(KAT) 자체 테스트를 수행합니다.
-
kernel_kats—커널 암호화 루틴을 위한 KAT -
md_kats- libmd 및 libc의 경우 KAT -
openssl_kats- OpenSSL 암호화 구현을 위한 KAT -
openssl-102_kats—OpenSSL v1.0.2 암호화 구현을 위한 KAT -
quicksec_7_0_kats—Quicksec_7_0Toolkit 암호화 구현을 위한 KAT -
srxpfe_kats—SRX 패킷 포워딩 엔진용 KAT
KAT 자체 테스트는 디바이스에서 FIPS 작동 모드가 활성화된 경우 시작 및 재부팅 시 자동으로 수행됩니다. 또한 조건부 자체 테스트가 자동으로 수행되어 디지털 서명된 소프트웨어 패키지, 생성된 난수, RSA 및 ECDSA 키 쌍, 수동으로 입력한 키를 검증합니다.
KAT가 성공적으로 완료되면 시스템 로그(syslog) 파일이 업데이트되어 실행된 테스트가 표시됩니다.
디바이스가 KAT에 실패하면 디바이스는 시스템 로그 파일에 세부 정보를 기록하고 FIPS 오류 상태(패닉)를 입력한 후 재부팅합니다.
명령은 file show /var/log/messages 시스템 로그를 표시합니다.
재부팅이 완료된 후 정상 작동을 계속하십시오. 오류가 발생하면 주니퍼 네트웍스 기술 지원 센터(JTAC)로 문의하십시오.
FIPS 자체 테스트를 구성하려면 관리자 권한이 있어야 합니다. 디바이스는 FIPS 모드 소프트웨어에서 평가된 버전의 Junos OS를 실행해야 합니다.
이 예에서 FIPS 자체 테스트는 매주 수요일 미국 뉴욕시에서 오전 9:00에 실행됩니다.
디바이스에서 전원 켜기 자체 테스트 수행
암호화 모듈의 전원을 켤 때마다 모듈은 암호화 알고리즘이 여전히 올바르게 작동하고 중요한 데이터가 손상되지 않았는지 테스트합니다. 전원 켜기 자체 테스트는 모듈의 전원을 껐다 켜서 필요에 따라 수행됩니다. 장치의 전원을 켜거나 재설정할 때 모듈은 다음 자체 테스트를 수행합니다. 모듈에서 다른 암호화를 사용하기 전에 모든 KAT를 성공적으로 완료해야 합니다. KAT 중 하나가 실패하면 모듈이 심각한 오류 오류 상태로 들어갑니다. 모듈은 전원 켜기 자체 테스트를 실행하는 동안 SRX1600 장치에 대해 다음과 같은 상태 출력을 표시합니다.Initializing Verified Exec: uhub1: 2 ports with 2 removable, self powered uhub0: 10 ports with 10 removable, self powered random: randomdev_wait_until_seeded unblock wait random: Entropy start-up health tests performed on 1024 samples passed. random: unblocking device. random: HMAC-DRBG: instantiated with 1024 SW events, 396 HW Shannons FIPS veriexec ECDSA Verify Known Answer Test: Passed Verified os-kernel-prd-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Enforcing Verified Exec: Verified os-libs-12-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Mounting os-libs-12-x86-64-20231122.ee0e992_builder_stable_12_234 Verified os-runtime-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Mounting os-runtime-x86-64-20231122.ee0e992_builder_stable_12_234 Verified os-package-20231117 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Mounting os-package-20231117.015524_builder_stable_12 ** /dev/gpt/config ** Last Mounted on /.mount/config ** Phase 1 - Check Blocks and Sizes ** Phase 2 - Check Pathnames ** Phase 3 - Check Connectivity ** Phase 4 - Check Reference Counts ** Phase 5 - Check Cyl groups 18 files, 16 used, 406103 free (15 frags, 50761 blocks, 0.0% fragmentation) ***** FILE SYSTEM IS CLEAN ***** ** /dev/gpt/var ** Last Mounted on /.mount/var ** Phase 1 - Check Blocks and Sizes ** Phase 2 - Check Pathnames ** Phase 3 - Check Connectivity ** Phase 4 - Check Reference Counts ** Phase 5 - Check Cyl groups 2429 files, 3384459 used, 269714 free (434 frags, 33660 blocks, 0.0% fragmentation) ***** FILE SYSTEM IS CLEAN ***** @ 1706766571 [2024-02-01 05:49:31 UTC] verify pending ... Verified fips-mode-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified jdocs-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified dsa-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified jmrt-base-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified jinsight-x86-32-23.10 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified jmrt-test-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified jphone-home-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified jsd-x86-32-23.10-jet-1 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified jtpm2-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-daemons-srx-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-daemons-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-km-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-l2-rsi-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-libs-compat32-srx-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-dp-crypto-support-srx-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-libs-srx-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-libs-srxtvp-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-libs-compat32-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-libs-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-modules-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-platform-srx-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-openconfig-x86-32-23.10 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-net-mtx-prd-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-platform-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-pppoe-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-probe-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-redis-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-routing-lsys-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-routing-compat32-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-routing-aggregated-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-routing-controller-external-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-routing-mpls-oam-basic-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-runtime-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-runtime-srxtvp-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-runtime-srx-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-vmguest-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-sysmond-lite-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-statesync-pub-sub-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified jweb-srxtvp-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified na-telemetry-x86-32-23.10 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-boot-junos-ve-x86-32-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified junos-net-prd-x86-64-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-compat32-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-libs-12-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-kernel-prd-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-libs-compat32-12-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-crypto-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-package-20231117 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-runtime-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-vmguest-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-modules-net-x86-64-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified py-base-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified os-zoneinfo-20231122 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Verified py-extensions-x86-32-20231221 signed by PackageProductionECP256_2023 method ECDSA256+SHA256 @ 1706766572 [2024-02-01 05:49:32 UTC] verify done @ 1706766572 [2024-02-01 05:49:32 UTC] activating Verified jail-runtime signed by PackageProductionECP256_2023 method ECDSA256+SHA256 kern.activate_pending_set: 0 -> 1 NOTE: 'pending' set now 'active' @ 1706766572 [2024-02-01 05:49:32 UTC] mount start @ 1706766572 [2024-02-01 05:49:32 UTC] junos 23.4R1.9 Mounting os-zoneinfo-20231122.ee0e992_builder_stable_12_234 Mounting os-libs-compat32-12-x86-64-20231122.ee0e992_builder_stable_12_234 Mounting os-compat32-x86-64-20231122.ee0e992_builder_stable_12_234 Mounting py-extensions-x86-32-20231221.205905_builder_junos_234_r1 Mounting py-base-x86-32-20231221.205905_builder_junos_234_r1 Mounting os-vmguest-x86-64-20231122.ee0e992_builder_stable_12_234 Mounting junos-net-prd-x86-64-20231221.205905_builder_junos_234_r1 Mounting os-crypto-x86-64-20231122.ee0e992_builder_stable_12_234 Mounting junos-libs-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-libs-compat32-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-runtime-x86-32-20231221.205905_builder_junos_234_r1 Starting watchdog daemon ... Mounting na-telemetry-x86-32-23.4R1.9 Mounting junos-vmguest-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-sysmond-lite-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-libs-compat32-srx-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-runtime-srx-x86-32-20231221.205905_builder_junos_234_r1 Mounting junos-platform-srx-x86-32-20231221.205905_builder_junos_234_r1 Mounting junos-platform-x86-32-20231221.205905_builder_junos_234_r1 Mounting junos-runtime-srxtvp-x86-32-20231221.205905_builder_junos_234_r1 Mounting junos-routing-mpls-oam-basic-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-routing-lsys-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-routing-controller-external-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-routing-compat32-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-routing-aggregated-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-redis-x86-32-20231221.205905_builder_junos_234_r1 Mounting junos-probe-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-pppoe-x86-32-20231221.205905_builder_junos_234_r1 Mounting junos-openconfig-x86-32-23.4R1.9 Mounting junos-modules-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-libs-srxtvp-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-libs-srx-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-l2-rsi-20231221.205905_builder_junos_234_r1 Mounting junos-km-x86-32-20231221.205905_builder_junos_234_r1 Mounting junos-dp-crypto-support-srx-x86-32-20231221.205905_builder_junos_234_r1 Mounting junos-daemons-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-daemons-srx-x86-64-20231221.205905_builder_junos_234_r1 Mounting jtpm2-x86-32-20231221.205905_builder_junos_234_r1 Mounting jsd-x86-32-23.4R1.9-jet-1 Mounting jphone-home-x86-32-20231221.205905_builder_junos_234_r1 Mounting jmrt-base-x86-64-20231221.205905_builder_junos_234_r1 Mounting jmrt-test-x86-64-20231221.205905_builder_junos_234_r1 Mounting jinsight-x86-32-23.4R1.9 Mounting jdocs-x86-32-20231221.205905_builder_junos_234_r1 Mounting fips-mode-x86-64-20231221.205905_builder_junos_234_r1 Mounting dsa-x86-64-20231221.205905_builder_junos_234_r1 @ 1706766593 [2024-02-01 05:49:53 UTC] mount done Removing /etc/malloc.conf Detected data disk Initialize /var subdirs... Mounting shared partition /var/host .. Detected swap drive Enable swap *** Creating PVIDb..\n 1754+0 records in 1754+0 records out 912080 bytes transferred in 0.009332 secs (97732756 bytes/sec) Copied libschema-filter-dd.tlv to /opt/lib/dd/filter\n Executing the Junos host files signature script Verified manifest signed by PackageDevelopmentECP256_2023 method ECDSA256+SHA256 *** Mounting Host disks ... @ 1706766594 [2024-02-01 05:49:54 UTC] vmguest: setup ... @ 1706766594 [2024-02-01 05:49:54 UTC] vmguest: mounted /dev/vtbd3s2 ERROR: cannot find: jsim-pfe usage: /usr/sbin/pkg add ... where is a directory or compressed tar file Mounting the /dev/vtbd3s2 to /var/host Verified manifest signed by PackageDevelopmentECP256_2023 method ECDSA256+SHA256 /usr/sbin/pkg: package fips-mode-x86-64-20231221.205905_builder_junos_234_r1 is already installed Checking platform support for: srxtvp Attempting to add missing junos-modules-srxtvp Verified junos-modules-srxtvp signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Adding junos-modules-srxtvp-x86-64-20231221.205905_builder_junos_234_r1 ... The package junos-modules-srxtvp-x86-64-20231221.205905_builder_junos_234_r1 is now active Attempting to add missing junos-appsecure-tvp Verified junos-appsecure-tvp signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Adding junos-appsecure-tvp-x86-32-20231221.205905_builder_junos_234_r1 ... The package junos-appsecure-tvp-x86-32-20231221.205905_builder_junos_234_r1 is now active Attempting to add missing junos-ike Verified junos-ike signed by PackageProductionECP256_2023 method ECDSA256+SHA256 Adding junos-ike-x86-32-20231221.205905_builder_junos_234_r1 ... The package junos-ike-x86-32-20231221.205905_builder_junos_234_r1 is now active Mounting junos-modules-srxtvp-x86-64-20231221.205905_builder_junos_234_r1 Mounting junos-appsecure-tvp-x86-32-20231221.205905_builder_junos_234_r1 @ 1706766596 [2024-02-01 05:49:56 UTC] mountlate start Mounting jweb-srxtvp-x86-32-20231221.205905_builder_junos_234_r1 veriexec: /packages/mnt/jweb-srxtvp-1b9a5fd9/jail/html/jsdm/javascript/intf-config-gui.js.gz mode 555 != 444 veriexec: chmod 444 /packages/mnt/jweb-srxtvp-1b9a5fd9/jail/html/jsdm/javascript/intf-config-gui.js.gz: Bad file descriptor veriexec: /packages/mnt/jweb-srxtvp-1b9a5fd9/jail/usr/lib/hooks/pvidb/libpvidb_hooks.so mode 444 != 555 veriexec: chmod 555 /packages/mnt/jweb-srxtvp-1b9a5fd9/jail/usr/lib/hooks/pvidb/libpvidb_hooks.so: Bad file descriptor veriexec: /packages/mnt/jweb-srxtvp-1b9a5fd9/jail/webapi/mime.types uid:gid 930:950 != 0:0 veriexec: chown 0:0 /packages/mnt/jweb-srxtvp-1b9a5fd9/jail/webapi/mime.types: Bad file descriptor veriexec: /packages/mnt/jweb-srxtvp-1b9a5fd9/jail/webapi/nginx.conf uid:gid 930:950 != 0:0 veriexec: chown 0:0 /packages/mnt/jweb-srxtvp-1b9a5fd9/jail/webapi/nginx.conf: Bad file descriptor Setup /packages/mnt/jweb-srxtvp-1b9a5fd9/jail/var/cache dir only for srxtvp mount_nullfs: /web-api: No such file or directory Mounting junos-statesync-pub-sub-x86-32-20231221.205905_builder_junos_234_r1 Mounting junos-ike-x86-32-20231221.205905_builder_junos_234_r1 @ 1706766599 [2024-02-01 05:49:59 UTC] mountlate done kern.module_path: /packages/sets/pending/boot/os-vmguest/;/packages/sets/pending/boot/os-crypto/;/packages/sets/pending/boot/netstack/;/packages/sets/pending/boot/junos-statesync-pub-sub/;/packages/sets/pending/boot/junos-modules/;/packages/sets/pending/boot/junos-net-platform/;/packages/sets/pending/boot/os-kernel/;/packages/sets/pending/boot/os-modules-net/ -> /modules;/modules/ifpfe_drv;/modules/ifpfe_media;/modules/peertype;/modules/platform Loading JUNOS chassis module chassis_init_hw_chassis_startup_time: chassis startup time 0.000000, shared: 0x7ffffffff340, base: 0x7ffffffff000, offset: 0x340 IPsec: Initialized Security Association Processing. Loading the SLB driver Loading the Protobuf-C module hgcommdev0: port 0xc000-0xc0ff mem 0xfeb9f000-0xfeb9ffff at device 22.0 on pci0 hgcommdev0: hgcommdev: registers at 0xfffff800feb9f000 pci-hgcomdev module loaded bcmsdk_5_9_x kld Loading BCMSDK module..... Junosprocfs mounted on /junosproc. VirtIO PCI 9P Transport adapter is not present @ 1706766601 [2024-02-01 05:50:01 UTC] mgd start Creating initial configuration: ... mgd: Running FIPS Self-tests mgd: Testing kernel KATS: mgd: NIST 800-90 HMAC DRBG Known Answer Test: Passed mgd: DES3-CBC Known Answer Test: Passed mgd: HMAC-SHA1 Known Answer Test: Passed mgd: HMAC-SHA2-256 Known Answer Test: Passed mgd: SHA-2-384 Known Answer Test: Passed mgd: SHA-2-512 Known Answer Test: Passed mgd: AES128-CMAC Known Answer Test: Passed mgd: AES-CBC Known Answer Test: Passed mgd: Testing MACSec KATS: mgd: AES128-CMAC Known Answer Test: Passed mgd: AES256-CMAC Known Answer Test: Passed mgd: AES-ECB Known Answer Test: Passed mgd: AES-KEYWRAP Known Answer Test: Passed mgd: KBKDF Known Answer Test: Passed mgd: Testing libmd KATS: mgd: HMAC-SHA1 Known Answer Test: Passed mgd: HMAC-SHA2-256 Known Answer Test: Passed mgd: SHA-2-512 Known Answer Test: Passed mgd: Testing OpenSSL v1.0.2 KATS: mgd: FIPS ECDSA Known Answer Test: Passed mgd: FIPS ECDH Known Answer Test: Passed mgd: DES3-CBC Known Answer Test: Passed mgd: HMAC-SHA1 Known Answer Test: Passed mgd: HMAC-SHA2-224 Known Answer Test: Passed mgd: HMAC-SHA2-256 Known Answer Test: Passed mgd: HMAC-SHA2-384 Known Answer Test: Passed mgd: HMAC-SHA2-512 Known Answer Test: Passed mgd: AES-CBC Known Answer Test: Passed mgd: AES-GCM Known Answer Test: Passed mgd: RSA-ENC Known Answer Test: Passed mgd: RSA-SIGN Known Answer Test: Passed mgd: KDF-IKE-V1 Known Answer Test: Passed mgd: KDF-SSH-SHA256 Known Answer Test: Passed mgd: KAS-ECC-EPHEM-UNIFIED-NOKC Known Answer Test: Passed mgd: KAS-FFC-EPHEM-NOKC Known Answer Test: Passed mgd: Testing OpenSSL KATS: mgd: FIPS ECDSA Known Answer Test: Passed mgd: FIPS ECDH Known Answer Test: Passed mgd: DES3-CBC Known Answer Test: Passed mgd: HMAC-SHA1 Known Answer Test: Passed mgd: HMAC-SHA2-224 Known Answer Test: Passed mgd: HMAC-SHA2-256 Known Answer Test: Passed mgd: HMAC-SHA2-384 Known Answer Test: Passed mgd: HMAC-SHA2-512 Known Answer Test: Passed mgd: AES-CBC Known Answer Test: Passed mgd: AES-GCM Known Answer Test: Passed mgd: RSA-ENC Known Answer Test: Passed mgd: RSA-SIGN Known Answer Test: Passed mgd: KDF-IKE-V1 Known Answer Test: Passed mgd: KDF-SSH-SHA256 Known Answer Test: Passed mgd: KAS-ECC-EPHEM-UNIFIED-NOKC Known Answer Test: Passed mgd: KAS-FFC-EPHEM-NOKC Known Answer Test: Passed mgd: Testing QuickSec 7.0 KATS: mgd: DES3-CBC Known Answer Test: Passed mgd: HMAC-SHA1 Known Answer Test: Passed mgd: HMAC-SHA2-224 Known Answer Test: Passed mgd: HMAC-SHA2-256 Known Answer Test: Passed mgd: HMAC-SHA2-384 Known Answer Test: Passed mgd: HMAC-SHA2-512 Known Answer Test: Passed mgd: AES-CBC Known Answer Test: Passed mgd: AES-GCM Known Answer Test: Passed mgd: SSH-RSA-ENC Known Answer Test: Passed mgd: SSH-RSA-SIGN Known Answer Test: Passed mgd: SSH-ECDSA-SIGN Known Answer Test: Passed mgd: KDF-IKE-V1 Known Answer Test: Passed mgd: KDF-IKE-V2 Known Answer Test: Passed mgd: Testing QuickSec KATS: mgd: DES3-CBC Known Answer Test: Passed mgd: HMAC-SHA1 Known Answer Test: Passed mgd: HMAC-SHA2-224 Known Answer Test: Passed mgd: HMAC-SHA2-256 Known Answer Test: Passed mgd: HMAC-SHA2-384 Known Answer Test: Passed mgd: HMAC-SHA2-512 Known Answer Test: Passed mgd: AES-CBC Known Answer Test: Passed mgd: AES-GCM Known Answer Test: Passed mgd: SSH-RSA-ENC Known Answer Test: Passed mgd: SSH-RSA-SIGN Known Answer Test: Passed mgd: KDF-IKE-V1 Known Answer Test: Passed mgd: KDF-IKE-V2 Known Answer Test: Passed mgd: Testing SSH IPsec KATS: mgd: NIST 800-90 HMAC DRBG Known Answer Test: Passed mgd: DES3-CBC Known Answer Test: Passed mgd: HMAC-SHA1 Known Answer Test: Passed mgd: HMAC-SHA2-256 Known Answer Test: Passed mgd: AES-CBC Known Answer Test: Passed mgd: SSH-RSA-ENC Known Answer Test: Passed mgd: SSH-RSA-SIGN Known Answer Test: Passed mgd: KDF-IKE-V1 Known Answer Test: Passed mgd: Testing file integrity: mgd: File integrity Known Answer Test: Passed mgd: Testing crypto integrity: mgd: Crypto integrity Known Answer Test: Passed mgd: Expect an exec Authentication error... MAC/veriexec: no fingerprint (file=/sbin/kats/cannot-exec fsid=233 fileid=49356 gen=1 uid=0 pid=27334 ppid=27301 gppid=27298)mgd: /sbin/kats/run-tests: /sbin/kats/cannot-exec: Authentication error mgd: FIPS Self-tests Passed