Applying Tamper-Evident Seals to the Cryptographic Module
The physical embodiment of the cryptographic module included in the device is that of a multi-chip standalone device that meets FIPS 140-3 Level 2 physical security requirements. The module is completely enclosed in a rectangular nickel door clear zinc coated, cold rolled steel, plated steel, and brushed aluminum enclosure. There are no ventilation holes, gaps, slits, cracks, slots, or crevices that would allow for any sort of observation of any component contained within the cryptographic boundary. Tamper-evident seals allow the operator to verify if the enclosure has been breached. These seals are not factory-installed and must be applied by the Cryptographic Officer.
Seals are available for order from Juniper Networks using part number JNPR-FIPS-TAMPER-LBLS.
As a Cryptographic Officer, you are responsible for:
Applying seals to secure the cryptographic module
Controlling any unused seals
Controlling and observing any changes, such as repairs or booting from an external USB drive to the cryptographic module, that require removing or replacing the seals to maintain the security of the module
As per the security inspection guidelines, upon receipt of the cryptographic module, the Cryptographic Officer must check that the labels are free of any sings of potential tampering.
General Tamper-Evident Seal Instructions
All FIPS-certified switches with USB ports require a tamper-evident seal on the USB port. The SRX345 and SRX345-DUAL-AC variants implement USB ports which must be protected by tamper-evident seals.
While applying seals, follow these general instructions:
Handle the seals with care. Do not touch the adhesive side. Do not cut or otherwise resize a seal to make it fit.
Make sure all surfaces to which the seals are applied are clean and dry and clear of any residue.
Apply the seals with firm pressure across the seal to ensure adhesion. Allow at least 24 hours for the adhesive to cure.
Applying Tamper-Evident Seals on SRX300, SRX320, SRX340, SRX345, and SRX345-DUAL-AC Devices
On SRX300, SRX320, SRX340, SRX345, and SRX345-DUAL-AC devices, apply tamper-evident seals at the following locations in addition to those placed on the USB ports on the SRX345 and SRX345-DUAL-AC models:
-
Apply four seals on the front I/O slots.
-
Apply five seals at the top of the chassis, covering each of the five chassis screws.
-
Apply two seals at the front of the chassis on either side of the LED matrix on the right of the device.
-
Apply two seals on the rear panel, covering the blank faceplate. If the grounding connection is not used, apply a seal across this as well.