How to Enable and Configure Junos OS in FIPS Mode of Operation
You, as Cryptographic Officer, can enable and configure Junos OS in FIPS mode of operation on your device. Before you begin enabling and configuring FIPS mode of operation on the device:
-
Verify the secure delivery of your device.
-
Apply tamper-evident-seals to the cryptographic module, see Applying Tamper-Evident Seals to the Cryptographic Module.
To enable the Junos OS in FIPS mode of operation, perform the following steps:
Zeroize the device before enabling FIPS mode of operation
user@host> request system zeroizeEnable the FIPS mode on the device.
user@host# set system fips level 2Set the root password.
user@host# set system root-authentication plain-text-passwordNew password: type password hereRetype new password: retype password hereRemove the CSPs on commit check and reboot the device.
user@host# commitAfter you reboot the device, perform integrity and self-tests when the module is operating in FIPS mode.
user@host:fips> show version Hostname: host-srx300 Model: srx300-poe-ac Junos: 24.4R2 JUNOS Software Release [24.4R2]