system fips-cc
Use this command to enable and configure Federal Information Processing Standards (FIPS) and Common Criteria (CC) compliant mode.
Syntax
config system fips-cc
set status {enable | disable | fips-ciphers}
set entropy-token {dynamic | enable | disable}
set reseed-interval <reseed-interval_int>
set ssl-client-restrict {enable | disable}
end
Variable | Description | Default |
Select fips-ciphers mode The
For TLS1.3
For TLS1.2
The supported ciphers for SSH traffic include:
fips-ciphers mode.To ensure a truly Once |
disable |
|
Use the entropy token to seed the RNG in FIPS-CC mode.
|
disable
|
|
Set the interval to reseed the RNG. The valid range is 0–1440 minutes. |
1440 |
|
Enable/disable ciphers restriction. |
disable
|