system fips-cc
Use this command to enable and configure Federal Information Processing Standards (FIPS) and Common Criteria (CC) compliant mode.
The following FortiWeb images don't support fips-cc
mode:
-
FWB_HYPERV
-
FWB_XENAWS
-
FWB_XENAWS_ONDEMAND
-
FWB_AWSCLD
-
FWB_VM_PAYG
-
FWB_AZURE
-
FWB_AZURE_ONDEMAND
-
FWB_KVM
-
FWB_KVM_PAYG
-
FWB_GCP
-
FWB_GCP_ONDEMAND
-
FWB_OCI
-
FWB_OCI_ONDEMAND
-
FWB_ALI
-
FWB_FTCLD
-
FWB_GCPCLD
-
FWB_OCICLD
The fips-ciphers
mode is only supported by the following images:
-
FWB_XENAWS
-
FWB_XENAWS_ONDEMAND
-
FWB_AZURE
-
FWB_AZURE_ONDEMAND
Syntax
config system fips-cc
set status {enable | disable | fips-ciphers}
set entropy-token {dynamic | enable | disable}
set reseed-interval <reseed-interval_int>
set ssl-client-restrict {enable | disable}
end
Variable | Description | Default |
Select fips-ciphers mode The
For TLS1.3
For TLS1.2
The supported ciphers for SSH traffic include:
fips-ciphers mode.To ensure a truly Once |
disable |
|
Use the entropy token to seed the RNG in FIPS-CC mode.
|
disable |
|
Set the interval to reseed the RNG. The valid range is 0–1440 minutes. |
1440 |
|
Enable/disable ciphers restriction. | disable
|