AMLS-NM-200825 - The Arista Multilayer Switch must use FIPS-compliant mechanisms for authentication to a cryptographic module - SSH FIPS

Information

Unapproved mechanisms that are used for authentication to the cryptographic module are not verified and therefore cannot be relied upon to provide confidentiality or integrity, and DoD data may be compromised.

Network devices utilizing encryption are required to use FIPS-compliant mechanisms for authenticating to cryptographic modules.

FIPS 140-2 is the current standard for validating that mechanisms used to access cryptographic modules utilize authentication that meets DoD requirements.

Solution

Enable FIPS restrictions via the following commands:
Enable
Configure
Management ssh
Fips restrictions
Exit

Additionally, the switch should be configured to use its Hardware Random Number Generator as a source of entropy for the SSH protocol. To enable this, configure:

Enable
Configure
Management security
Entropy source hardware

Once this has been changed, regenerate the SSH RSA Keys with:

Reset ssh hostkey rsa

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Arista_MLS_DCS-7000_Series_Y20M07_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000803, Group-ID|V-67197, Rule-ID|SV-81687r1_rule, STIG-ID|AMLS-NM-200825, Vuln-ID|V-67197

Plugin: Arista

Control ID: 42dc543f8138931ba2e9a68360b59a6e450d8347a05c533c8b871a6a5cb4d9ce