HP VPN Firewall Appliances Access Control Command Reference

Table Of Contents
258
The SSL server only supports TLS1.0.
The SSH server does not support SSHv1 clients
The SSH only supports RSA.
RSA key pairs must have a modulus length of 2048 bits, and DSA key pairs must have a modulus
length from 1024 to 2048 bits.
SSH, SNMPv3, IPsec and SSL do not support DES, RC4, 3DES, or MD5.
Related commands: display fips status.
Examples
# Enable FIPS mode.
<Sysname> system-view
[Sysname] fips mode enable
fips self-test
Syntax
fips self-test
View
System view
Default Level
3: Manage level
Parameters
None
Description
Use the fips self-test command to trigger a self-test on the password algorithms.
To verify whether the password algorithm modules operate correctly, use this command to trigger a
self-test on the password algorithms. The triggered self-test is the same as the automatic self-test when the
device starts up.
If the self-test fails, the device automatically reboots.
This command is available only when the device starts up with the configuration file where the fips mode
enable command is configured.
Example
# Trigger a self-test on the password algorithms.
<Sysname> fips self-test
Self-tests are running. Please wait...
Self-tests succeeded.
display fips status
Syntax
display fips status