Summary
This document explains about the requirement and configuration required in PTP 820 for FIPS 140-2-Compliance
Cause
The objective of FIPS 140-2 is to provide a standard for secured communication devices, with an emphasis on encryption and cryptographic methods. The FIPS standards are broadcasted by the National Institute of Standards and Technology (NIST) and provide an extensive set of requirements for both hardware and software. It is the responsibility of the customer to ensure that the above FIPS requirements are met
Solution
In order to confirm that the radios are FIPS 140-2 Compliance, we must ensure that:
- To use the FIPS hardware
- The FIPS validated software version to be used.
PTP 820 FIPS Requirements and Configuration
Release 8.3, PTP 820G PTP 820C and PTP 820S can be configured to be FIPS 140-2-compliant in specific hardware and software configurations.
Hardware Requirements
For PTP 820 C/S/G nodes to be FIPS-compliant, the unit must be FIPS-compliant hardware.
Software Requirements
FIPS compliance requires the user to operate the PTP 820C/S/G in FIPS mode. FIPS mode must be enabled by the user. It can be enabled via the Web EMS, the CLI, or SNMPv3. Enabling FIPS mode requires a system reset.
Requirements for FIPS Compliance:
For PTP 820C or PTP 820S node to be FIPS-compliant, the unit must be FIPS-compliance hardware.
For PTP 820G node to be FIPS-compliant, the chassis must be FIPS-compliant.
For PTP 820C, PTP 820S, or PTP 820G AES-256 Payload Encryption must be configured
Note: Special labels must be affixed to a FIPS-compliant PTP 820G unit. These labels are tamper-evident and must be applied in such a way that it is not possible to open the chassis. These labels must be replaced whenever components are added to or removed from the unit. Replacement labels can be ordered from Cambium Networks. Tamper-evident labels should be inspected for integrity at least once every six months. For further details, refer to the PTP 820G Installation Guide.
Enabling FIPS Mode from GUI
To set the unit to operate in FIPS mode:
1.Select Platform > Security > General > Configuration. The Security General Configuration page opens:
2.Click on enable under FIPS admin configuration and then apply the configuration:
Note: Changing the FIPS configuration causes a unit reset.
3.Apply the same configuration on second radio as well.
Enabling FIPS Mode from CLI
To set the unit to operate in FIPS mode, enter the following command in root view:
root> platform security fips-mode set admin enable
Note: Changing the FIPS configuration causes a unit reset.
To disable FIPS mode, enter the following command in root view:
root> platform security fips-mode set admin disable
To display the unit’s current FIPS setting, enter the following command in root view:
root> platform security fips-mode show
Status values are:
- enable – FIPS mode is enabled.
- disable – FIPS mode is disabled.
Enabling FIPS Mode from SNMP
The below MIB OID to be used for enabling the FIPS admin configuration and to check the status:
MIB OID |
MIB Name |
MIB Type |
MIB Access |
Description |
1.3.6.1.4.1.2281.10.11.10.1 |
genEquipSecurityFipsAdmin |
INTEGER (2..3) |
read-write |
FIPS admin configuration parameter |
1.3.6.1.4.1.2281.10.11.10.2.0 |
genEquipSecurityFipsStatus |
INTEGER {down(0) Up (1)} |
read-only |
FIPS operational status |
After enabling FIPS:
- The MD5 option for SNMPv3 is blocked.
- After any system reset, the length of time before users can log back into the system is longer than usual due to FIPS-related self-testing.
FIPS certified latest software versions:
https://support.cambiumnetworks.com/files/ptp820/#r2
For PTP 820 C & S - PTP820CS - G2U-8.3.0.0.0.517 Firmware 12-December-2018
For PTP 820 G - PTP820G - G2U-8.3.0.0.0.517 Firmware 12-December-2018
FIPS certified PTP 820 G/C/S part numbers:
FIPS certified PTP 820 C part numbers |
||
SN |
Part number |
Description |
1 |
C150082B051 |
PTP 820C FIPS-140 Ready Radio,15GHz,TR640,ChH,Hi,15245-15355MHz |
2 |
C150082B052 |
PTP 820C FIPS-140 Ready Radio,15GHz,TR640,ChH,Lo,14605-14715MHz |
3 |
C150082B050 |
PTP 820C FIPS-140 Ready Radio,NTIA 15GHz,TR640,All, Lo,14500-14710MHz |
4 |
C150082B049 |
PTP 820C FIPS-140 Ready Radio,NTIA 15GHz,TR640,All,Hi,15140-15350MHz |
5 |
C230082B035 |
PTP 820C FIPS-140 Ready Radio,NTIA 23GHz,TR1200,ChH,Hi,23000-23600MHz |
6 |
C230082B036 |
PTP 820C FIPS-140 Ready Radio,NTIA 23GHz,TR1200,ChH,Lo,21780-22400MHz |
7 |
C230082B033 |
PTP 820C FIPS-140 Ready Radio,NTIA 23GHz,TR1200,ChL,Hi,22400-23020MHz |
8 |
C230082B034 |
PTP 820C FIPS-140 Ready Radio,NTIA 23GHz,TR1200,ChL,Lo,21200-21800MHz |
9 |
C070082B093 |
PTP 820C FIPS-140 Ready Radio,NTIA 7GHz,TR300,Ch1W5,Hi,7434.5-7585.5MHz |
10 |
C070082B094 |
PTP 820C FIPS-140 Ready Radio,NTIA 7GHz,TR300,Ch1W5,Lo,7134.5-7285.5MHz |
11 |
C070082B095 |
PTP 820C FIPS-140 Ready Radio,NTIA 7GHz,TR300,Ch6W10,Hi,7584.5-7765.5MHz |
12 |
C070082B096 |
PTP 820C FIPS-140 Ready Radio,NTIA 7GHz,TR300,Ch6W10,Lo,7284.5-7465.5MHz |
13 |
C080082B087 |
PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch1W5,Hi,8095-8245MHz |
14 |
C080082B088 |
PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch1W5,Lo,7735-7885MHz |
15 |
C080082B089 |
PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch5W9,Hi,8215-8365MHz |
16 |
C080082B090 |
PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch5W9,Lo,7855-8005MHz |
17 |
C080082B091 |
PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch9W13,Hi,8335-8485MHz |
18 |
C080082B092 |
PTP 820C FIPS-140 Ready Radio,NTIA 8GHz,TR360,Ch9W13,Lo,7975-8125MHz |
FIPS certified PTP 820 G part numbers |
||
SN |
Part number |
Description |
1 |
C000082M021 |
PTP 820G NTIA FIPS-140 Ready, Dual Modem, Eth + 16 E1/T1 |
2 |
N000082H004 |
PTP 820GX RMC-B card, FIPS-140 Ready |
3 |
N000082H002 |
PTP 820GX TCC-B2 Card, FIPS-140 Ready |
4 |
N000082H003 |
PTP 820GX TCC-B2-XG-MC card, FIPS-140 Ready |
5 |
N000082H001 |
PTP 820GX TCC-B-MC Card, FIPS-140 Ready |
FIPS certified PTP 820 S part numbers |
||
SN |
Part number |
Description |
1 |
C150082B047 |
PTP 820S FIPS-140 Ready Radio,15GHz,TR640,ChH,Hi,15245-15355MHz |
2 |
C150082B048 |
PTP 820S FIPS-140 Ready Radio,15GHz,TR640,ChH,Lo,14605-14715MHz |
3 |
C150082B045 |
PTP 820S FIPS-140 Ready Radio,15GHz,TR640,ChL,Hi,15140-15250MHz |
4 |
C150082B046 |
PTP 820S FIPS-140 Ready Radio,15GHz,TR640,ChL,Lo,14500-14610MHz |
5 |
C070082B089 |
PTP 820S FIPS-140 Ready Radio,7GHz,TR300A,Ch1W5,Hi,7434.5-7585.5MHz |
6 |
C070082B090 |
PTP 820S FIPS-140 Ready Radio,7GHz,TR300A,Ch1W5,Lo,7134.5-7285.5MHz |
7 |
C070082B091 |
PTP 820S FIPS-140 Ready Radio,7GHz,TR300A,Ch6W10,Hi,7584.5-7765.5MHz |
8 |
C070082B092 |
PTP 820S FIPS-140 Ready Radio,7GHz,TR300A,Ch6W10,Lo,7284.5-7465.5MHz |
9 |
C080082B081 |
PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch1W5,Hi,8095-8245MHz |
10 |
C080082B082 |
PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch1W5,Lo,7735-7885MHz |
11 |
C080082B083 |
PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch5W9,Hi,8215-8365MHz |
12 |
C080082B084 |
PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch5W9,Lo,7855-8005MHz |
13 |
C080082B085 |
PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch9W13,Hi,8335-8485MHz |
14 |
C080082B086 |
PTP 820S FIPS-140 Ready Radio,8GHz,TR360A,Ch9W13,Lo,7975-8125MHz |