Document toolboxDocument toolbox

set fips_mode

You can use the set fips_mode command to enable the FIPS mode. This command restarts the appliance to go through the boot time self tests when it exits the FIPS mode.

  • In a Grid, you can set the FIPS mode only on the Grid Master. The setting is propagated to all Grid members during the joining process. After the configuration is changed, the members will be restarted.
  • You can set the FIPS mode on standalone systems.
  • In an HA setup, you can set the FIPS mode only on the standalone Grid Master, and then configure it as a node in the HA pair. Perform the same step for the second node of the HA pair. You cannot change the FIPS mode setting on the HA Grid Master or the HA member.

To enable or disable the FIPS configuration, connect to the CLI console, and then enter the set fips_mode command. For more information, see Enabling / Disabling the FIPS Mode.

To clear the FIPS mode, you can use the reset all command. For more information, see reset all.

Note

You must perform a factory reset to reset the appliance to its original factory settings before using the FIPS mode.

Syntax

set fips_mode
This command has no arguments.

Examples

Infoblox > set fips_mode
Enable FIPS mode? (y or n): y
New FIPS Mode Settings:
  FIPS mode enabled: Yes
    is this correct? (y or n): y
Please refer to the Guidance Documentation Supplement Appendix of the NIOS Administrator Guide for the requirements to operate a grid in a FIPS compliant manner.
The system will be rebooted to place it into FIPS mode. Are you sure you want to continue (y or n): y
Integrity private key and certificate were generated successfully.
Sign executable files by sha256sum...