All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Juniper Networks QFX10002, QFX10008 and QFX10016

Certificate#4882StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorJuniper Networks, Inc.
Medium review priority  ·  no TCB surface named  ·  last validated 20 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date11/17/2026
CaveatInterim validation. When operated in Approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorJuniper Networks, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Juniper Networks QFX10002, QFX10008 and QFX10016
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>firmware load<br/>upgrade<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Show status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>SSH<br/>HTTPS<br/>library named: openssl</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Juniper Networks QFX10002, QFX10008 and QFX10016
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>firmware load<br/>upgrade<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Show status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>SSH<br/>HTTPS<br/>library named: openssl</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Juniper Networks, Inc. Juniper Networks QFX10002, QFX10008 and QFX10016

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Hardware11
Table 3: Modes List and Description11
Table 4: Approved Algorithms - Kernel12
Table 5: Approved Algorithms - LibMD12
Table 6: Approved Algorithms - OpenSSL14
Table 7: Approved Algorithms -14
Table 8: Vendor-Affirmed Algorithms14
Table 9: Non-Approved, Allowed Algorithms with No Security Claimed15
Table 10: Non-Approved, Not Allowed Algorithms15
Table 11: Security Function Implementations18
Table 12: Entropy Certificates18
Table 13: Entropy Sources18
Table 14: Ports and Interfaces20
Table 15: Authentication Methods22
Table 16: Roles23
Table 17: Approved Services37
Table 18: Non-Approved Services39
Table 19: Storage Areas41
Table 20: SSP Input-Output Methods41
Table 21: SSP Zeroization Methods42
Table 22: SSP Table 146
Table 23: SSP Table 249
Table 24: Pre-Operational Self-Tests49
Table 25: Conditional Self-Tests54
Table 26: Pre-Operational Periodic Information54
Table 27: Conditional Periodic Information56
Table 28: Error States56
Figure 1: Front view of QFX10002-36Q, QFX10002-72Q and QFX10002-60C7
Figure 2: Rear view for QFX10002-36Q7
Figure 3: Rear view of QFX10002-72Q7
Figure 4: Rear view of QFX10002-60C8
Figure 5: Front view of QFX100088
Figure 6: Rear view of QFX100088
Figure 7: Front view of QFX1000169
Figure 8: Rear view image QFX1000169
Figure 9 – High-level Block Diagram for QFX10002/QFX10008/QFX1001610
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication3
5Software/Firmware security1
6Operational environment1
7Physical security1
1.1 Overview

Introduction Federal Information Processing Standards Publication 140-3 — Security Requirements for Cryptographic Modules specifies requirements for cryptographic modules to be deployed in a Sensitive but Unclassified environment. The National Institute of Standards and Technology (NIST) and Canadian Centre for Cyber Security (CCCS) Cryptographic Module Validation Program (CMVP) run the FIPS 140-3 program. The NVLAP accredits independent testing labs to perform FIPS 140-3 testing; the CMVP validates modules meeting FIPS 140-3 validation. Validated is the term given to a module that is documented and tested against the FIPS 140-3 criteria. More information is available on the CMVP website at: https://csrc.nist.gov/projects/cryptographic-module-validation-program. About this Document This non-proprietary Cryptographic Module Security Policy for the Juniper Networks QFX10002, QFX10008 and QFX10016 provides an overview of the product and a high-level description of how it meets the overall Level 1, security requirements of FIPS 140-3. Disclaimer The contents of this document are subject to revision without notice due to continued progress in methodology, design, and manufacturing. Juniper Networks shall have no liability for any error or damages of any kind resulting from the use of this document. Notices This document may be freely reproduced and distributed in its entirety without modification. This document describes the cryptographic module security policy for the Juniper Networks QFX10002, QFX10008, QFX10016 (Hardware versions: QFX10002-36Q, QFX10002-60C, QFX10002-72Q, QFX10008 and QFX10016) cryptographic module (also referred to as the “module” hereafter) with firmware version Junos OS 22.3R1-S2.3. The module has a multi-chip standalone embodiment. It contains specification of the security rules, under which the cryptographic module operates, including the security rules derived from the requirements of the FIPS 140-3 standard.

1.2 Security Levels
Page 6
SectionTitleSecurity Level
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.3 Additional Information

The module claims an overall Security Level of 1 with all individual sections at a Security Level

1 with the exceptions of Roles, Services and Authentication (claimed at Security Level 3). The

module does not implement any non-invasive security mitigations or mitigations of other attacks and thus the requirements per these sections are inapplicable.

2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The cryptographic module provides for an encrypted connection, using SSH, between the management station and itself, i.e., the QFX switch. Module Type: Hardware Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic module’s operational environment is a limited operational environment. The cryptographic boundary of the hardware module is the entirety of the module/chassis (demarked with a black outline in the figures below). This includes the Routing Engine (RE). No components have been excluded from the cryptographic boundary of the module. Tested Operational Environment’s Physical Perimeter (TOEPP): The Tested Operational Environment’s Physical Perimeter (TOEPP) is the entirety of the module chassis.

Page 7

Figure 1: Front view of QFX10002-36Q, QFX10002-72Q and QFX10002-60C Figure 2: Rear view for QFX10002-36Q Figure 3: Rear view of QFX10002-72Q

Page 8

Figure 4: Rear view of QFX10002-60C Figure 5: Front view of QFX10008 Figure 6: Rear view of QFX10008

Page 9

Figure 7: Front view of QFX100016 Figure 8: Rear view image QFX100016

Page 10
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
QFX10002- 36QQFX10002 -36QJunos OS 22.3R1-S2.3Intel Xeon E3- 1125V2JPSU-1600W-AC- AFO JPSU-1600W- DC-AFO
QFX10002- 72QQFX10002-72QJunos OS 22.3R1-S2.3Intel Xeon E3- 1125V2JPSU-1600W-AC- AFO JPSU-1600W- DC-AFO
QFX10002- 60CQFX10002-60CJunos OS 22.3R1-S2.3Intel Xeon E3- 1125V2JPSU-1600W-AC- AFO JPSU-1600W- DC-AFO

Figure 9 – High-level Block Diagram for QFX10002/QFX10008/QFX10016

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification – Hardware:

Page 11
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
QFX10008QFX10008 with QFX10000 Control boardJunos OS 22.3R1-S2.3Intel Xeon E3- 1125V2QFX10000-PWR-AC QFX10000-PWR-DC
QFX10016QFX10016 with QFX10000 Control boardJunos OS 22.3R1-S2.3Intel Xeon E3- 1125V2QFX10000-PWR-AC QFX10000-PWR-DC
Mode NameDescriptionTypeStatus Indicator
Approved mode• The operator can verify that the cryptographic module is in the Approved mode by observing the console prompt and running the “show version” command; • When operating in the Approved mode, the prompt will read “<operator>:fips#” (e.g. root:fips#); • The “show version” command will allow the Crypto Officer to verify that the validated firmware version is running on the module; • The Crypto Officer can also use the “show system fips chassis level” command (returns “level 1”) to determine if the module is operating in the Approved mode; • The Approved mode is entered when the module is configured for it and successfully passes all self-tests (both pre-operational and conditional cryptographic algorithm self-tests (CASTs))Approvedglobal indicator (string 'fips' included in the command prompt)
Non- Approved mode• The cryptographic module supports a non- Approved mode of operation; • When operated in the non-Approved mode of operation, the module supports non-Approved algorithms as well as the algorithms supported in the Approved mode of operationNon- Approvedglobal indicator (implicit indicator based on exclusion of string 'fips' from the command prompt)

Table 2: Tested Module Identification – Hardware

2.3 Excluded Components

No components have been excluded from the cryptographic boundary of the module. Modes List and Description: Table 3: Modes List and Description

Page 12
AlgorithmCAVP CertPropertiesReference
HMAC DRBGA3337Prediction Resistance - Yes Mode - SHA2-256SP 800-90A Rev. 1
HMAC-SHA2- 256A3337Key Length - Key Length: 256FIPS 198-1
SHA2-256A3337Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
AlgorithmCAVP CertPropertiesReference
SHA2-512A3348Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
AlgorithmCAVP CertPropertiesReference
AES-CBCA3349Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA3349Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

The hardware versions contained in Table 2, with Junos OS 22.3R1-S2.3 installed, contain one Approved mode of operation and a non-Approved mode of operation. The Junos OS 22.3R1S2.3 firmware image must first be installed on the module. The module is configured during initialization by the Crypto Officer to operate in the Approved mode or the non-Approved mode. When operated in the non-Approved mode of operation, the module supports non-Approved algorithms as well as the algorithms supported in the Approved mode of operation. The module is in a non-compliant state by default and the Crypto Officer can place the module into the nonApproved mode of operation by following the instructions in Section 11 Life-Cyle Assurance in this document. Mode Change Instructions and Status: The module must always be zeroised when switching between the Approved mode of operation and the non-Approved mode of operation and vice versa. Degraded Mode Description: The module does not support a degraded mode of operation.

2.5 Algorithms

Approved Algorithms: Kernel Table 4: Approved Algorithms - Kernel LibMD Table 5: Approved Algorithms - LibMD OpenSSL

Page 13
AlgorithmCAVP CertPropertiesReference
AES-ECBA3349Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
ECDSA KeyGen (FIPS186-4)A3349Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3349Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A3349Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A3349Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
HMAC DRBGA3349Prediction Resistance - Yes Mode - SHA2-256SP 800-90A Rev. 1
HMAC-SHA-1A3349Key Length - Key Length: 160FIPS 198-1
HMAC-SHA2-256A3349Key Length - Key Length: 256FIPS 198-1
HMAC-SHA2-512A3349Key Length - Key Length: 512FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A3349Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A3349Domain Parameter Generation Methods - FC, MODP-2048 Scheme - dhEphem - KAS Role - initiatorSP 800-56A Rev. 3
KDF SSH (CVL)A3349Cipher - AES-128, AES-192, AES-256, TDES Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
RSA KeyGen (FIPS186-4)A3349Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A3349Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A3349Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
SHA-1A3349Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-256A3349Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-512A3349Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
Page 14
AlgorithmCAVP CertPropertiesReference
SHA2-512A3337Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
Safe Primes Key GenerationA3349Safe Prime Groups - MODP-2048SP 800-56A Rev. 3
Safe Primes Key VerificationA3349Safe Prime Groups - MODP-2048SP 800-56A Rev. 3
NamePropertiesImplementationReference
CKG - Section 4 and 5.1Key Type:AsymmetricN/ANIST SP800-133r2 Section 4: Asymmetric seed generation using an unmodified output from an Approved DRBG; Section 5.1: Key Pairs for Digital Signature Schemes
CKG - Section 4 and 5.2Key Type:AsymmetricN/ANIST SP800-133r2 Section 4: Asymmetric seed generation using an unmodified output from an Approved DRBG; Section 5.2: Key Pairs for Key Establishment
CKG - Section 6.2.1Key Type:SymmetricN/ANIST SP800-133r2 Section 6.2.1: Derivation of symmetric keys

Table 6: Approved Algorithms - OpenSSL Table 7: Approved Algorithms The following protocol is supported by the module in the Approved mode: SSHv2 (EC Diffie-Hellman P-256, P-384, P-521; Diffie-Hellman MODP2048; RSA 2048, 3072

4096 bits; ECDSA P-256, P-384, P-521; AES CBC 128, 192, 256 bits; AES CTR 128, 192, 256

bits, HMAC-SHA-1, HMAC-SHA2-256, HMAC-SHA2-512) The SSH protocol allows independent selection of key exchange, authentication, cipher and integrity algorithms. Please note that there are algorithms, modes, and key/moduli sizes that have been CAVP-tested but are not used by any approved service of the module. Only the algorithms, modes/methods, and key lengths/curves/moduli shown in the table above are used by an approved service of the module. Vendor-Affirmed Algorithms: 6.2.1 Table 8: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: The module does not support any non-Approved algorithms in the Approved mode, i.e., it does not support Non-Approved Algorithms Allowed in the Approved Mode of Operation.

Page 15
NameCaveatUse and Function
SHA2-256 (JUNOS 22.3R1 QFX10K-LibMD Implementation)no security claimedUsed to store operator passwords in hashed form, per IG 2.4.A: Use of a non-approved cryptographic algorithm to “obfuscate” a CSP
SHA-1 (JUNOS 22.3R1 QFX10K-Kernel)no security claimedUsed for an extraneous check in the Kernel, per IG 2.4.A: Use of an approved, non-approved or proprietary algorithm for a purpose that is not security relevant
NameUse and Function
RSA with key size less than 2048SSH
ECDSA with ed25519 curveSSH
EC Diffie-Hellman with ed25519 curveSSH
ARCFOURSSH
BlowfishSSH
CASTSSH
DSA (SignGen, SigVer, non-compliant)SSH
HMAC-MD5SSH
HMAC-RIPEMD160SSH
UMACSSH
NameTypeDescriptionPropertiesAlgorithms
KAS1KAS-135KDF KAS-SSCKey Agreement for SSHv2SP 800-56Arev3 KAS-ECC per IG D.F Scenario 2 path (2):size: P- 256, P-384, P- 521 curves; encryption strength:128,KAS-ECC-SSC Sp800-56Ar3 KDF SSH

The module does not support any non-Approved algorithms in the Approved mode, i.e., it does Table 10: Non-Approved, Not Allowed Algorithms Operation, all Approved algorithms supported in the Approved mode of operation are also

Page 16
NameTypeDescriptionPropertiesAlgorithms
192, 256 bits; strength caveat: SSP establishment methodology provides between 128 and 256 bits of encryption strength
KAS2AsymKeyPair- KeyGen AsymKeyPair- KeyVer KAS-135KDF KAS-SSCKey Agreement for SSHv2SP800-56Arev3 KAS-FFC per IG D.F Scenario 2 path (2):size: MODP 2048; encryption strength: SSP establishment methodology provides 112 bits of encryption strengthKAS-FFC-SSC Sp800-56Ar3 KDF SSH Safe Primes Key Generation Safe Primes Key Verification
KTS1KTS-WrapKey Transport for SSHv2SP800-38A AES CBC, CTR and HMAC 198 per IG D.G:size: 128, 192, and 256-bit keys; SSP establishment methodology provides between 128 and 256 bits of encryption strengthAES-CBC AES-CTR AES-ECB HMAC-SHA-1 HMAC-SHA2- 256 HMAC-SHA2- 512 SHA-1 SHA2-256 SHA2-512
ECDSA SigVerDigSig-SigVerECDSA Signature Verification used for firmware integrityFIPS 186-4 :size: P-256, encryption strength: 128 bitsECDSA SigVer (FIPS186-4)
ECDSA SigVer2DigSig-SigVerECDSA Signature Verification used for identity- based public key authenticationFIPS 186-4:size: P-256, P-384, P- 521 curves, 128, 192 and 256 bitsECDSA SigVer (FIPS186-4)
Page 17
NameTypeDescriptionPropertiesAlgorithms
DRBGDRBGKernel DRBG providing random bits to the DRBG2 for SSP generation in the user/application spaceHMAC DRBG HMAC-SHA2- 256 SHA2-256
DRBG2DRBGSSP generation in user/application spaceHMAC DRBG HMAC-SHA2- 256 SHA2-256
Entropy SouceENT-CondNon-Physical Entropy SourceSHA2-512
ECDSA KeyGenAsymKeyPair- KeyGenGeneration of SSH host keysECDSA KeyGen (FIPS186-4)
ECDSA KeyGen2AsymKeyPair- KeyGenSSP Agreement in the context of SSHECDSA KeyGen (FIPS186-4)
ECDSA KeyVerAsymKeyPair- KeyVerVerification of keys generatedECDSA KeyVer (FIPS186-4)
ECDSA SigGenDigSig-SigGenSignature Generation using ECDSA in the context of SSHECDSA SigGen (FIPS186-4)
RSA KeyGenAsymKeyPair- KeyGenGeneration of SSH host keysRSA KeyGen (FIPS186-4)
RSA SigGenDigSig-SigGenSignature Generation using RSA in the context of SSHRSA SigGen (FIPS186-4)
RSA SigVerDigSig-SigVerSignature Verification using RSA for public key authenticationRSA SigVer (FIPS186-4)
Password HashSHAUsed to store passwords in hashed formSHA2-512
CKGCKGCryptographic Key Generation (CKG)CKG - Section 6.2.1 Key Type: Symmetric
CASTs on bootBC-UnAuth DigSig-SigGen DigSig-SigVer DRBG ENT-CondList of algorithms for which Known Answer Tests (CASTs) haveAES-CBC HMAC DRBG HMAC-SHA-1 HMAC-SHA2- 256
Page 18
NameTypeDescriptionPropertiesAlgorithms
KAS-135KDF MAC SHAbeen implemented in the module and perform on each bootHMAC-SHA2- 512 KAS-ECC-SSC Sp800-56Ar3 KAS-FFC-SSC Sp800-56Ar3 KDF SSH ECDSA SigGen (FIPS186-4) ECDSA SigVer (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigVer (FIPS186-4) HMAC DRBG HMAC-SHA2- 256 SHA2-512 SHA2-512
Cert NumberVendor Name
E89Juniper Networks
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Junos OS Non- Physical Entropy SourceNon- PhysicalIntel Xeon E3- 1125v28 bits0.83 bitsSHA2-512 (CAVP Cert. #A3337)

Table 11: Security Function Implementations

2.7 Algorithm Specific Information

The module only supports testable RSA moduli/key sizes (2048, 3072 and 4096 bits) and thus the requirements per FIPS 140-3 IG C.F do not apply. Table 12: Entropy Certificates Table 13: Entropy Sources

2.9 Key Generation
Page 19

The module implements two NIST SP 800-90Ar1 DRBGs and supports the following sections per NIST SP 800-133r2 (CKG): Sections 4, 5.1, 5.2 and 6.2.1.

2.10 Key Establishment

Per IG D.F: The module implements full KAS (KAS-ECC-SSC, KAS-FFC-SSC per NIST SP 800-56Ar3 and KDF SSH per NIST SP 800-135r1; IG D.F Scenario 2 (path 2 option 2, separate testing of the SSC and SP800-135r1 KDF). The KAS1 and KAS2 in the SFI Table have been documented in accordance with this requirement. KAS1: KAS (KAS-ECC-SSC Cert.#A3349 and CVL Cert. #A3349; SSP establishment methodology provides between 128 and 256 bits of encryption strength) KAS2: KAS (KAS-FFC-SSC Cert.#A3349 and CVL Cert. #A3349; SSP establishment methodology provides 112 bits of encryption strength) The Approved Algorithm list includes the tested components (KAS-ECC-SSC, KAS-FFC-SSC and KDF SSH) as individual entries. Per IG D.G: The module supports the IETF SSH protocol and thus implements key transport in the context of the protocol (per the KTS1 entry in the SFI table of the Security Policy). The module implements the following approved KTS using approved AES modes: AES CBC and CTR: KTS (AES Cert. #A3349 and HMAC Cert. #A3349; key establishment methodology provides between 128 and 256 bits of encryption strength)

2.11 Industry Protocols

No parts of the SSH protocol, other than the KDF, have been tested by the CAVP or CMVP.

2.12 Additional Information

The module design corresponds to the security rules below. The term shall in this context specifically refers to a requirement for correct usage of the module in the Approved mode; all other statements indicate a security rule implemented by the module.

  1. The module clears previous authentications on power cycle.
  2. When the module has not been placed in a valid role, the operator does not have access to any cryptographic services.
  3. Self-tests do not require any operator action.
  4. Data output is inhibited during SSP generation, self-test execution, zeroisation, and error states.
  5. Status information does not contain SSPs or sensitive data that if misused could lead to a compromise of the module.
  6. There are no restrictions on which SSPs are zeroised by the zeroisation service.
Page 20
Physical PortLogical Interface(s)Data That Passes
EthernetData Input Data Output Control Input Status OutputLAN Communications (QFX10002-36Q(40: 2 MGMT, 36 QSFP+, 1 ETH), QFX10002-72Q(80: 2 MGMT, 72 QSFP+, 1 ETH), QFX10002-60C (63: 2 MGMT, 60 QSFP+, 1 ETH), QFX10008(12: 4 MGMT, 8 SFP+), QFX10016(12: 4 MGMT, 8 SFP+))
SerialControl Input Status OutputSerial Console Port (QFX10002(1), QFX10008(2), QFX10016(2))
USBData Input Control InputLoad Junos OS image/configuration (QFX10002(1), QFX10008(2), QFX10016(2))
PowerPowerPower connector (QFX10002-36Q(4), QFX10002-72Q(4), QFX10002-60C(4), QFX10008(6), QFX10016(10))
LEDStatus OutputStatus indicator lighting (QFX10002(4) QFX10008(13) QFX10016(13))
ResetControl InputReset (QFX10002(1) QFX10008(2) QFX10016(2))
SMBControl Input Status OutputPTP Connectors (QFX10002(2) QFX10008(8) QFX10016(8))
Backplane Line Card InterfaceData Input Data Output Control Input Status OutputLine card interface (QFX10008(8) QFX10016(16))
  1. The module does not support a maintenance interface or role.
  2. The module does not output intermediate key values.
  3. The module does not output plaintext CSPs.
  4. The Crypto officer shall verify that the firmware image to be loaded on the module is a FIPS 140-3 validated image. If any non-validated firmware image is loaded the module will no longer be a validated module.
  5. The Crypto Officer shall retain control of the module while zeroisation is in process.
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 14: Ports and Interfaces The module does not support control output.

Page 21
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Username and password over the console and SSH• The module enforces 10- character passwords (at minimum) chosen from the 96 human readable ASCII characters; The maximum password length is 20- characters; Thus, the probability of a successful random attempt is 1/(96^10), which is less than 1/1,000,000 (million); • The module enforces a timed access mechanism as follows: For the first two failed attempts (assuming 0 time to process), no timed access is enforced; Upon the third attempt, the module enforces a 5-second delay; Each failed attempt thereafter results in an additional 5-second delay above the previous (e.g., 4th failed attempt = 10-second delay, 5th failed attempt = 15-second delay, 6th failed attempt = 20- second delay, 7th failed attempt = 25-second delay); This leads to a maximum of 7 possible attempts in a one-minute period for each getty; The best approach for the attacker would be to disconnect after 4 failed attempts and wait for a new getty to be spawned; This would allow the attacker to perform roughly 9.6 attempts per minute (576 attempts per hour/60 mins); this would be rounded down to 9 per minute, because there is no such thing as 0.6 attempts; The probability of a success with multiple consecutive attempts inSHA2-512 (A3348)1/(96^10)9/(96^10)
4 Roles, Services, and Authentication
4.1 Authentication Methods
Page 22
Method NameDescription a one-minute period is 9/(96^10), which is less than 1/100,000Security MechanismStrength Each AttemptStrength per Minute
Username and ECDSA public key over SSH• The module supports ECDSA (P-256, P-384, and P-521), which has a minimum equivalent computational resistance to attack of either 2^128, 2^192 or 2^256 depending on the curve; Thus, the probability of a successful random attempt is 1/(2^128), which is less than 1/1,000,000 (million) • Configurable SSH connection establishment rate limits the number of connection attempts, and thus failed authentication attempts in a one-minute period to a maximum of 15,000 attempts; The probability of a success with multiple consecutive attempts in a one- minute period is 15,000/(2^128), which is less than 1/100,000ECDSA SigVer (FIPS186-4) (A3349)1/(2^128)15,000/(2^128)
Username and RSA public key over SSH• The module supports RSA (2048, 3072, 4096 bits), which has a minimum equivalent computational resistance to attack of 2^112 (2048 bits); Thus, the probability of a successful random attempt is 1/ (2^112), which is less than 1/1,000,000 (million) • Configurable SSH connection establishment rate limits the number of connection attempts, and thus failed authentication attempts in a one- minute period to a maximum of 15,000 attempts; The probability of a success with multiple consecutive attempts in a one- minute period is 15,000/(2^112), which is less than 1/100,000RSA SigVer (FIPS186-4) (A3349)1/ (2^112)15,000/(2^112)

Table 15: Authentication Methods The module enforces the separation of roles using identity-based operator authentication. The module implements two forms of identity-based authentication, username, and password over

Page 23
NameTypeOperator TypeAuthentication Methods
Super-userIdentityCrypto Officer (CO)Username and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH
OperatorIdentityUserUsername and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH
Read-onlyIdentityUserUsername and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH
RootIdentityCrypto Officer (CO)Username and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH
UnauthorisedIdentityUserUsername and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH

based authentication over SSHv2.

4.2 Roles

Table 16: Roles correspond to the User role. The module supports concurrent operators but does not support a maintenance role and/or bypass capability. An operator assuming the Crypto Officer role configures and monitors the module via a console or SSH connection. As Root or Super-user, the Crypto Officer has permission to view and configure passwords and public keys within the module. The User role monitors the module via the console or SSH. The User role does not have the permission to modify the configuration.

Page 24
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access
Configure security (security relevant)Security relevant configuratio n (SSH, authenticati on data)Global Approved Mode indicator “fips” at the CLI combined with successf ul completio n of each serviceCommands (SSH configuration: set system services ssh root-login allow)TrafficDRBG DRBG2 Passwor d Hash CKGRoot - SSH Private Host Key: G - User Password: W,E - CO Password: W,E - HMAC_DRBG V value: E - HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - SSH Public Host Key: G - User Authentication Public Keys: W - CO Authentication Public Keys: W Super-user - SSH Private Host Key: G - User Password: W,E - CO Password: W,E - HMAC_DRBG V value: E -
Page 25
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - HMAC_DRBG Key value: E - SSH Public Host Key: G - CO Authentication Public Keys: W - User Authentication Public Keys: W
Configure (non- security relevant)Non- security relevant configuratio nGlobal Approved Mode indicator “fips” at the CLI combined with successf ul completio n of each serviceCommands (miscellaneous commands e.g., for IP address configuration, routing protocols, etc.)TrafficPasswor d HashSuper-user - CO Password: E Root - CO Password: E
Show statusQuery the module statusGlobal Approved Mode indicator “fips” at the CLI combined with successf ul completio n of each serviceCommand (show)CLI outputPasswor d HashSuper-user - CO Password: E Root - CO Password: E Operator - User Password: E Read-only - User Password: E Unauthorised
Page 26
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access - User Password: E
Show status (LED)LEDs on the module provide physical status outputLED(s) on the chassis turned onN/ALEDNoneSuper-user Operator Read-only Unauthorised Root Unauthenticat ed
Show module’s versioning informatio nQuery the module’s versioning informationGlobal Approved Mode indicator “fips” at the CLI combined with successf ul completio n of each serviceCommand (show version)CLI outputPasswor d HashSuper-user - CO Password: E Operator - User Password: E Read-only - User Password: E Unauthorised - User Password: E Root - CO Password: E
Zeroise (Perform zeroisatio n)Destroy all SSPsGlobal Approved Mode indicator “fips” at the CLI combined with successf ul completio n of each serviceCommand (request vmhost zeroise no-forwarding)N/APasswor d HashSuper-user - SSH Private Host Key: Z - SSH ECDH Private Key: Z - SSH DH Private Key: Z - SSH Session Key: Z - User Password: Z - CO Password: E,Z - HMAC_DRBG V value: Z - HMAC_DRBG Key value: Z - HMAC_DRBG entropy input: Z
Page 27

Name

Description

Indicator

Inputs

Output s

Security Function s

SSP Access - HMAC_DRBG seed: Z - ECDH Shared Secret: Z - DH Shared Secret: Z - HMAC Key: Z - SSH Public Host Key: Z - User Authentication Public Keys: Z - CO Authentication Public Keys: Z - JuniperRootC A: Z - PackageCA: Z - SSH ECDH Public Key: Z - SSH DH Public Key: Z - SSH ECDH Client Public Key: Z - SSH DH Client Public Key: Z Root - SSH Private Host Key: Z - SSH ECDH Private Key: Z - SSH DH Private Key: Z - SSH Session Key: Z - User Password: Z - CO Password: E,Z - HMAC_DRBG

Page 28
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access V value: Z - HMAC_DRBG Key value: Z - HMAC_DRBG entropy input: Z - HMAC_DRBG seed: Z - ECDH Shared Secret: Z - DH Shared Secret: Z - HMAC Key: Z - SSH Public Host Key: Z - User Authentication Public Keys: Z - CO Authentication Public Keys: Z - JuniperRootC A: Z - PackageCA: Z - SSH ECDH Public Key: Z - SSH DH Public Key: Z - SSH ECDH Client Public Key: Z - SSH DH Client Public Key: Z
Perform approved security functions (SSH connectio n)Initiate SSH connection for SSH monitoring and control (CLI)Global Approved Mode indicator “fips” at the CLI combinedAuthentication data (Username and password/publi c-key based authentication)SSH sessionKAS1 KAS2 KTS1 ECDSA SigVer2 DRBG DRBG2Super-user - SSH Private Host Key: E - SSH ECDH Private Key: G,E,Z - SSH DH
Page 29
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access
with successf ul completio n of each serviceEntropy Souce ECDSA KeyGen ECDSA KeyGen2 ECDSA KeyVer ECDSA SigGen RSA KeyGen RSA SigGen RSA SigVer Passwor d Hash CKGPrivate Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH DH Public Key: G,E,Z - SSH ECDH Public Key: G,E,Z - CO Password: E - CO Authentication Public Keys: E - SSH ECDH Client Public Key: W,E,Z - SSH DH Client Public Key: W,E,Z Root - SSH Private Host Key: E - SSH ECDH Private Key:
Page 30

Name

Description

Indicator

Inputs

Output s

Security Function s

SSP Access G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - CO Password: E - CO Authentication Public Keys: E - SSH ECDH Client Public Key: G,E,Z - SSH DH Client Public Key: G,E,Z Operator - SSH Private Host Key: E

Page 31

Name

Description

Indicator

Inputs

Output s

Security Function s

SSP Access - SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - User Password: E - User Authentication Public Keys: E - SSH ECDH Client Public Key: G,E,Z - SSH DH Client Public Key: G,E,Z - HMAC_DRBG Key value: E Read-only

Page 32

Name

Description

Indicator

Inputs

Output s

Security Function s

SSP Access - SSH Private Host Key: E - SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - User Password: E - User Authentication Public Keys: E - SSH ECDH Client Public Key: G,E,Z - SSH DH Client Public

Page 33

Name

Description

Indicator

Inputs

Output s

Security Function s

SSP Access Key: G,E,Z Unauthorised - SSH Private Host Key: E - SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - User Password: E - User Authentication Public Keys: E - SSH ECDH Client Public Key: G,E,Z - SSH DH Client Public Key: G,E,Z

Page 34
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access - HMAC_DRBG Key value: E
Console AccessConsole monitoring and control (CLI)Global Approved Mode indicator “fips” at the CLI combined with successf ul completio n of each serviceUsername, password (set system login user <username> class <crypto- officer/user class> operator authentication plaintext- password)N/APasswor d HashSuper-user - CO Password: E Operator - CO Password: E Read-only - User Password: E Unauthorised - User Password: E Root - CO Password: E
Perform self-tests (remote reset)Software initiated reset, performs self-tests on demand via SSHGlobal Approved Mode indicator “fips” at the CLI combined with successf ul completio n of each serviceControl input/reset signal (request vmhost reboot)N/AKAS1 KAS2 KTS1 DRBG DRBG2 Entropy Souce ECDSA KeyGen ECDSA KeyGen2 ECDSA KeyVer ECDSA SigGen RSA KeyGen RSA SigGen Passwor d Hash CKG CASTs on bootSuper-user - SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG Key value: G,E,Z - HMAC_DRBG V value: G,E,Z - HMAC_DRBG entropy input: G,E,Z - HMAC_DRBG seed: G,E,Z - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z
Page 35

Name

Description

Indicator

Inputs

Output s

Security Function s

SSP Access - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - CO Password: E - Firmware Integrity Key: E - SSH Private Host Key: E - SSH Public Host Key: E - SSH ECDH Client Public Key: W,E,Z - SSH DH Client Public Key: W,E,Z - SSH Private Host Key: E - SSH Public Host Key: E - User Authentication Public Keys: E - CO Authentication Public Keys: E Root - SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG Key value: G,E,Z - HMAC_DRBG V value: G,E,Z -

Page 36
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access HMAC_DRBG entropy input: G,E,Z - HMAC_DRBG seed: G,E,Z - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - CO Password: E - Firmware Integrity Key: E - SSH Private Host Key: E - SSH Public Host Key: E - SSH ECDH Client Public Key: W,E,Z - SSH DH Client Public Key: W,E,Z - SSH Private Host Key: E - SSH Public Host Key: E - User Authentication Public Keys: E - CO Authentication Public Keys: E
Perform self-tests (local reset)Hardware reset or power cycleGlobal Approved Mode indicatorControl input/reset signalN/ACASTs on bootSuper-user - Firmware Integrity Key: E
Page 37
NameDescriptionIndicator “fips” at the CLI combined with successf ul completio n of each serviceInputsOutput sSecurity Function sSSP Access Root - Firmware Integrity Key: E Operator - Firmware Integrity Key: E Read-only - Firmware Integrity Key: E Unauthorised - Firmware Integrity Key: E Unauthenticat ed - Firmware Integrity Key: E
Load ImageVerification and loading of a validated firmware image into the router/switc hGlobal Approved Mode indicator “fips” at the CLI combined with successf ul completio n of each serviceImage, commandsN/AECDSA SigVer Passwor d HashSuper-user - CO Password: E - Firmware Integrity Key: E - JuniperRootC A: E - PackageCA: E Root - CO Password: E - Firmware Integrity Key: E - JuniperRootC A: E - PackageCA: E
Page 38
NameDescriptionAlgorithmsRole
Configure security (security relevant)Security relevant configurationRSA with key size less than 2048 ECDSA with ed25519 curve EC Diffie- Hellman with ed25519 curve ARCFOUR Blowfish CAST DSA (SignGen, SigVer, non- compliant) HMAC-MD5 HMAC- RIPEMD160 UMACRoot, Super-user
Configure (non- security relevant)Non-security relevant configurationNoneRoot, Super-user
Show statusQuery the module statusNoneRoot, Super-user, Operator, Read-Only, Unauthorized
Show status (LED)LEDs on the module provide physical status outputNoneRoot, Super-user, Operator, Read-Only, Unauthorized, Unauthenticated
Show module’s versioning informationQuery the module’s versioning informationNoneRoot, Super-user, Operator, Read-Only, Unauthorized
Zeroise (Perform zeroisation)Destroy all SSPsNoneRoot, Super-user
Perform approved security functions (SSH connection)Initiate SSH connection for SSH monitoring and control (CLI)RSA with key size less than 2048 ECDSA with ed25519 curve EC Diffie- Hellman with ed25519 curve ARCFOUR Blowfish CAST DSA (SignGen, SigVer, non- compliant) HMAC-MD5Root, Super-user, Operator, Read-Only, Unauthorized
Page 39
NameDescriptionAlgorithmsRole
HMAC- RIPEMD160 UMAC
Console AccessConsole monitoring and control (CLI)NoneRoot, Super-user, Operator, Read-Only, Unauthorized
Perform self-tests (remote reset)Software initiated reset, performs self-tests on demandNoneRoot, Super-user, Operator, Read-Only, Unauthorized
Perform self-tests (local reset)Hardware reset or power cycleNoneRoot, Super-user, Operator, Read-Only, Unauthorized, Unauthenticated
Load ImageVerification and loading of a validated firmware image into the router/switchNoneRoot, Super-user

Table 18: Non-Approved Services

4.5 External Software/Firmware Loaded

The module supports loading of firmware from an external source (a complete image replacement) and a firmware load test using ECDSA P-256 with SHA2-256 (CAVP Cert. #A3349) is performed in support of the load.

4.6 Cryptographic Output Actions and Status

The module does not support self-initiated cryptographic output.

5.1 Integrity Techniques

The module performs the firmware integrity check using ECDSA P-256 with SHA2-256 (CAVP Cert. #A3349). The ECDSA P-256 public key used for signature verification is a non-SSP and stored persistently across reboots in the module’s Non-Volatile RAM (NVRAM) and is exempt from zeroisation. The operator can initiate the integrity test on demand by rebooting the module.

5.3 Additional Information
Page 40

The module firmware image is delivered in the form of a pre-compiled tarball (.tgz).

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited How Requirements are Satisfied: The module contains a limited operational environment since it supports loading of firmware from an external source. The Junos OS 22.3R1-S2.3 operating system is contained within the module, i.e., the tested configurations listed in the Tested Module Identification – Hardware in this document.

6.2 Configuration Settings and Restrictions

Security rules and restrictions for configuration of the operational environment have been specified in Sections 2.12 and 11.1 of this document.

7 Physical Security
7.1 Mechanisms and Actions Required

The module’s physical embodiment is that of a multi-chip standalone meeting Level 1 Physical Security requirements. The module is completely enclosed in a rectangular nickel or clear zinc coated, cold rolled steel, plated steel and brushed aluminum enclosure. The module enclosure is made of production grade materials. There are no ventilation holes, gaps, slits, cracks, slots, or crevices that would allow for any sort of observation of any component contained within the cryptographic boundary. No actions are required by the operator to ensure that physical security is maintained.

8 Non-Invasive Security
8.1 Mitigation Techniques

The module does not implement any non-invasive security mitigations and thus the requirements per this section do not apply to the module.

9 Sensitive Security Parameters Management
9.1 Storage Areas
Page 41
Storage Area NameDescriptionPersistence Type
NVRAMNon-Volatile Random Access MemoryStatic
RAMRandom Access MemoryDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Entered over SSH - NVRAMExternal endpointNVRAMEncryptedAutomatedElectronicKTS1
Loaded at manufactureExternal endpointNVRAMPlaintextN/AN/A
Entered through the CLI via console connection - NVRAMExternal endpointNVRAMPlaintextManualDirect
Input during SSH negotiationExternal endpointRAMPlaintextAutomatedElectronic
Output during SSH negotiation (host key)NVRAMExternal endpointPlaintextAutomatedElectronic
Output during SSH negotiation (Key Agreement public key)RAMExternal endpointPlaintextAutomatedElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroisation commandCommand used to zeroise the module: request vmhost zeroize no-forwardingUsed to provide zeroisation as a serviceOperator initiated
Power-cyclePower cycling the module to zeroise temporary SSPsPower cycling the module to zeroise temporary SSPsOperator initiated
Session terminationTermination of SSH sessions automatically zeroisesTermination of SSH sessions automatically zeroisesModule initiated
9.2 SSP Input-Output Methods

Table 20: SSP Input-Output Methods The module is complaint with FIPS 140-3 IG 9.5.A MD/DE and AD/EE for SSPs entered via the entered/ouput/established via SSH respectively.

9.3 SSP Zeroization Methods
Page 42
Zeroization MethodDescription temporary SSPs used as part of the sessionRationale temporary SSPs used as part of the sessionOperator Initiation
Not zeroisedPSP not zeroised since it cannot be modified due to being inaccessible in the filesystemPSP not zeroised since it cannot be modified due to being inaccessible in the filesystemN/A
Derivation of SSH session keyEC Diffie-Hellman/Diffie- Hellman shared secrets are zeroised after use in derivation of SSH session keyEC Diffie-Hellman/Diffie- Hellman shared secrets are zeroised after use in derivation of SSH session keyModule initiated
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
SSH Private Host KeyHost key generated, used for authenticatio n and encryption in the context of SSHP-256 for ECDSA, 2048 bits for RSA - 128 bits for ECDSA, 112 bits for RSAPrivate Host Key - CSPDRBG2 ECDSA KeyGen RSA KeyGenKAS1 KAS2
SSH ECDH Private KeyEphemeral EC Diffie- Hellman private key used in SSHKAS- ECC- SSC P- 256, P- 384, P- 512 - 128 bits, 192 bits, 256 bitsECDH Private Key - CSPDRBG2 ECDSA KeyGen2KAS1
SSH DH Private KeyEphemeral Diffie- Hellman private key used in SSH2048 bits for KAS- FFC-SSC - 112 bits for KAS- FFC-SSCDH Private Key - CSPDRBG2KAS2
SSH Session KeySSH Session Key128 bits, 192 bits, 256 bits - 128 bits, 192 bits, 256 bitsSession Key - CSPCKGKAS1 KAS2

Table 21: SSP Zeroization Methods

Page 43
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
User PasswordPasswords used to authenticate users to the module10-20 character s - 1/(96^10) per attempt, 9/(96^10) per minuteUser Password - CSP
CO PasswordPasswords used to authenticate COs to the module10-20 character s - 1/(96^10) per attempt, 9/(96^10) per minuteCO Password - CSP
HMAC_DRB G V valueA critical value of the internal state of DRBG256 bits - 256 bitsInternal state of the DRBG - CSPDRBG DRBG2DRBG DRBG 2
HMAC_DRB G Key valueA critical value of the internal state of DRBG440 bits - 440 bitsInternal state of the DRBG - CSPDRBG DRBG2DRBG DRBG 2
HMAC_DRB G entropy inputEntropy input to the HMAC_DRB G512 bits - 448 bitsEntropy input to the HMAC_DRB G - CSPEntropy Souce
HMAC_DRB G seedSeed provided to the HMAC_DRB G512 bits - 440 bitsSeed provided to the HMAC_DRB G - CSPDRBG DRBG2DRBG DRBG 2
ECDH Shared SecretUsed in EC Diffie- Hellman (ECDH) exchangeP-256, P- 384, P- 521 - 128 bits, 192 bits, 256 bitsShared secret - CSPKAS1
DH Shared SecretUsed in Diffie- Hellman (DH) exchange2048 bits - 112 bitsShared secret - CSPKAS2
HMAC KeyMAC key128 bits and 256MAC key - CSPKAS1 KAS2
Page 44
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
bits - 128 bits and 256 bits
SSH Public Host KeyHost key generated, used to identify the host. Also paired with the private key for authenticatio n and encryption in the context of SSHP-256 for ECDSA and 2048 bits for RSA - 128 bits for ECDSA, 112 bits for RSAPublic key - PSPDRBG2 ECDSA KeyGen RSA KeyGen
User Authenticatio n Public KeysUsed to authenticate users to the moduleP-256, P- 384, P- 521 for ECDSA and 2048, 3072 and 4096 bits for RSA - 128, 192, 256 bits for ECDSA, 112, 192 and 256 bits for RSAPublic key - PSP
CO Authenticatio n Public KeysUsed to authenticate the CO to the moduleP-256, P- 384, P- 521 for ECDSA and 2048, 3072 and 4096 bits for RSA - 128, 192, 256 bits for ECDSA, 112, 192 and 256Public key - PSP
Page 45
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
bits for RSA
JuniperRootC AECDSA prime256v1 X.509 V3 Certificate Used to verify the validity of the PackagCAECDSA P-256 - 128 bitsPublic key certificate - Neither
PackageCAECDSA prime256v1 X.509 V3 Certificate Certificate that holds the public key for the signing key used to generate all the signatures used on the packages and signature listsECDSA P-256 - 128 bitsPublic key certificate - Neither
SSH ECDH Public KeyEphemeral EC Diffie- Hellman public key used in SSHKAS- ECC- SSC P- 256, P- 384, P- 512 - 128 bits, 192 bits, 256 bits for KAS- ECC- SSCPublic key - PSPDRBG2 ECDSA KeyGen2
SSH DH Public KeyEphemeral Diffie- Hellman public key used in SSH2048 bits for KAS- FFC-SSC - 112 bits for KAS- FFC-SSCPublic key - PSPDRBG2
Page 46
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
Firmware Integrity KeyPublic key used to perform the firmware integrity test on each boot and authenticate firmware loaded from an external sourceECDSA P-256 - 128 bitsPublic key - Neither
SSH ECDH Client Public KeyEphemeral EC Diffie- Hellman public key used in SSH (sent by the client to the module acting as the server)KAS- ECC- SSC P- 256, P- 384, P- 512 - 128 bits, 192 bits, 256 bits for KAS- ECC- SSCPublic key - PSP
SSH DH Client Public KeyEphemeral Diffie- Hellman public key used in SSH (sent by the client to the module acting as the server)2048 bits for KAS- FFC-SSC - 112 bits for KAS- FFC-SSCPublic key - PSP
Name SSH Private Host KeyInput - OutputStorage NVRAM:PlaintextStorage DurationZeroization Zeroisation commandRelated SSPs
SSH ECDH Private KeyRAM:PlaintextUntil session terminationZeroisation command Power-cycle Session termination
SSH DH Private KeyRAM:PlaintextUntil session terminationZeroisation command Power-cycle
Page 47
NameInput - OutputStorageStorage DurationZeroization Session terminationRelated SSPs
SSH Session KeyRAM:PlaintextUntil session terminationZeroisation command Power-cycle Session termination
User PasswordEntered over SSH - NVRAM Entered through the CLI via console connection - NVRAMNVRAM:Obfuscated NVRAM:ObfuscatedZeroisation command
CO PasswordEntered over SSH - NVRAM Entered through the CLI via console connection - NVRAMNVRAM:Obfuscated NVRAM:ObfuscatedZeroisation command
HMAC_DRBG V valueRAM:PlaintextUntil power- cyclePower-cycle
HMAC_DRBG Key valueRAM:PlaintextUntil power- cyclePower-cycle
HMAC_DRBG entropy inputRAM:PlaintextUntil power- cyclePower-cycle
HMAC_DRBG seedRAM:PlaintextUntil power- cyclePower-cycle
ECDH Shared SecretRAM:PlaintextUntil SSH session key derivationZeroisation command Power-cycle Derivation of SSH session key
DH Shared SecretRAM:PlaintextUntil SSH session key derivationZeroisation command Power-cycle Derivation
Page 48
NameInput - OutputStorageStorage DurationZeroization of SSH session keyRelated SSPs
HMAC KeyRAM:PlaintextUntil session terminationZeroisation command Power-cycle Session termination
SSH Public Host KeyOutput during SSH negotiation (host key)NVRAM:PlaintextZeroisation command
User Authentication Public KeysEntered over SSH - NVRAM Entered through the CLI via console connection - NVRAMNVRAM:PlaintextZeroisation command
CO Authentication Public KeysEntered over SSH - NVRAM Entered through the CLI via console connection - NVRAMNVRAM:PlaintextZeroisation command
JuniperRootCALoaded at manufactureNVRAM:PlaintextNot zeroised
PackageCALoaded at manufactureNVRAM:PlaintextNot zeroised
SSH ECDH Public KeyOutput during SSH negotiation (Key Agreement public key)RAM:PlaintextUntil session terminationZeroisation command Power-cycle Session termination
SSH DH Public KeyOutput during SSH negotiation (Key Agreement public key)RAM:PlaintextUntil session terminationZeroisation command Power-cycle Session termination
Firmware Integrity KeyLoaded at manufactureNVRAM:PlaintextNot zeroised
Page 49
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
SSH ECDH Client Public KeyInput during SSH negotiationRAM:PlaintextUntil session terminationZeroisation command Power-cycle Session termination
SSH DH Client Public KeyInput during SSH negotiationRAM:PlaintextUntil session terminationZeroisation command Power-cycle Session termination
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Firmware Integrity TestUsing ECDSA P-256 with SHA2-256KATSW/FW IntegrityFIPS Self-tests PassedVerify
Algorith m or TestTest PropertiesTest MethodTest TypeIndicatorDetailsCondition s
HMAC DRBG (A3337)Prediction Resistance: Yes Supports Reseed Capabilities: Mode: SHA2- 256 Entropy Input: 256 Nonce: 128 Personalizati on String Length: 0- 256 Increment 8 AdditionalKATCASTNIST 800-90 HMAC DRBG Known Answer Test : PassedN/ADuring boot
10.1 Pre-Operational Self-Tests

Table 24: Pre-Operational Self-Tests The module is complaint with FIPS 140-3 IG 10.2.A in that it performs a self-test, a Known integrity test on each boot prior to executing the firmware integrity test.

10.2 Conditional Self-Tests
Page 50
Algorith m or TestTest Properties Input: 8-256 Increment 8 Returned Bits: 1024Test MethodTest TypeIndicatorDetailsCondition s
HMAC- SHA2- 256 (A3337)Key Length: 256 bitsKATCASTHMAC- SHA2- 256 Known Answer Test : PassedN/ADuring boot
AES- CBC (A3349)Key Length: 128 bitsKATCASTAES-CBC Known Answer Test : PassedEncryptDuring boot
AES- CBC (A3349)Key Length: 192 bitsKATCASTAES-CBC Known Answer Test : PassedEncryptDuring boot
AES- CBC (A3349)Key Length: 256 bitsKATCASTAES-CBC Known Answer Test : PassedEncryptDuring boot
AES- CBC (A3349)Key Length: 128 bitsKATCASTAES-CBC Known Answer Test : PassedDecryptDuring boot
AES- CBC (A3349)Key Length: 192 bitsKATCASTAES-CBC Known Answer Test : PassedDecryptDuring boot
AES- CBC (A3349)Key Length: 256 bitsKATCASTAES-CBC Known Answer Test : PassedDecryptDuring boot
HMAC DRBG (A3349)Mode: SHA2- 256, Entropy Input: 256 , Nonce: 128, Personalizati on StringKATCASTNIST 800-90 HMAC DRBG Known AnswerN/ADuring boot
Page 51
Algorith m or TestTest Properties Length: 0- 256 , Increment 8 , Additional Input: 8-256 Increment 8 , Returned Bits: 1024Test MethodTest TypeIndicator Test : PassedDetailsCondition s
HMAC- SHA-1 (A3349)Key Length: 160 bitsKATCASTHMAC- SHA-1 Known Answer Test : PassedN/ADuring boot
HMAC- SHA2- 256 (A3349)Key Length: 256 bitsKATCASTHMAC- SHA2- 256 Known Answer Test : PassedN/ADuring boot
HMAC- SHA2- 512 (A3349)Key Length: 512 bitsKATCASTHMAC- SHA2- 512 Known Answer Test : PassedN/ADuring boot
KAS- ECC- SSC Sp800- 56Ar3 (A3349)Domain Parameter Generation Methods: P- 256KATCASTKAS- ECC- EPHEM- UNIFIED- NOKC Known Answer Test: PassedN/ADuring boot
KAS- ECC- SSC Sp800- 56Ar3 (A3349)Domain Parameter Generation Methods: P- 384KATCASTKAS- ECC- EPHEM- UNIFIED- NOKC Known Answer Test: PassedN/ADuring boot
Page 52
Algorith m or TestTest PropertiesTest MethodTest TypeIndicatorDetailsCondition s
KAS- FFC- SSC Sp800- 56Ar3 (A3349)Domain Parameter Generation Methods: MODP-2048KATCASTKAS- FFC- EPHEM- NOKC Known Answer Test: PassedN/ADuring boot
KDF SSH (A3349)Cipher: AES- 128, AES- 192, AES- 256 ; Hash Algorithm: SHA-1, SHA2-256, SHA2-384, SHA2-512KATCASTKDF- SSH- SHA2- 256 Known Answer Test: PassedN/ADuring boot
RSA SigGen (FIPS186 -4) (A3349)Modulus 2048 bits SHA2-256KATCASTRSA- SIGN Known Answer Test: PassedSignDuring boot
RSA SigVer (FIPS186 -4) (A3349)Modulus 2048 bits SHA2-256KATCASTRSA- VERIFY Known Answer Test: PassedVerifyDuring boot
ECDSA SigGen (FIPS186 -4) (A3349)Curve: P-256 Hash Algorithm: SHA2-256KATCASTECDSA- SIGN Known Answer Test: PassedSignDuring boot
ECDSA SigVer (FIPS186 -4) (A3349)Curve: P-256 Hash Algorithm: SHA2-256KATCASTECDSA- VERIFY Known Answer Test: PassedVerifyDuring boot
SHA2- 512 (A3348)SHA2-512KATCASTSHA-2- 512 Known Answer Test: PassedN/ADuring boot
Page 53
Algorith m or TestTest PropertiesTest MethodTest TypeIndicatorDetailsCondition s
Entropy testNIST SP 800-90B Repetitive Count TestRCTCASTpassCutoff value C = 21During boot and continually
Entropy testNIST SP 800-90B Adapative Proportion TestAPTCASTpassW = 512; Cutoff value C = 311During boot and continually
ECDSA KeyGen (FIPS186 -4) (A3349)Curve: P-256 Hash Algorithm: SHA2-256PCTPCT0Key pair generated for signature generation/verificati on in the context of SSHv2 protocolOn key generation
ECDSA KeyGen (FIPS186 -4) (A3349)Curve: P-256 Hash Algorithm: SHA2-256PCTPCT0Key pair generated for SSP agreement in the context of SSHv2 protocolOn key generation
KAS- FFC- SSC Sp800- 56Ar3 (A3349)Capabilities: Domain Parameter: MODP2048PCTPCT0Key pair generated for SSP agreement in the context of SSHv2 protocolOn key generation
RSA KeyGen (FIPS186 -4) (A3349)Modulus: 2048 Hash SHA2-256PCTPCT0Key pair generated for signature generation/verificati on in the context of SSHv2 protocolOn key generation
ECDSA SigVer (FIPS186 -4) (A3349)Curve: P-256 Hash Algorithm: SHA2-256KATSW/F W LoadHost OS upgrade staged. Reboot the system to complete installatio n!VerifyOn loading of firmware from an external source
Manual entry test (duplicat e entries)Duplicate entry test required for entry of operator passwords via direct connection toDuplicat e entry testManua l EntryComman d prompt with "fips" string provided post completioN/AOn configurati on of operator passwords
Page 54

Algorith m or Test

Test Properties the module's console (serial) interface

Test Method

Test Type

Indicator n of the test

Details

Condition s

Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Firmware Integrity TestKATSW/FW IntegrityOn DemandManually via a reboot
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC DRBG (A3337)KATCASTOn DemandManually via a reboot
HMAC-SHA2- 256 (A3337)KATCASTOn DemandManually via a reboot
AES-CBC (A3349)KATCASTOn DemandManually via a reboot
AES-CBC (A3349)KATCASTOn DemandManually via a reboot
AES-CBC (A3349)KATCASTOn DemandManually via a reboot
AES-CBC (A3349)KATCASTOn DemandManually via a reboot
AES-CBC (A3349)KATCASTOn DemandManually via a reboot
AES-CBC (A3349)KATCASTOn DemandManually via a reboot
HMAC DRBG (A3349)KATCASTOn DemandManually via a reboot
HMAC-SHA-1 (A3349)KATCASTOn DemandManually via a reboot
HMAC-SHA2- 256 (A3349)KATCASTOn DemandManually via a reboot

Table 25: Conditional Self-Tests Cryptographic Algorithm Self-tests (CASTs) are performed on each boot of the module. Other conditional self-tests are performed by the module when the corresponding condition is met. The pairwise consistency tests are performed on key pair generation for use in signature generation/verification (ECDSA and/or RSA tests) and/or for use in KAS-ECC-SSC or KASFFC-SSC SSP agreement (ECDSA and FFC tests respectively). The firmware load test is performed when a firmware image is loaded onto the module from an external source.

10.3 Periodic Self-Test Information

Table 26: Pre-Operational Periodic Information

Page 55
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 512 (A3349)KATCASTOn DemandManually via a reboot
KAS-ECC-SSC Sp800-56Ar3 (A3349)KATCASTOn DemandManually via a reboot
KAS-ECC-SSC Sp800-56Ar3 (A3349)KATCASTOn DemandManually via a reboot
KAS-FFC-SSC Sp800-56Ar3 (A3349)KATCASTOn DemandManually via a reboot
KDF SSH (A3349)KATCASTOn DemandManually via a reboot
RSA SigGen (FIPS186-4) (A3349)KATCASTOn DemandManually via a reboot
RSA SigVer (FIPS186-4) (A3349)KATCASTOn DemandManually via a reboot
ECDSA SigGen (FIPS186-4) (A3349)KATCASTOn DemandManually via a reboot
ECDSA SigVer (FIPS186-4) (A3349)KATCASTOn DemandManually via a reboot
SHA2-512 (A3348)KATCASTOn DemandManually via a reboot
Entropy testRCTCASTOn DemandManually via a reboot
Entropy testAPTCASTOn DemandManually via a reboot
ECDSA KeyGen (FIPS186-4) (A3349)PCTPCTOn DemandManually via a reboot
ECDSA KeyGen (FIPS186-4) (A3349)PCTPCTOn DemandManually via a reboot
KAS-FFC-SSC Sp800-56Ar3 (A3349)PCTPCTOn DemandManually via a reboot
RSA KeyGen (FIPS186-4) (A3349)PCTPCTOn DemandManually via a reboot
ECDSA SigVer (FIPS186-4) (A3349)KATSW/FW LoadOn DemandManually via loading of firmware from an external source
Page 56
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Manual entry test (duplicate entries)Duplicate entry testManual EntryOn DemandManually via configuration of operator passwords
NameDescriptionConditionsRecovery MethodIndicator
Hard Error stateIf the pre-operation firmware integrity test, if any of the CASTs or pair- wise consistency tests fail, then the module returns an error indicator, inhibits all data output and enters the hard error stateIf the pre- operational firmware integrity test or if any of the CASTs failN/A"FIPS error: self- test failure" for firmware integrity failure, "FIPS error 1: <name of the algorithm> Known Answer Test: Failed" for CAST failure and -1 for pair-wise consistency test failure
Soft Error state•In case of a firmware load test failure, the module rejects the firmware, returns an error indicator and enters the soft error state •In the event of an APT or RCT health test failure, output from the entropy source is inhibited, all entropy accumulated in the conditioning context is discarded and the start- up health-tests are performed againIf the firmware load test fails If the APT or RCT test failsN/A for firmware load test failure; In case of APT and/or RCT failures, new data continues to be tested by the health tests, and once both health tests indicate a “pass”, the entropy source again outputs data"Validation Error" for the firmware load test failure; entropy data discarded in case of APT/RCT failure

Table 27: Conditional Periodic Information prior to any other use of cryptography by the module in the Approved mode of operation. These

10.4 Error States
Page 57

If the conditional self-tests fail, the module enters the soft error state, i.e., it rejects the generated keypair/loaded image, returns an error indicator and resumes normal operation.

10.5 Operator Initiation of Self-Tests

Each time the module is powered up it tests that all the cryptographic algorithms operate correctly, and that sensitive data have not been damaged. Pre-operational as well as Conditional Cryptographic Algorithm Self-tests (CAST) are performed on each power up/boot of the module and on demand by power cycling the module (Perform self-tests (remote reset) service).

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The Crypto Officer must follow the procedures defined below for secure installation, initialization, startup and operation of the module. Crypto Officer Guidance The Crypto Officer must check to verify the firmware image being loaded on the module is the FIPS 140-3 validated version/image. If the image is the FIPS 140-3 validated image, then proceed with installation of the image. Installing The Firmware Image Download the validated firmware image from https://www.juniper.net/support/downloads/junos.html. Log in to the Juniper Networks authentication system using the username (generally your e-mail address) and password supplied by Juniper Networks representatives. Select the validated firmware image. Download the firmware image to a local host or to an internal software distribution site. Connect to the console port on the device from your management device and log in to the Junos OS CLI. Copy the firmware package to the device to the /var/tmp/ directory. Install the new package on the device using the following command: operator > request vmhost software add /var/tmp/<package>.tgz. NOTE: If you need to terminate the installation, do not reboot your device; instead, finish the installation and then issue the request system software delete package.tgz command, where package.tgz is, for example, jinstall-host-qfx-10-f-x86-64.22.3R1-S2.3.secure-signed.tgz.This is your last chance to stop the installation. Reboot the device to complete the load and start the installation: For QFX10002-60C: operator> request vmhost reboot

Page 58

For QFX10002-36Q/QFX10002-72Q/QFX10008/QFX10016: operator> request system reboot After the reboot has completed, log in and use the show version command to verify that the new version of the firmware is successfully installed. Also install the built-in fips-mode.tgz package needed for enabling the Approved-mode and the jpfe-fips package needed for execution of the CASTs. Please note that this is a one-time installation after which the module remains in the Approved mode once enabled and automatically executes the CASTs on each boot without requiring any operator or external intervention. The following are the commands used for installing these packages: operator >request system software add optional://fips-mode.tgz operator >request system software add optional://jpfe-fips.tgz Enabling Approved Mode of Operation The Crypto Officer is responsible for initializing the module in the Approved mode of operation. The Approved mode of operation is not automatically enabled. The Crypto Officer shall place the module in the Approved mode by first zeroising it to ensure no SSPs are present. Next, the cryptographic officer shall follow the steps found in the Junos OS FIPS Evaluated Configuration Guide for QFX Series, Release 22.3R1 document Chapter 2 to place the module into an Approved mode of operation. The steps from the aforementioned document have been reiterated below. To enable the Approved mode in Junos OS on the module:

  1. Zeroise the module using the “request vmhost zeroize” command for QFX10002-60C hardware version or “request system zeroize” command for the other hardware versions. Once the module comes up in the “amnesiac mode” post zeroisation, connect to it using the console port with username “root” and enter the configuration mode. Enable the Approved mode on the device by setting the Approved level to 1, and verify the level: [edit] root# set system fips level 1 [edit] root# show system fips level level 1;
  2. Configure the root-authentication password (i.e., Crypto Officer credentials) as follows: root> edit Entering configuration mode [edit] root# set system root-authentication plain-text password New password: Retype new password:
Page 59
  1. Commit the configuration [edit ] root# commit configuration check succeeds Generating RSA key /etc/ssh/fips_ssh_host_key Generating RSA2 key /etc/ssh/fips_ssh_host_rsa_key Generating ECDSA key /etc/ssh/fips_ssh_host_ecdsa_key 'system' reboot is required to transition to fips level 1 commit complete
  2. Reboot the device: [edit] root# run request system reboot Reboot the system ? [yes,no] (no) yes During the reboot, the device runs the pre-operational firmware integrity test and all CASTs. It returns a login prompt as follows: root:fips>
  3. After the reboot has completed, log in and use the show version command to verify the firmware version is the validated version: root:fips > show version Placing the Module in the Non-Approved Mode of Operation As Crypto Officer, the operator needs to disable the Approved mode of operation on the device to return it to the non-Approved mode of operation. To disable the Approved mode on the device, the module must be zeroised (step 1 defined above).
11.2 Administrator Guidance

For further information and for the Administrator guidance, please see the Junos OS FIPS Evaluated Configuration Guide for QFX, Release 22.3R1 document.

11.3 Non-Administrator Guidance

For further information and for the Administrator guidance, please see the Junos OS FIPS Evaluated Configuration Guide for QFX, Release 22.3R1 document.

11.4 Maintenance Requirements
Page 60

No other maintenance requirements apply for operation of the module in the Approved/nonApproved modes as defined above.

11.5 End of Life

The module can be securely sanitized at the end of its lifetime by zeroising it.

12 Mitigation of Other Attacks
12.1 Attack List

The module does not implement any mitigation of other attacks and thus the requirements per this section do not apply to the module.