Configure a FIPS appliance for the first time
-
FIPS FAQ can be found here: FIPS FAQ.
Configure secure HTTPS by using the CLI
-
Initialize the hardware security module (HSM) on the FIPS card of the appliance. For information about initializing the HSM, see one of the following links:
-
For MPX: Configure the HSM.
-
-
If the appliance is part of a high availability setup, enable the SIM. For information about enabling the SIM on the primary and secondary appliances, see Configure FIPS appliances in a high availability setup.
-
Import the FIPS key into the HSM of the FIPS card of the appliance. At the command prompt, type:
import ssl fipskey serverkey -key ns-server.key -inform PEM -
Add a certificate-key pair. At the command prompt, type:
add certkey server -cert ns-server.cert -fipskey serverkey -
Bind the certificate-key created in the previous step to the following internal services. At the command prompt, type:
bind ssl service nshttps-127.0.0.1-443 -certkeyname serverbind ssl service nshttps-::11-443 -certkeyname server
Configure secure HTTPS by using the GUI
-
Initialize the hardware security module (HSM) on the FIPS card of the appliance. For information about initializing the HSM, see one of the following links:
-
For MPX: Configure the HSM.
-
-
If the appliance is part of a high availability setup, enable the secure information system (SIM). For information about enabling the SIM on the primary and secondary appliances, see Configure FIPS appliances in a high availability setup.
-
Import the FIPS key into the HSM of the FIPS card of the appliance. For more information about importing a FIPS key, see the Import an existing FIPS key section.
-
Navigate to Traffic Management > SSL > Certificates.
-
In the details pane, click Install.
-
In the Install Certificate dialog box, type the certificate details.
-
Click Create, and then click Close.
-
Navigate to Traffic Management > Load Balancing > Services.
-
In the details pane, on the Action tab, click Internal Services.
-
Select
nshttps-127.0.0.1-443from the list, and then click Open. -
On the SSL Settings tab, in the Available pane, select the certificate created in step 7, click Add, and then click OK.
-
Select
nshttps-::11-443from the list, and then click Open. -
On the SSL Settings tab, in the Available pane, select the certificate created in step 7, click Add, and then click OK.
-
Click OK.
Configure secure RPC by using the CLI
-
Initialize the hardware security module (HSM) on the FIPS card of the appliance. For information about initializing the HSM, see one of the following links:
-
For MPX: Configure the HSM.
-
-
Enable the secure information system (SIM). For information about enabling the SIM on the primary and secondary appliances, see Configure FIPS appliances in a high availability setup.
-
Import the FIPS key into the HSM of the FIPS card of the appliance. At the command prompt, type:
import ssl fipskey serverkey -key ns-server.key -inform PEM -
Add a certificate-key pair. At the command prompt, type:
add certkey server -cert ns-server.cert -fipskey serverkey -
Bind the certificate-key pair to the following internal services. At the command prompt, type:
bind ssl service nsrpcs-127.0.0.1-3008 -certkeyname serverbind ssl service nskrpcs-127.0.0.1-3009 -certkeyname serverbind ssl service nsrpcs-::1l-3008 -certkeyname server -
Enable secure RPC mode. At the command prompt, type:
set ns rpcnode \<IP address\> -secure YESFor more information about changing an RPC node password, see Change an RPC node password.
Configure secure RPC by using the GUI
-
Initialize the hardware security module (HSM) on the FIPS card of the appliance. For information about initializing the HSM, see one of the following links:
-
For MPX: Configure the HSM.
-
-
Enable the secure information system (SIM). For information about enabling the SIM on the primary and secondary appliances, Configure FIPS appliances in a high availability setup.
-
Import the FIPS key into the HSM of the FIPS card of the appliance. For more information about importing a FIPS key, the Import an existing FIPS key section.
-
Navigate to Traffic Management > SSL > Certificates.
-
In the details pane, click Install.
-
In the Install Certificate dialog box, type the certificate details.
-
Click Create, and then click Close.
-
Navigate to Traffic Management > Load Balancing > Services.
-
In the details pane, on the Action tab, click Internal Services.
-
Select
nsrpcs-127.0.0.1-3008from the list, and then click Open. -
On the SSL Settings tab, in the Available pane, select the certificate created in step 7, click Add, and then click OK.
-
Select
nskrpcs-127.0.0.1-3009from the list, and then click Open. -
On the SSL Settings tab, in the Available pane, select the certificate created in step 7, click Add, and then click OK.
-
Select
nsrpcs-::11-3008from the list, and then click Open. -
On the SSL Settings tab, in the Available pane, select the certificate created in step 7, click Add, and then click OK.
-
Click OK.
-
Navigate to System > Network > RPC.
-
In the details pane, select the IP address, and click Open.
-
In the Configure RPC Node dialog box, select Secure.
-
Click OK.