Verify the SMC Appliance self-tests

The SMC Appliance contains several modules that run self-tests when the SMC Appliance starts.

Known answer tests (KAT) and pairwise consistency tests (PCT) are run for the software cryptographic modules.

Integrity check verifies the ECDSA signature of a catalog file of the SHA-256 hashes of all binaries.

Noise source health tests include a Repetition Count Test and a Chi-Squared test to fulfill the role of the Adaptive Proportion Test as specified by NIST SP 800-90B.

Table 1. SMC FIPS Java API self-tests
Algorithm Type Test Method
HMAC-SHA2-256 Software Integrity Message Authentication
AES-ECB Encryption CAST KAT
AES-ECB Decryption CAST KAT
AES-CCM Encryption CAST KAT
AES-CCM Decryption CAST KAT
AES-CMAC Generation CAST KAT
AES-CMAC Verification CAST KAT
KAS-ECC Primitive “Z” Computation CAST KAT
KAS-FFC Primitive “Z” Computation CAST KAT
HASH_DRBG SHA2-256 CAST KAT
HMAC-DRBG HMAC-SHA2-256 CAST KAT
CTR_DRBG AES-CTR 256 bits CAST KAT
DSA Signature Generation CAST KAT
DSA Signature Verification CAST KAT
ECDSA Signature Generation CAST KAT
ECSDA Signature Verification CAST KAT
AES-GCM Encrypt CAST KAT
AES-GCM Decrypt CAST KAT
HMAC-SHA2-256 CAST KAT
HMAC-SHA2-512 CAST KAT
HMAC-SHA3-256 CAST KAT
KDA OneStep CAST KAT
KDA TwoStep CAST KAT
KBKDF CAST KAT
PBKDF CAST KAT
SHA-3 CAST KAT
RSA Signature Generation CAST KAT
RSA Signature Verification CAST KAT
RSA Encryption CAST KAT
RSA Decryption CAST KAT
SHA-1 CAST KAT
SHA2-256 CAST KAT
SHA2-512 CAST KAT
SHAKE256 CAST KAT
ANS 9.63 KDF CAST KAT
IKEv2 KDF CAST KAT
SNMP KDF CAST KAT
SRTP KDF CAST KAT
SSH KDF CAST KAT
TLS 1.0 KDF CAST KAT
TLS 1.1 KDF CAST KAT
TLS 1.2 KDF CAST KAT
HMAC CAST KAT
SHS CAST KAT
DH Pair-Wise Consistency Test PCT
DSA Pair-Wise Consistency Test PCT
EC DH Pair-Wise Consistency Test PCT
ECDSA Pair-Wise Consistency Test PCT
RSA Pair-Wise Consistency Test PCT
Table 2. SMC FIPS Library self-tests
Algorithm Type Test Method
HMAC-SHA2-256 Software integrity Message Authentication
SHA2-512 CAST KAT
SHA3-256 CAST KAT
AES-ECB CAST KAT
AES-GCM CAST KAT
KBKDF CAST KAT
KDA OneStep CAST KAT
HKDF CAST KAT
ANS X9.42 KDF (CVL) CAST KAT
ANS X9.63 KDF (CVL) CAST KAT
SSH KDF (CVL) CAST KAT
TLS 1.2 KDF (CVL) CAST KAT
TLS 1.3 KDF (CVL) CAST KAT
PBKDF2 CAST KAT
CTR_DRBG CAST KAT
Hash_DRBG CAST KAT
HMAC_DRBG CAST KAT
KAS-FFC-SSC CAST KAT
KAS-ECC-SSC CAST KAT
RSA CAST KAT
ECDSA CAST KAT
ECDSA Pair-Wise Consistency Test PCT
RSA Pair-Wise Consistency Test PCT
Safe Primes Pair-Wise Consistency Test PCT
Table 3. SMC FIPS Cryptographic Module for NTP self-tests
Algorithm Type Test Method
HMAC-SHA-256 Software integrity Message Authentication
SHA-1 CAST KAT
SHA-224 CAST KAT
SHA-256 CAST KAT
SHA-384 CAST KAT
SHA-512 CAST KAT
AES-ECB CAST KAT
AES-CBC CAST KAT
AES-GCM CAST KAT
AES-CMAC CAST KAT
HMAC SHA-224 CAST KAT
HMAC SHA-256 CAST KAT
HMAC SHA-384 CAST KAT
HMAC SHA-512 CAST KAT
KBKDF CAST KAT
HKDF CAST KAT
TLS 1.0/1.1 KDF CAST KAT
TLS 1.2 KDF CAST KAT
IKEv2 PRF CAST KAT
PBKDF2 CAST KAT
Hash_DRBG CAST KAT
KAS-FFC-SSC CAST KAT
KAS-ECC-SSC CAST KAT
RSA CAST KAT
DSA CAST KAT
ECDSA CAST KAT
Safe Primes Conditional Pairwise Consistency Self-Test PCT
ECDH Conditional Pairwise Consistency Self-Test PCT
RSA Conditional Pairwise Consistency Self-Test PCT
ECDSA Conditional Pairwise Consistency Self-Test PCT

Check the self-test results in the console. The self-test messages are also sent to the SMC Appliance syslog.

  • If the SMC FIPS Java API cryptographic module self-test fails, the server application fails to start, and an error message is shown on the console and the appliance halts its execution automatically.
    fipssmc: ERROR: FIPS SMC Bouncy Castle
    fipssmc: FIPS System Shutdown
  • If a power-up self-test fails, an error message is shown on the console and the appliance halts and is not remotely accessible.
    fipstest:Performing FIPS NSS crypto selftests...
    Fatal FIPS Error: fipstest:ERROR:FIPS NSS crypto selftest failed: /lib/fips/fipstest-ossl: 255
    fipstest: Performing FIPS OpenSSL crypto selftests…
    Fatal FIPS Error: fipstest:ERROR:FIPS OpenSSL crypto selftest failed: /lib/fips/fipstest-ossl: 1
  • If the file system integrity check fails, an error message is shown on the console and the appliance halts and is not remotely accessible.
    fipscheck: Performing FIPS integrity check…
    Fatal FIPS Error: fipscheck:ERROR:FIPS integrity check failed. /usr/bin/smca-fipscheck: 255
  • If a noise source health test fails, an error message is shown on the console and the appliance halts and is not remotely accessible.
    fipsrngdtest: Performing FIPS rngd self test...
    Fatal FIPS Error: fipsrngdtest:ERROR:FIPS rngd self test failed: 1

If a self-test fails, see the Reset the SMC Appliance to factory settings topic.

Next steps

  • If the self-tests succeed, continue configuring the SMC Appliance.
  • If a self-test fails, restart the SMC Appliance manually. It does not restart automatically.
  • If a self-test continues to fail, reset the SMC Appliance to factory settings.
    To reset the SMC Appliance:
    1. Reboot the SMC Appliance.
    2. Select the VCDROM option from the boot menu.
    3. Start the fresh install.