Verify the SMC Appliance self-tests
The SMC Appliance contains several modules that run self-tests when the SMC Appliance starts.
Known answer tests (KAT) and pairwise consistency tests (PCT) are run for the software cryptographic modules.
Integrity check verifies the ECDSA signature of a catalog file of the SHA-256 hashes of all binaries.
Noise source health tests include a Repetition Count Test and a Chi-Squared test to fulfill the role of the Adaptive Proportion Test as specified by NIST SP 800-90B.
| Algorithm | Type | Test Method |
|---|---|---|
| HMAC-SHA2-256 | Software Integrity | Message Authentication |
| AES-ECB Encryption | CAST | KAT |
| AES-ECB Decryption | CAST | KAT |
| AES-CCM Encryption | CAST | KAT |
| AES-CCM Decryption | CAST | KAT |
| AES-CMAC Generation | CAST | KAT |
| AES-CMAC Verification | CAST | KAT |
| KAS-ECC Primitive “Z” Computation | CAST | KAT |
| KAS-FFC Primitive “Z” Computation | CAST | KAT |
| HASH_DRBG SHA2-256 | CAST | KAT |
| HMAC-DRBG HMAC-SHA2-256 | CAST | KAT |
| CTR_DRBG AES-CTR 256 bits | CAST | KAT |
| DSA Signature Generation | CAST | KAT |
| DSA Signature Verification | CAST | KAT |
| ECDSA Signature Generation | CAST | KAT |
| ECSDA Signature Verification | CAST | KAT |
| AES-GCM Encrypt | CAST | KAT |
| AES-GCM Decrypt | CAST | KAT |
| HMAC-SHA2-256 | CAST | KAT |
| HMAC-SHA2-512 | CAST | KAT |
| HMAC-SHA3-256 | CAST | KAT |
| KDA OneStep | CAST | KAT |
| KDA TwoStep | CAST | KAT |
| KBKDF | CAST | KAT |
| PBKDF | CAST | KAT |
| SHA-3 | CAST | KAT |
| RSA Signature Generation | CAST | KAT |
| RSA Signature Verification | CAST | KAT |
| RSA Encryption | CAST | KAT |
| RSA Decryption | CAST | KAT |
| SHA-1 | CAST | KAT |
| SHA2-256 | CAST | KAT |
| SHA2-512 | CAST | KAT |
| SHAKE256 | CAST | KAT |
| ANS 9.63 KDF | CAST | KAT |
| IKEv2 KDF | CAST | KAT |
| SNMP KDF | CAST | KAT |
| SRTP KDF | CAST | KAT |
| SSH KDF | CAST | KAT |
| TLS 1.0 KDF | CAST | KAT |
| TLS 1.1 KDF | CAST | KAT |
| TLS 1.2 KDF | CAST | KAT |
| HMAC | CAST | KAT |
| SHS | CAST | KAT |
| DH | Pair-Wise Consistency Test | PCT |
| DSA | Pair-Wise Consistency Test | PCT |
| EC DH | Pair-Wise Consistency Test | PCT |
| ECDSA | Pair-Wise Consistency Test | PCT |
| RSA | Pair-Wise Consistency Test | PCT |
| Algorithm | Type | Test Method |
|---|---|---|
| HMAC-SHA2-256 | Software integrity | Message Authentication |
| SHA2-512 | CAST | KAT |
| SHA3-256 | CAST | KAT |
| AES-ECB | CAST | KAT |
| AES-GCM | CAST | KAT |
| KBKDF | CAST | KAT |
| KDA OneStep | CAST | KAT |
| HKDF | CAST | KAT |
| ANS X9.42 KDF (CVL) | CAST | KAT |
| ANS X9.63 KDF (CVL) | CAST | KAT |
| SSH KDF (CVL) | CAST | KAT |
| TLS 1.2 KDF (CVL) | CAST | KAT |
| TLS 1.3 KDF (CVL) | CAST | KAT |
| PBKDF2 | CAST | KAT |
| CTR_DRBG | CAST | KAT |
| Hash_DRBG | CAST | KAT |
| HMAC_DRBG | CAST | KAT |
| KAS-FFC-SSC | CAST | KAT |
| KAS-ECC-SSC | CAST | KAT |
| RSA | CAST | KAT |
| ECDSA | CAST | KAT |
| ECDSA | Pair-Wise Consistency Test | PCT |
| RSA | Pair-Wise Consistency Test | PCT |
| Safe Primes | Pair-Wise Consistency Test | PCT |
| Algorithm | Type | Test Method |
|---|---|---|
| HMAC-SHA-256 | Software integrity | Message Authentication |
| SHA-1 | CAST | KAT |
| SHA-224 | CAST | KAT |
| SHA-256 | CAST | KAT |
| SHA-384 | CAST | KAT |
| SHA-512 | CAST | KAT |
| AES-ECB | CAST | KAT |
| AES-CBC | CAST | KAT |
| AES-GCM | CAST | KAT |
| AES-CMAC | CAST | KAT |
| HMAC SHA-224 | CAST | KAT |
| HMAC SHA-256 | CAST | KAT |
| HMAC SHA-384 | CAST | KAT |
| HMAC SHA-512 | CAST | KAT |
| KBKDF | CAST | KAT |
| HKDF | CAST | KAT |
| TLS 1.0/1.1 KDF | CAST | KAT |
| TLS 1.2 KDF | CAST | KAT |
| IKEv2 PRF | CAST | KAT |
| PBKDF2 | CAST | KAT |
| Hash_DRBG | CAST | KAT |
| KAS-FFC-SSC | CAST | KAT |
| KAS-ECC-SSC | CAST | KAT |
| RSA | CAST | KAT |
| DSA | CAST | KAT |
| ECDSA | CAST | KAT |
| Safe Primes | Conditional Pairwise Consistency Self-Test | PCT |
| ECDH | Conditional Pairwise Consistency Self-Test | PCT |
| RSA | Conditional Pairwise Consistency Self-Test | PCT |
| ECDSA | Conditional Pairwise Consistency Self-Test | PCT |
Check the self-test results in the console. The self-test messages are also sent to the SMC Appliance syslog.
- If the SMC FIPS Java API cryptographic module self-test fails, the server application fails to start, and an error message is shown on the console and the appliance halts its execution
automatically.
fipssmc: ERROR: FIPS SMC Bouncy Castle fipssmc: FIPS System Shutdown - If a power-up self-test fails, an error message is shown on the console and the appliance halts and is not remotely
accessible.
fipstest:Performing FIPS NSS crypto selftests... Fatal FIPS Error: fipstest:ERROR:FIPS NSS crypto selftest failed: /lib/fips/fipstest-ossl: 255fipstest: Performing FIPS OpenSSL crypto selftests… Fatal FIPS Error: fipstest:ERROR:FIPS OpenSSL crypto selftest failed: /lib/fips/fipstest-ossl: 1 - If the file system integrity check fails, an error message is shown on the console and the appliance halts and is not remotely
accessible.
fipscheck: Performing FIPS integrity check… Fatal FIPS Error: fipscheck:ERROR:FIPS integrity check failed. /usr/bin/smca-fipscheck: 255 - If a noise source health test fails, an error message is shown on the console and the appliance halts and is not remotely
accessible.
fipsrngdtest: Performing FIPS rngd self test... Fatal FIPS Error: fipsrngdtest:ERROR:FIPS rngd self test failed: 1
If a self-test fails, see the Reset the SMC Appliance to factory settings topic.
Next steps
- If the self-tests succeed, continue configuring the SMC Appliance.
- If a self-test fails, restart the SMC Appliance manually. It does not restart automatically.
- If a self-test continues to fail, reset the SMC Appliance to factory settings.To reset the SMC Appliance:
- Reboot the SMC Appliance.
- Select the VCDROM option from the boot menu.
- Start the fresh install.