Verify the Security Engine self-tests
The Security Engine contains the Forcepoint Network Security Platform FIPS Library, Forcepoint Network Security Platform FIPS Cryptographic Module, and Forcepoint Network Security Platform Cryptographic Kernel Module. The modules run several self-tests when the Forcepoint Network Security Platform appliance starts.
The modules perform these tests:
- Cryptographic Algorithm Self-Tests (CAST) implemented as Known Answer Tests (KAT)
- Forcepoint Network Security Platform FIPS Library self-tests
- Forcepoint Network Security Platform FIPS Cryptographic Module self-tests
- Forcepoint Network Security Platform Cryptographic Kernel Module self-tests
| Algorithm | Type | Test Method |
|---|---|---|
| HMAC-SHA2- 256 | SW/FW Integrity | Message Authentication |
| AES-ECB | CAST | KAT |
| AES-GCM | CAST | KAT |
| Counter DRBG | CAST | KAT |
| DSA SigGen (FIPS186-4) | CAST | KAT |
| DSA SigVer (FIPS186-4) | CAST | KAT |
| ECDSA SigGen (FIPS186-4) | CAST | KAT |
| ECDSA SigVer (FIPS186-4) | CAST | KAT |
| Hash DRBG | CAST | KAT |
| HMAC DRBG | CAST | KAT |
| HMAC-SHA2-256 | CAST | KAT |
| KASECC-SSC Sp800-56Ar3 | CAST | KAT |
| KAS-FFCSSC Sp800-56Ar3 | CAST | KAT |
| KAS-IFCSSC | CAST | KAT |
| KDF SP800-108 | CAST | KAT |
| KDA OneStep SP800-56Cr2 | CAST | KAT |
| KDA TwoStep SP800-56Cr2 | CAST | KAT |
| KTS-IFC | CAST | KAT |
| KTS-IFC | CAST | KAT |
| PBKDF | CAST | KAT |
| RSA SigGen (FIPS186-4) | CAST | KAT |
| RSA SigVer (FIPS186-4) | CAST | KAT |
| SHA-1 | CAST | KAT |
| SHA2-512 | CAST | KAT |
| SHA3-256 | CAST | KAT |
| KDF ANS 9.42 | CAST | KAT |
| KDF ANS 9.63 | CAST | KAT |
| KDF SSH | CAST | KAT |
| TLS v1.2 KDF RFC7627 | CAST | KAT |
| TLS v1.3 KDF | CAST | KAT |
| RSA KeyGen (FIPS186-4) | Pair-Wise Consistency Test | PCT |
| ECDSA KeyGen (FIPS186-4) | Pair-Wise Consistency Test | PCT |
| DSA KeyGen (FIPS186-4) | Pair-Wise Consistency Test | PCT |
| ECDSA SigGen (FIPS186-4) | CAST | KAT |
| ECDSA SigVer (FIPS186-4) | CAST | KAT |
| HMAC-SHA2-256 | CAST | KAT |
| AES-ECB | CAST | KAT |
| AES-GCM | CAST | KAT |
| AES-GCM | CAST | KAT |
| Counter DRBG | CAST | KAT |
| DSA SigGen (FIPS186-4) | CAST | KAT |
| DSA SigVer (FIPS186-4) | CAST | KAT |
| ECDSA SigGen (FIPS186-4) | CAST | KAT |
| ECDSA SigVer (FIPS186-4) | CAST | KAT |
| Hash DRBG | CAST | KAT |
| HMAC DRBG | CAST | KAT |
| HMAC-SHA2-256 | CAST | KAT |
| KAS-ECC-SSC Sp800-56Ar3 | CAST | KAT |
| KAS-FFC-SSC Sp800-56Ar3 | CAST | KAT |
| KAS-IFC-SSC | CAST | KAT |
| KDF SP800-108 | CAST | KAT |
| KDA OneStep SP800-56Cr2 | CAST | KAT |
| KDA TwoStep SP800-56Cr2 | CAST | KAT |
| KTS-IFC | CAST | KAT |
| KTS-IFC | CAST | KAT |
| PBKDF | CAST | KAT |
| RSA SigGen (FIPS186-4) | CAST | KAT |
| RSA SigVer (FIPS186-4) | CAST | KAT |
| SHA-1 | CAST | KAT |
| SHA2-512 | CAST | KAT |
| SHA3-256 | CAST | KAT |
| KDF ANS 9.42 | CAST | KAT |
| KDF ANS 9.63 | CAST | KAT |
| KDF SSH | CAST | KAT |
| TLS v1.2 KDF RFC7627 | CAST | KAT |
| TLS v1.3 KDF | CAST | KAT |
| RSA KeyGen (FIPS186-4) | Pair-Wise Consistency Test | PCT |
| ECDSA KeyGen (FIPS186-4) | Pair-Wise Consistency Test | PCT |
| DSA KeyGen (FIPS186-4) | Pair-Wise Consistency Test | PCT |
| ECDSA SigGen (FIPS186-4) | CAST | KAT |
| ECDSA SigVer (FIPS186-4) | CAST | KAT |
| Algorithm | Type | Test Method |
|---|---|---|
| ECDSA signature verify with NIST P-224 and SHA2-224 | Software Integrity | |
| SHA-1 | CAST | KAT |
| SHA2-512 | CAST | KAT |
| SHA3-224 | CAST | KAT |
| HMAC-SHA2-256 | CAST | KAT |
| AES-CBC encryption (128-bit key) | CAST | KAT |
| AES-CBC decryption (128-bit key) | CAST | KAT |
| AES-CCM encryption (128-bit key) | CAST | KAT |
| AES-CCM decryption (128-bit key) | CAST | KAT |
| AES-GCM encryption (128-bit key) | CAST | KAT |
| AES-GCM decryption (128-bit key) | CAST | KAT |
| AES-XTS encryption (128-bit key strength) | CAST | KAT |
| AES-XTS decryption (128-bit key strength) | CAST | KAT |
| AES-CMAC (192-bit key) | CAST | KAT |
| TDES-CBC encryption (192-bit key) | CAST | KAT |
| TDES-CBC decryption (192-bit key) | CAST | KAT |
| Counter DRBG AES-256 (instantiate, generate and reseed; includes AES-ECB mode encryption) | CAST | KAT |
| RSA SigGen 2048-bit with SHA2-256 | CAST | KAT |
| RSA SigVer 2048-bit with SHA2-256 | CAST | KAT |
| DSA SigGen (P=2048/N=256 with SHA2-224) | CAST | KAT |
| DSA SigVer (P=1024/N=160 with SHA2-224) | CAST | KAT |
| ECDSA SigGen (NIST P-224 with SHA2-224) | CAST | KAT |
| ECDSA SigVer (NIST P-224 with SHA2-224) | CAST | KAT |
| KTS-IFC Key Encapsulation 2048-bit (RSA-OAEP) | CAST | KAT |
| KTS-IFC Key Un-encapsulation 2048-bit (RSA-OAEP) | CAST | KAT |
| KAS-FFC-SSC (P=2048/N=224) | CAST | KAT |
| KAS-ECC-SSC (NIST P-224) | CAST | KAT |
| KDF SP800-108 (Counter Mode) | CAST | KAT |
| KDA HKDF (includes KDF SP800-108 Feedback Mode) | CAST | KAT |
| KDF SP800-108 (Double Pipeline Mode) | CAST | KAT |
| KDF IKEv1 | CAST | KAT |
| KDF IKEv2 | CAST | KAT |
| TLS v1.2 KDF RFC7627 | CAST | KAT |
| SP 800-90A-r1, (Instantiate/Generate) health tests for Counter DRBG AES-256 | CAST | KAT |
| SP 800-90A-r1, (Reseed) health test Counter DRBG AES-256 | CAST | KAT |
| SP 800-90B, start-up and continuous health tests (RCT and APT) for JitterEntropy ENT (NP) | CAST | Fault Detection Tests |
| Algorithm | Type | Test Method |
|---|---|---|
| HMAC-SHA2-256 | Software Integrity | Message Authentication |
| AES encryption (AES-CBC, AES-CFB128, AES-ECB, AES-OFB 128, 192, 256) | CAST | KAT |
| AES decryption (AES-CBC, AES-CFB128, AES-ECB, AES-OFB 128, 192, 256) | CAST | KAT |
| AES-GCM 128 authenticated encryption | CAST | KAT |
| AES-GCM 128 authenticated decryption | CAST | KAT |
| SHA (SHA-1, SHA2-256, SHA2- 512) | CAST | KAT |
| HMAC (HMAC-SHA-1, HMACSHA2-256, HMAC-SHA2- 512) | CAST | KAT |
Check the self-test results in the console.
- If a cryptographic self-test or a noise source health test fails, an error message is shown on the console and the appliance is restarted automatically. Noise source health tests are
automatically executed as part of the self-tests when Forcepoint Network Security Platform FIPS Library and Forcepoint Network Security Platform FIPS
Cryptographic Module are
loaded.
FIPS: OpenSSL self-tests FAILED, rebooting… Cryptographic Kernel Module self tests failed FIPS: Cryptographic module self-tests FAILED, rebooting...FIPS: rootfs integrity check FAILED, rebooting…
Next steps
- If the self-tests succeed, continue configuring the Security Engine.
- If the problem persists, reset the Security Engine to factory settings.To reset the Security Engine, do the following:
- Power off the Security Engine.
- Power on the Security Engine, and select the System restore options option from the local console boot menu.
- Follow the instructions to reset the Security Engine.