Code CR2500 Code FIPS Manual de usuario Pagina 6

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 8
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 5
C005590_01_CR2500_CR3500_User Manual_Appendix H
5
The code below shows the Authencaon .crb le that contains a new value for the CO password. This code is provided
as an example only and Code Corporaon recommends that the password below never be used in your producon
environment. This is an example based on the Reader password ‘NewRPass’.
; 8/5/2010 20:15
;Authentication command for FIPS Code products
;This example shows
;%48 = H = FIPS Command Set
;%33 = 3 = Authenticate Command
;Cryptographic Ofcer Password is %4E%65%77%52%50%61%73%73 or NewRPass (Passwords must not contain
%00-%1F)
%48%33%4E%65%77%52%50%61%73%73
Inializaon
The Inializaon process updates the CO password, the Reader password and the KEK. Now that you have new
Authencaon, Inializaon, and new Authencaon bar codes created you can use them to inialize the modules.
Note: Any customizaon bar codes such as Sux Enter must be scanned before pung the modules in FIPS mode.
1. Scan the QuickConnect code on the modem to pair the reader and modem modules.
2. Authencate the CO using the default Authencaon bar code (See Figure 1). Observe the indicators on
the modules showing that the CO has been authorized. (See secon ‘FIPS mode indicators on the
modules’ below)
3. Inialize the modules using the custom Inializaon bar code you created above. Observe the indicators
on the modules showing that the module has been inialized but no user is authencated. (See secon
‘FIPS mode indicators on the modules’ below)
4. The FIPS modules are now ready to be authencated by the Reader role to pass FIPS encrypted data or
the CO role to re-inialize again.
Zeroizaon
The Zeroizaon process removes the custom passwords and KEK applied in the Inializaon process. If the FIPS modules
are in an unknown state, Zeroize the modules and re-Inialize. You would also want to Zeroize the modules if you
believe the passwords or KEK have been compromised. Aer Zeroizaon the modules will respond just as non-FIPS
readers and modems unl they have been re-Inialized.
Below is the bar code for the Zeroizaon command:
Figure 2 - Zeroizaon Bar Code
FIPS Mode Indicators On the Modules
Due to the available lights and screens on the dierent FIPS modules they have slightly dierent behavior when
indicang FIPS modes.
CR2500 FIPS Reader -
The CR2500 module indicates FIPS mode in three stages. The three stages are:
Vista de pagina 5
1 2 3 4 5 6 7 8

Comentarios a estos manuales

Sin comentarios