Reference Guide

37
o RSA Pairwise Consistency Test
ArubaOS Crypto Module
o CRNG Test to Approved RNG (FIPS 186-2 RNG)
o ECDSA Pairwise Consistency Test
o RSA Pairwise Consistency Test
ArubaOS Uboot BootLoader Module
o Firmware Load Test - RSA PKCS#1 v1.5 (2048 bits) signature verification
CRNG tests to non-Approved RNGs
These self-tests are run for the Atheros hardware cryptographic implementation as well as for the Aruba
OpenSSL and ArubaOS cryptographic module implementations.
Self-test results are written to the serial console.
In the event of a KATs failure, the AP logs different messages, depending on the error.
For an ArubaOS OpenSSL AP module and ArubaOS cryptographic module KAT failure:
AP rebooted [DATE][TIME] : Restarting System, SW FIPS KAT failed
For an AES Atheros hardware POST failure:
Starting HW SHA1 KAT ...Completed HW SHA1 AT
Starting HW HMAC-SHA1 KAT ...Completed HW HMAC-SHA1 KAT
Starting HW DES KAT ...Completed HW DES KAT
Starting HW AES KAT ...Restarting system.