Dell AP-93, W- AP92, W-AP105, AP-92, AP-175, W-AP93, W-AP175, AP-105 User Services, Pmk, Ptk, Eapol MIC

Page 36

Service

Description

CSPs Accessed (see section 6

 

 

below for complete description of

 

 

CSPs)

 

 

 

 

 

Creation/use of secure

The module supports use of

IKEv1/IKEv2 Preshared

management session between

IPSec for securing the

 

Secret

module and CO

management channel.

DH Private Key

 

 

 

 

DH Public Key

 

 

IPSec session encryption

 

 

 

keys

 

 

IPSec session

 

 

 

authentication keys

 

 

RSA key pair

 

 

 

 

Creation/use of secure mesh

The module requires secure

WPA2-PSK

channel

connections between mesh points

802.11i PMK

 

using 802.11i

 

 

 

 

 

802.11i PTK

 

 

802.11i EAPOL MIC

 

 

 

Key

 

 

802.11i EAPOL

 

 

 

Encryption Key

 

 

∙ 802.11i AES-CCM key

 

 

802.11i GMK

 

 

802.11i GTK

 

 

∙ 802.11i AES-CCM key

 

 

 

System Status

CO may view system status

See creation/use of secure

 

information through the secured

management session above.

 

management channel

 

 

 

 

 

 

4.2.2 User Services

The User services defined in Remote AP FIPS mode and CPSec protected AP FIPS mode shares the same services with the Crypto Officer role, please refer to Section 4.2.1, “Crypto Officer Services”. The following services are provided for the User role defined in Remote Mesh Portal FIPS mode and Remote Mesh Point FIPS mode:

Service

Description

CSPs Accessed (see section 6

 

 

below for complete description of

 

 

CSPs)

 

 

 

 

 

 

 

Generation and use of 802.11i

When the module is in mesh

802.11i

PMK

cryptographic keys

configuration, the inter-module

802.11i

PTK

 

mesh links are secured with

 

 

 

 

 

802.11i.

802.11i

EAPOL MIC

 

 

 

Key

 

 

 

802.11i EAPOL

 

 

 

Encryption Key

 

 

 

 

 

36

Image 36
Contents Version Feb Aruba Networks Crossman Ave Sunnyvale, CA Page Aruba Dell Relationship Acronyms and Abbreviations AP-105 SeriesAP-175 Series Security Levels Physical SecurityROLES, Authentication and Services Introduction Aruba Dell RelationshipAcronyms and Abbreviations GHz IPSecProduct Overview AP-92Physical Description Aruba Part Number Dell Corresponding Part NumberAP-92 Indicator LEDs Label Function Action Status PWREnet AP-93 Label Function Action StatusAP-93 Indicator LEDs Label Function Action Status AP-105 Wireless Access Point AP-105 SeriesAP-105 Indicator LEDs Label Function Action Status AP-175 Wireless Access Point AP-175 SeriesPhysical Description AP-175 Indicator LEDs Label Function Action Status PositionModule Objectives Security LevelsPhysical Security Applying TELs2 AP-92 TEL Placement AP-92 Tel placement front viewAruba AP-92 Tel placement right view 3 AP-93 TEL Placement Aruba AP-92 Tel placement bottom viewAruba AP-93 Tel placement left view 4 AP-105 TEL Placement Aruba AP-93 Tel placement top viewAruba AP-105 Tel placement left view 5 AP-175 TEL Placement Aruba AP-105 Tel placement bottom viewAruba AP-175 Tel placement back view Inspection/Testing of Physical Security Mechanisms Aruba AP-175 Tel placement top viewConfiguring Remote AP Fips Mode Modes of OperationEnable Fips mode on the AP. This accomplished by going to Configuring Remote Mesh Portal Fips Mode Configuring Remote Mesh Point Fips Mode Verify that the module is in Fips mode Operational EnvironmentLogical Interfaces Fips 140-2 Logical Interfaces Module Physical InterfaceRoles, Authentication and Services Crypto Officer AuthenticationRoles User Authentication Wireless Client AuthenticationStrength of Authentication Mechanisms Authentication Mechanism StrengthWPA2-PSK Services Crypto Officer ServicesWPA2 PSK KEKUser Services PMKPTK Eapol MICWireless Client Services Unauthenticated Services∙ FTP ∙ Tftp ∙ NTP Cryptographic Algorithms Non-FIPS Approved AlgorithmsCritical Security Parameters HmacRNG PSK AES-CCMGMK GTKSelf Tests For an AES Atheros hardware Post failure