Dell W-AP135, AP-134, AP-135, W-AP134 manual User Services, Pmk, Ptk, Eapol MIC

Page 26

Service

Description

CSPs Accessed (see section 6

 

 

below for complete description of

 

 

CSPs)

 

 

 

 

 

Creation/use of secure

The module supports use of

IKEv1/IKEv2 Preshared

management session between

IPSec for securing the

 

Secret

module and CO

management channel.

DH Private Key

 

 

 

 

DH Public Key

 

 

IPSec session encryption

 

 

 

keys

 

 

IPSec session

 

 

 

authentication keys

 

 

RSA key pair

 

 

 

 

Creation/use of secure mesh

The module requires secure

WPA2-PSK

channel

connections between mesh points

802.11i PMK

 

using 802.11i

 

 

 

 

 

802.11i PTK

 

 

802.11i EAPOL MIC

 

 

 

Key

 

 

802.11i EAPOL

 

 

 

Encryption Key

 

 

∙ 802.11i AES-CCM key

 

 

802.11i GMK

 

 

802.11i GTK

 

 

∙ 802.11i AES-CCM key

 

 

 

System Status

CO may view system status

See creation/use of secure

 

information through the secured

management session above.

 

management channel

 

 

 

 

 

 

4.2.2 User Services

The User services defined in Remote AP FIPS mode and CPSec protected AP FIPS mode shares the same services with the Crypto Officer role, please refer to Section 4.2.1, “Crypto Officer Services”. The following services are provided for the User role defined in Remote Mesh Portal FIPS mode and Remote Mesh Point FIPS mode:

Service

Description

CSPs Accessed (see section 6

 

 

below for complete description of

 

 

CSPs)

 

 

 

 

 

 

 

Generation and use of 802.11i

When the module is in mesh

802.11i

PMK

cryptographic keys

configuration, the inter-module

802.11i

PTK

 

mesh links are secured with

 

 

 

 

 

802.11i.

802.11i

EAPOL MIC

 

 

 

Key

 

 

 

802.11i EAPOL

 

 

 

Encryption Key

 

 

 

 

 

26

Image 26
Contents Fips 140-2 Non-Proprietary Security Policy Page Modes of Operation Aruba Dell Relationship Acronyms and AbbreviationsSecurity Levels Physical Security Operational Environment Logical InterfacesServices Acronyms and Abbreviations IntroductionAruba Dell Relationship CPSecSHA Physical Description Product OverviewAP-134 Aruba Part Number Dell Corresponding Part NumberENET0 AP-134 Indicator LEDs Label Function Action StatusPWR ENET1AP-135 AP-135 Indicator LEDs Label Function Action Status Physical Security Module ObjectivesSecurity Levels Applying TELs2 AP-134 TEL Placement AP-134 Front view3 AP-135 TEL Placement AP-134 Top ViewAP-135 Front view Inspection/Testing of Physical Security Mechanisms AP-135 Top viewConfiguring Remote AP Fips Mode Modes of OperationEnable Fips mode on the AP. This accomplished by going to Configuring Remote Mesh Portal Fips Mode Configuring Remote Mesh Point Fips Mode Verify that the module is in Fips mode Operational EnvironmentLogical Interfaces Fips 140-2 Logical Interface Module Physical InterfaceRoles Roles, Authentication and ServicesCrypto Officer Authentication Strength of Authentication Mechanisms User AuthenticationWireless Client Authentication Authentication Mechanism StrengthWPA2-PSK WPA2 PSK ServicesCrypto Officer Services KEKPTK User ServicesPMK Eapol MICWireless Client Services Unauthenticated Services∙ FTP ∙ Tftp ∙ NTP Cryptographic Algorithms Non-FIPS Approved AlgorithmsCritical Security Parameters HmacRNG PSK AES-CCMGMK GTKSelf Tests For an AES Atheros hardware Post failure