Aruba Networks FIPS 140-2 manual Wireless Client Services

Page 28

Service

Description

CSPs

Accessed (see section 6

 

 

below for complete description of

 

 

CSPs)

 

 

 

 

 

 

 

802.11i AES-CCM key

 

 

802.11i GMK

 

 

802.11i GTK

 

 

 

 

Use of WPA preshared key for

When the module is in mesh

 

 

establishment of IEEE 802.11i

configuration, the inter-module

WPA2 PSK

keys

mesh links are secured with

 

 

 

802.11i. This is authenticated

 

 

 

with a shared secret

 

 

 

 

 

 

4.2.3 Wireless Client Services

The following module services are provided for the Wireless Client role in each of FIPS approved modes.

Service

Description

CSPs

Accessed (see section 6

 

 

below for complete description of

 

 

CSPs)

 

 

 

 

 

Generation and use of 802.11i

In all modes, the links between

802.11i PMK

cryptographic keys

the module and wireless client are

802.11i PTK

 

secured with 802.11i.

 

 

 

 

 

802.11i EAPOL MIC

 

 

 

Key

 

 

802.11i EAPOL

 

 

 

Encryption Key

 

 

802.11i AES-CCM key

 

 

802.11i GMK

 

 

802.11i GTK

 

 

 

 

Use of WPA preshared key for

When the module is in advanced

 

 

establishment of IEEE 802.11i

Remote AP configuration, the

WPA2 PSK

keys

links between the module and the

 

 

 

wireless client are secured with

 

 

 

802.11i. This is authenticated

 

 

 

with a shared secret only.

 

 

 

 

 

 

Wireless bridging services

The module bridges traffic

 

 

 

between the wireless client and

None

 

the wired network.

 

 

 

 

 

 

 

28

Image 28
Contents Fips 140-2 Non-Proprietary Security Policy Page Services Aruba Dell Relationship Acronyms and AbbreviationsAruba AP-120 Series Security Levels Physical SecurityPage Introduction Aruba Dell RelationshipAcronyms and Abbreviations GHzLAN Product Overview Aruba AP-120 SeriesPhysical Description Aruba Part Number Dell Corresponding Part NumberPWR Indicator LEDs Label Function Action StatusEnet Label Function Action Status Module Objectives Security LevelsPhysical Security Applying TELsAruba AP-124 TEL Placement AP-124 Front viewAP-124 Back view Aruba AP-125 TEL Placement AP-124 Bottom viewAP-125 Front view AP-125 Right view Inspection/Testing of Physical Security Mechanisms AP-125 Bottom viewConfiguring Remote AP Fips Mode Modes of OperationEnable Fips mode on the AP. This accomplished by going to Configuring Remote Mesh Portal Fips Mode Configuring Remote Mesh Point Fips Mode Verify that the module is in Fips mode Operational EnvironmentLogical Interfaces Fips 140-2 Logical Interfaces Module Physical InterfaceCrypto Officer Authentication Roles, Authentication and ServicesRoles User Authentication Wireless Client AuthenticationStrength of Authentication Mechanisms Authentication Mechanism StrengthWPA2-PSK Services Crypto Officer ServicesService Description CSPs Accessed see section WPA2 PSKService Description CSPs User ServicesService Wireless Client Services Unauthenticated Services ∙ FTP ∙ Tftp ∙ NTPCryptographic Algorithms Non-FIPS Approved AlgorithmsCritical Security Parameters HmacRNG PTK PSKAES-CCM GMK GTKSelf Tests For an AES Cavium hardware Post failure