certification
This command lets you see the status of the following compliance modes and turn them on or off.
- National Essential Security Certification (LINCE): A public standard of Spain that defines security requirements for cryptographic modules. For compliant SFOS versions, see National Essential Security Certification (LINCE).
- Federal Information Processing Standard 140-3 (FIPS 140-3) Level 1: A public standard of the United States that defines security requirements for cryptographic modules. For compliant SFOS versions, see FIPS 140-3 Level 1.
Command
system certification
Syntax
system certification
lince [enable|disable|show]
fips [enable|disable|show]
Options
Use the following options to manage LINCE and FIPS compliance modes.
LINCE
lince [enable|disable|show]-
Turn LINCE compliance mode on or off and see the current compliance status.
Tip
For more information about backup-restore, firmware upgrades, firewall behavior after you turn on LINCE, and HA deployments, see How to turn on LINCE.
Example
system certification lince enablesystem certification lince disablesystem certification lince show
FIPS
fips [enable|disable|show]-
Turn FIPS compliance mode on or off and see the current compliance status.
Warning
Turning on FIPS requires a factory reset of the firewall to apply the FIPS-compliant algorithms to the firewall's features. After you turn on FIPS, you must configure the firewall again.
For more information about backup-restore, firmware upgrades, factory reset, and HA deployments, see Turn on FIPS.
Example
system certification fips enablesystem certification fips disablesystem certification fips show