Performing Self-Test

The cryptographic module enforces security rules to ensure that the Juniper Networks Junos OS Evolved in FIPS mode meets the security requirements of FIPS 140-3 Level 1. To validate the output of cryptographic algorithms approved for FIPS and test the integrity of some system modules, the device performs series of known answer test (KAT) self-tests.

The KAT self-tests are performed automatically at startup.

If the KATs are completed successfully, the dmesg log is updated to display the tests that are executed. You can view the logs by executing journalctl -b | grep self-test on the device shell.

Self-test failure results in a FIPS error state and the device automatically reboots after encountering a FIPS error state. No administrator actions are required.

Use of any of other cryptographic implementations was not evaluated nor tested during the CC evaluation of the TOE.

Integrity Validation

To validate the integrity, set the FIPS level and reboot the device and verify the integrity logs.

If there is an integrity failure, the modules stops and generates a FIPS error state (causing an automatic reboot as described above). No administrator actions are required.

You can check the logs for a successful integrity. For example: