The MD5/SHA1 algorithm standards are used by non-FIPS sensor images to verify a user password. FIPS capable Sensor images use the SHA-512 algorithm standard to verify the user password.
FIPS images require passwords to satisfy the following criterion:
Password length should be of minimum 15 characters.
Password should at the least contain 2 lower case, 2 upper case letters, 2 numeric, and 2 of the following special characters: !@#$%^&*()
New password must differ from the previous password by at least 4 characters.
Password must not be reused from the last 10 passwords.
Password expire in 45 days.
There can be issues during upgrade or downgrade between FIPS and non-FIPS Sensor images as mentioned below:
The default admin password has not changed: If there is no change in the default password, no conflict arises during upgrade/downgrade.
The default admin password has changed with FIPS capable image: If there is a change in the FIPS capable image, the password is reset to default. The initial bootup script of the FIPS capable image detects the password format to be of MD5 format and deletes it. The password is then reset to default SHA-512 supported format.
The default admin password has changed with non-FIPS capable image: Any change to a non-FIPS capable image will result in the password being reset to default. This process of resetting the password is done when the image is downloaded. The newly downloaded image version is compared to a tag, and if the newly downloaded image is non-FIPS capable, the password is deleted. The password is then reset to default MD5 supported format.
Upgrade or downgrade from non-FIPS to FIPS images
On a transition from non-FIPS to FIPS image, you can only login with default admin password. Since this default admin password is not FIPS compliant, you will be prompted to change the default admin password.
Note
If you had previously changed your password in a non-FIPS image, logging into the FIPS Sensor requires the default admin password for a FIPS images. The automatic configuration reset enforces the FIPS default password. The Manager notifies about this reset.
Upgrade or downgrade from FIPS images to non-FIPS
A transition from FIPS to non-FIPS will result in password being reset to default. You can only login using the default passwords for admin of the non FIPS image.