<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FIPS mode in Azure Government in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/fips-mode-in-azure-government/m-p/449294#M1392</link>
    <description>&lt;P&gt;We use FIPS-CC mode in the Azure Government Cloud, using&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/certifications/enable-fips-and-common-criteria-support/change-the-operational-mode-to-fips-cc-mode.html" target="_self"&gt;this article&lt;/A&gt;&amp;nbsp;to set it. Basically:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;SSH into the FW (using your username and ssh key file)&lt;/LI&gt;&lt;LI&gt;Enter the commands to put the firewall into maintenance mode (debug system maintenance-mode) - this will cause a reboot&lt;/LI&gt;&lt;LI&gt;SSH into the FW again, and set the FW to FIPS-CC mode using the article linked above, then reboot the firewall again&lt;/LI&gt;&lt;LI&gt;Once the firewall is back and in FIPS-CC mode, it should still allow you to SSH in using the same credentials. We then make an admin user so that we can log into the GUI for the firewall&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;As to your second question, we don't use an ARM template, but use Terraform instead, specifically the "tls" provider (&lt;A href="https://registry.terraform.io/providers/hashicorp/tls/latest" target="_blank"&gt;hashicorp/tls | Terraform Registry&lt;/A&gt;), which lets you make a private/public key pair, which we then import into Azure Key Vault.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that all helps!&lt;/P&gt;</description>
    <pubDate>Wed, 24 Nov 2021 18:52:07 GMT</pubDate>
    <dc:creator>StevenRogers</dc:creator>
    <dc:date>2021-11-24T18:52:07Z</dc:date>
    <item>
      <title>FIPS mode in Azure Government</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/fips-mode-in-azure-government/m-p/412578#M1210</link>
      <description>&lt;P&gt;Has anyone been successful in converting their VM-series appliances running in Azure Government to FIPS-CC mode? The SSH keys I created and allowed for FW management prior to the conversion were wiped out and resetting the keys via the Azure portal doesn't work (although the agent is running). I cannot get into the GUI either since admin is not a supported username in Azure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second question, does anyone have a ARM template that successfully installs a SSH public key on a newly provisioned firewall? I can't seem to find the proper syntax.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated, thank you in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 15:03:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/fips-mode-in-azure-government/m-p/412578#M1210</guid>
      <dc:creator>cl625410</dc:creator>
      <dc:date>2021-06-11T15:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS mode in Azure Government</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/fips-mode-in-azure-government/m-p/449294#M1392</link>
      <description>&lt;P&gt;We use FIPS-CC mode in the Azure Government Cloud, using&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/certifications/enable-fips-and-common-criteria-support/change-the-operational-mode-to-fips-cc-mode.html" target="_self"&gt;this article&lt;/A&gt;&amp;nbsp;to set it. Basically:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;SSH into the FW (using your username and ssh key file)&lt;/LI&gt;&lt;LI&gt;Enter the commands to put the firewall into maintenance mode (debug system maintenance-mode) - this will cause a reboot&lt;/LI&gt;&lt;LI&gt;SSH into the FW again, and set the FW to FIPS-CC mode using the article linked above, then reboot the firewall again&lt;/LI&gt;&lt;LI&gt;Once the firewall is back and in FIPS-CC mode, it should still allow you to SSH in using the same credentials. We then make an admin user so that we can log into the GUI for the firewall&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;As to your second question, we don't use an ARM template, but use Terraform instead, specifically the "tls" provider (&lt;A href="https://registry.terraform.io/providers/hashicorp/tls/latest" target="_blank"&gt;hashicorp/tls | Terraform Registry&lt;/A&gt;), which lets you make a private/public key pair, which we then import into Azure Key Vault.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that all helps!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 18:52:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/fips-mode-in-azure-government/m-p/449294#M1392</guid>
      <dc:creator>StevenRogers</dc:creator>
      <dc:date>2021-11-24T18:52:07Z</dc:date>
    </item>
  </channel>
</rss>

