<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FIPS-CC mode default user/password issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579548#M116148</link>
    <description>&lt;P&gt;TAC engineer recommended to install 10.2.5, Enable FIPS here, then once enabled, Upgrade to 10.2.8 to prepare for the Certificate issue coming here in April.&amp;nbsp; Once you're FIPS enabled on a certificate approved image, I have had no issues upgrading further.&amp;nbsp; I also got confirmation that this is a known bug that is being tracked for fixing and affects most (all?) "modern" releases of the PAN-OS image.&lt;/P&gt;
&lt;P&gt;My deployment is now active with FIPS enabled following the provided steps.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Mar 2024 01:33:17 GMT</pubDate>
    <dc:creator>kylebrolafski</dc:creator>
    <dc:date>2024-03-07T01:33:17Z</dc:date>
    <item>
      <title>FIPS-CC mode default user/password issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579181#M116107</link>
      <description>&lt;P&gt;We recently tried switching to FIPS-CC mode but the factory default user/password didn't work.&lt;/P&gt;
&lt;P&gt;The Admin guide showed the default user/password to be admin/admin even in FIPS-CC mode. We also found a Palo Alto documentation that for FIPS-CC it should be admin/paloalto but that didn't work as well. There was a mention of using the serial number as the password when logging in via SSH which also didn't work. Does anyone know what this user and password should be?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 19:21:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579181#M116107</guid>
      <dc:creator>B.Vance</dc:creator>
      <dc:date>2024-03-04T19:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS-CC mode default user/password issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579190#M116108</link>
      <description>&lt;P&gt;I've run into this same issue on 11.x.x and opened a ticket.&amp;nbsp; The first recommendation was to validate you haven't locked yourself out with too many failures as FIPS will hard lock that account.&amp;nbsp; And being the only account at this point, the box is now effectively bricked.&amp;nbsp; The second recommendation was to downgrade to a known good OS version, iirc that was 10.2.0 in my experience and convert to FIPS there, then upgrade to 11.x.x within FIPS mode.&amp;nbsp; The engineer made a veiled reference to this being a known issue without any public documentation yet but wouldn't explain further.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 21:14:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579190#M116108</guid>
      <dc:creator>kylebrolafski</dc:creator>
      <dc:date>2024-03-04T21:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS-CC mode default user/password issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579192#M116109</link>
      <description>&lt;P&gt;However, I am literally doing this right now on a new deployment and run into the same issue again.&amp;nbsp; 10.2.7-h3 appears to also have issues with the default FIPS credentials.&amp;nbsp; Searching the default creds to make sure my memory is intact is actually how I found this thread.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 21:19:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579192#M116109</guid>
      <dc:creator>kylebrolafski</dc:creator>
      <dc:date>2024-03-04T21:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS-CC mode default user/password issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579314#M116125</link>
      <description>&lt;P&gt;Hey KevinVanDyke,&lt;/P&gt;
&lt;P&gt;Thanks for your response. As a result we are now looking at getting an exemption with our FIPS requirement on the firewall until this issue is resolved by PAN. I'll except this as the solution and post back here if I discover anything further. Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 15:44:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579314#M116125</guid>
      <dc:creator>B.Vance</dc:creator>
      <dc:date>2024-03-05T15:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS-CC mode default user/password issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579548#M116148</link>
      <description>&lt;P&gt;TAC engineer recommended to install 10.2.5, Enable FIPS here, then once enabled, Upgrade to 10.2.8 to prepare for the Certificate issue coming here in April.&amp;nbsp; Once you're FIPS enabled on a certificate approved image, I have had no issues upgrading further.&amp;nbsp; I also got confirmation that this is a known bug that is being tracked for fixing and affects most (all?) "modern" releases of the PAN-OS image.&lt;/P&gt;
&lt;P&gt;My deployment is now active with FIPS enabled following the provided steps.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 01:33:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/fips-cc-mode-default-user-password-issue/m-p/579548#M116148</guid>
      <dc:creator>kylebrolafski</dc:creator>
      <dc:date>2024-03-07T01:33:17Z</dc:date>
    </item>
  </channel>
</rss>

