<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Key generation operation failed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/key-generation-operation-failed/m-p/19382#M14154</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only certs I have are the localhost self signed for the web gui and the HA certs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Thompson&lt;/P&gt;&lt;P&gt;National Labor Relations Board&lt;/P&gt;&lt;P&gt;202-273-4097&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 May 2012 19:54:44 GMT</pubDate>
    <dc:creator>LCMember4715</dc:creator>
    <dc:date>2012-05-21T19:54:44Z</dc:date>
    <item>
      <title>Key generation operation failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/key-generation-operation-failed/m-p/19380#M14152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;enabled FIPS over the weekend now I get the message &lt;SPAN style="font-size: 12.0pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;: Key generation operation failed - RSA when commiting&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 19:22:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/key-generation-operation-failed/m-p/19380#M14152</guid>
      <dc:creator>LCMember4715</dc:creator>
      <dc:date>2012-05-21T19:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Key generation operation failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/key-generation-operation-failed/m-p/19381#M14153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you use any selfsigned or imported certificates before you enabled FIPS-mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since according to the manual (PAN-OS_4.1_CLI_Reference_Guide.pdf, page 305):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;Appendix C&lt;BR /&gt;Federal Information Processing Standards Support&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure the firewall to support the Federal Information Processing Standards 140-2 (FIPS 140-2), which are used by civilian U.S. government agencies and government contractors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To enable FIPS mode on a software version that supports FIPS, boot the firewall into maintenance mode and then select Set FIPS Mode from the main menu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instructions on booting to maintenance mode, refer to the PAN-OS Command Line Interface Reference Guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When FIPS is enabled, the following apply:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• To log into the firewall, the browser must be TLS 1.0 compatible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• All passwords on the firewall must be at least six characters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• Accounts are locked after the number of failed attempts that is configured on the Device &amp;gt; Setup &amp;gt; Management page. If the firewall is not in FIPS mode, it can be configured so that it never locks out; however in FIPS mode, and lockout time is required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• The firewall automatically determines the appropriate level of self-testing and enforces the appropriate level of strength in encryption algorithms and cipher suites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• Non-FIPS approved algorithms are not decrypted and are thus ignored during decryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• When configuring IPSec, a subset of the normally available cipher suites is available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• Self-generated and imported certificates must contain public keys that are 2048 bits (or more).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• SSH key-based authentication must use RSA public keys that are 2048 bits or higher.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• The serial port is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• Telnet, TFTP, and HTTP management connections are unavailable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• Surf control is not supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• High availability (HA) encryption is required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• PAP authentication is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;• Kerberos support is disabled.&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 19:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/key-generation-operation-failed/m-p/19381#M14153</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-21T19:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Key generation operation failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/key-generation-operation-failed/m-p/19382#M14154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only certs I have are the localhost self signed for the web gui and the HA certs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Thompson&lt;/P&gt;&lt;P&gt;National Labor Relations Board&lt;/P&gt;&lt;P&gt;202-273-4097&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 19:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/key-generation-operation-failed/m-p/19382#M14154</guid>
      <dc:creator>LCMember4715</dc:creator>
      <dc:date>2012-05-21T19:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Key generation operation failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/key-generation-operation-failed/m-p/19383#M14155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What if you extract running-config.xml through GUI and with a texteditor search for "rsa" in that file - any thints here (for example ssh keys or such)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 20:09:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/key-generation-operation-failed/m-p/19383#M14155</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-21T20:09:30Z</dc:date>
    </item>
  </channel>
</rss>

