Information
All AOS-CX switch firmware is signed by HPE at the time the firmware is created. The firmware signature is verified at the time of download and verified at every boot. The public keys used to verify the firmware is stored within the bootloader and firmware. The firmware is digitally signed with RSA-3072and SHA-256. If the switch firmware validation fails at boot, the switch will fail to boot with one of the following errormessages and drop the user into the ServiceOS login screen:
Error: Signature verification failed
Error: Signature not found
Error: Invalid signature
Firmware is validated when downloaded to the device and on every boot. A manual check can be done on the firmware images at any time.
Solution
Firmware without a valid signature will not boot. A new firmware image with a valid signature should be copied onto the device.
Impact:
Firmware that fails validation will not be downloaded to the device. Firmware already on the device that fails validation will fail to boot.
Item Details
Category: CONFIGURATION MANAGEMENT, RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY
References: 800-53|CM-7(2), 800-53|CM-8, 800-53|CM-8(1), 800-53|CM-8(3), 800-53|CM-10, 800-53|CM-11, 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|2.6, CSCv7|3.4, CSCv7|3.5, CSCv7|11.4
Control ID: 6e729dc5dd1d4f0a6b0c9e3c55091f63992b1d4b189daabc5532e737e6e38773