During the cryptographic power-on self-test (POST), the appliance invokes the self-test routine provided by the cryptographic library. This self-test performs various checks, including checks that ensure the integrity of the library stored on disk, the proper operation of the cryptographic algorithms, and the soundness of the random number generators. If the self-test fails, then the appliance is forced to restart.
Note
The cryptographic POST is run automatically when the appliance is turned on or restarted, regardless of whether the appliance has been put in FIPS 140-3 or CC-NDcPP compliance. The appliance will not run if the cryptographic POST fails after every restart. If that happens, contact https://www.trellix.com/en-us/support/fe-support.html to report the problem.
A brief informative message is displayed on the console when the FIPS 140-3 cryptographic POST starts:
Running FIPS crypto POST...
If the POST is successful, the following message is displayed:
Done
If the POST fails, the following message appears on the console:
FIPS crypto POST failed. Automatic reboot in progress.
When the boot next fallback-reboot enable command is enabled, a failure in running the active compliance image might result in the appliance running the alternate image instead. If the alternate image is not a compliant image, the appliance will not be compliant. To ensure compliance, make certain both the current and alternate images meet the following release criteria:
FIPS compliance: Use release 9.0 or higher, until September 21, 2026.
NDcPP compliance: Use release 10.0 or higher.