Chapter6TOESUMMARYSPECIFICATION
toaccesstheaudittrailstorage.Thereisnootherinterfacetoaccesstheaudittrail
storage.HowevertheaudittrailstoredintheSNMP/SYSLOGserverisnotprotected
bytheTOE;
TheTSFshalloverwritetheoldeststoredauditrecordsinashwhenthemaximum
allowednumberofloglesreached.
6.1.2Identification&Authentication
Authenticationservicescanbehandledeitherinternally(xedpasswords)orthroughan
externalauthenticationservice,suchasaRADIUSorTACACS+server.Anoperator’s
authenticationparametersmustbevalidbeforeaccessisgrantedtoadministrative
functions.
lFIA_AFL.1Authenticationfailurehandling(console)
Thefollowingisdenedbytheadministrator:(1)Thenumberofunsuccessfullogin
attemptsallowedforthespeciedtime.(2)Thelockoutperiodinminuteswherethe
administratorisnotallowedtologin
Whentheabovesituationissatised,thatadministratorislockedoutfromanyfurtherlogin
withinaspeciedperiodoftime.Howeverwithintheperiodoflockingtime,anadministrator
isallowedtounlockthelockedaccount.
Parametersaremodiablefromtheprovideddefaultvalues:
1.TheTOEdetectswhenunsuccessfulauthenticationattemptsmeetanadministrator
congurablepositiveinteger(withinarangeofvalues3–16)
2.Whenthedenednumberofunsuccessfulauthenticationattemptshasbeenmet,the
TOEwillattheoptionoftheAdministratorpreventactivitiesthatrequireauthentication
untilanactionistakenbytheAdministrator,oruntilanAdministratordenedtime
period(withinarangeofvalues1-1440minutes)haselapsed.
lFIA_SOS.1Vericationofsecrets
Thevericationsofsecretsapplytoallauthenticationmethods:localconsole,andremote
SSHadministration.
Thepasswordneedstosatisfythefollowingrequirements:
1.Aminimumlength(characters)default6andwithinarangeof3-32,
2.atleastoneupperandonelowercasecharacter;
3.atleastonenumericcharactermustbepresentinthepassword;and
4.atleastonespecialcharactermustbepresentinthepassword.Specialcharacters
include:
~!@#$%^&*()_+|{}:”<>?`-=\[];’,./.
HoweverthepasswordsspeciedinRADIUS/TACACS+serverarenotsetupthroughthe
TOE.SothisSFRisonlyenforcedwhenperforminglocalauthentication.
lFIA_UAU.2Userauthenticationbeforeanyaction
TheTOEisconguredtouseRADIUS,TACACS+,andlocal/remoteauthenticationto
validateadministratorsrequestingaccesstothenetwork.Thepasswordauthentication
6-3
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION