Understanding Roles and Services for Junos OS in Common Criteria and FIPS
In FIPS mode, a role refers to the specific functions or responsibilities that users have when interacting with the cryptographic module. The primary roles in FIPS mode include:
- Security Administrator
FIPS user
The Security Administrator and FIPS users perform all configuration tasks for Junos OS in FIPS mode and issue all statements and commands. Security Administrator and FIPS user configurations must meet the requirements for Junos OS in FIPS mode.
The Junos OS in non-FIPS mode provides a wide range of capabilities for users and supports identity-based authentication.
Security Administrator Role and Responsibilities
The Security Administrator role is associated with the defined login class
security-admin. A Security Administrator has the
necessary permissions to perform all tasks to manage Junos OS. The system
requires administrative users (Security Administrator) to provide unique
identification and authentication data before granting any administrative
access.
We recommend that the Security Administrator follows security measures such as keeping passwords secure and checking audit files.
The permissions that distinguish the Security Administrator from other FIPS
users are secret, security,
maintenance, and control. The
Security Administrator has the login class that contains all these
permissions.
The Security Administrator role is crucial for maintaining the integrity and security of the system, especially in environments that require adherence to stringent federal security standards.
The Security Administrator has the following responsibilities:
Administer locally and remotely.
Create, modify, and delete user accounts, including configuration of authentication failure parameters.
Re-enable a user account.
Configure and maintain cryptographic elements related to the establishment of secure connections to and from the evaluated product.
Reset user passwords with FIPS-approved algorithms.
Examine log and audit files for events of interest.
Erase user-generated files, keys, and data by zeroizing the device.
What Is Expected of All FIPS Users
All FIPS users, including the Security Administrator, must observe security guidelines at all times.
All FIPS users must:
Keep all passwords confidential.
Store devices and documentation in a secure area.
Deploy devices in secure areas.
Check audit files periodically.
Conform to all other FIPS 140-3 security rules.
Follow these guidelines:
Users are trusted.
Users abide by all security guidelines.
Users do not deliberately compromise security.
Users behave responsibly at all times.