Configure a Network Device Collaborative Protection Profile Authorized Administrator

An account for root is always present in a configuration and is not intended for use in normal operation. In the evaluated configuration, the root account is restricted to the initial installation and configuration of the evaluated device.

An NDcPPv3.0e authorized administrator must have all permissions, including the ability to change the device configuration.

To configure an authorized administrator:

  1. Create a login class named security-admin with all permissions.
  2. Configure the hashed algorithm SHA256 or SHA512 for plain-text passwords. SHA512 is the default hashing algorithm.
  3. Commit the changes.
  4. Define your NDcPPv3.0e user authorized administrator.

    or

    To configure public key authentication and keyboard-interactive authentication:

    Note:

    ssh-ed25519 is not supported in FIPS mode although it is shown as a configurable option.

    To delete a configured login credential, use the following command:

    The set commands used to configure the credentials as shown above can be repeated to overwrite the currently configured credentials.

    The Keyboard-Interactive Based authentication for SSH is supported by default and needs no additional configuration apart from a password being configured for the user. Providing multifactor authentication mechanism would require the use of an external AAA server, which is outside the CC scope, as a result of which the keyboard-interactive authentication method works similarly to the password-based method in the evaluated configuration.

  5. Load an SSH key file that was previously generated using ssh-keygen. This command loads RSA (SSH version 2), or ECDSA (SSH version 2).
  6. Set the log-key-changes configuration statement to log when SSH authentication keys are added or removed.
    Note:

    When the log-key-changes configuration statement is enabled and committed (with the commit command in configuration mode), Junos OS logs the changes to the set of authorized SSH keys for each user (including the keys that were added or removed). Junos OS logs the differences since the last time the log-key-changes configuration statement was enabled. If the log-key-changes configuration statement was never enabled, then Junos OS logs all the authorized SSH keys.

  7. Commit the changes.

For details on how to start with shell mode, see Overview for Junos OS Guide.

Note:

The root password should be reset following the change to sha256 / sha512 for the password storage format. This ensures the new password is protected using a sha256 / sha512 hash. To reset the root password, use set system root-authentication plain-text-password password command, and confirm the new password when prompted.