User's Guide Part 1

Table Of Contents
Chapter 3: System planning Security planning
Login(1): Read Only
Administrative(6): System Administrator
NAS Prompt(7): Read Only
If the auth-role and service-type attributes are absent, PTP 700 selects the Read Only role.
The auth-role vendor-specific attribute is defined in Table 64.
Table 64
Definition of auth-role vendor-specific attribute
Field
Length
Value
Notes
Type 1 26 Vendor-specific attribute.
Length 1 12 Overall length of the attribute.
Vendor ID 4 17713 The same IANA code used for the SNMP enterprise
MIB.
Vendor Type 1 1 auth-role
Vendor Length 1 4 Length of the attribute specific part.
Attribute-
Specific
4 0..3 Integer type (32-bit unsigned). Supported values:
invalid-role(0), readonly-role(1), system-admin-role(2),
security-officer-role(3).
Planning for FIPS 140-2 operation
If the link is to operate in FIPS 140-2 secure mode, ensure that the following cryptographic
material is generated using a FIPS-approved cryptographic generator:
Key of Keys
TLS Private Key and Public Certificates
Entropy Input
Wireless Link Encryption Key for AES
Ensure that the web browsers used are enabled for HTTPS/TLS operation using FIPS-approved
cipher specifications.
Ensure that following attributes of user accounts for the web-based management interface
have been configured to match the operator’s network security policy:
Auto Logout Period.
Maximum Number of Login Attempts.
Login Attempt Lockout.
Minimum Password Change Period.
Password Expiry Period.
Webpage Session Control
Ensure that the following are configured:
Password complexity rules reset to best practice values.
User account passwords compliant with the network security policy.
Page 3-58