Understanding Roles and Services for Junos OS in Common Criteria and FIPS
The Security Administrator is associated with the defined login class “security-admin”, which has the necessary permission set to allow the administrator to perform all tasks necessary to manage the Junos OS. Administrative users (Security Administrator) must provide unique identification and authentication data before any administrative access to the system is granted.
Security Administrator roles and responsibilities are as follows:
- Ability to configure the access banner
- Ability to configure the remote session inactivity time before session termination
- Ability to update the TOE, and to verify the updates using digital signature capability prior to installing those updates
- Ability to start and stop services
- Ability to configure local audit behaviour (changes to storage locations for audit; changes to behaviour when local audit storage space is full, changes to local audit storage size)
- Ability to modify the behaviour of the transmission of audit data to an external IT entity
- Ability to manage the cryptographic keys
- Ability to configure the cryptographic functionality
- Ability to configure thresholds for SSH rekeying
- Ability to re-enable an Administrator account
- Ability to configure the local session inactivity time before session termination or locking
- Ability to configure the authentication failure parameters for FIA_AFL.1
- Ability to set the time which is used for time-stamps
- Ability to configure NTP
- Ability to administer the TOE locally
- Ability to manage the trusted public keys database.
The Juniper Networks Junos operating system (Junos OS) running in non-FIPS mode allows a wide range of capabilities for users, and authentication is identity-based.
Security Administrator performs all FIPS-mode-related configuration tasks and issue all statements and commands for Junos OS in FIPS mode.
Security Administrator Role and Responsibilities
The Security Administrator is the person responsible for enabling, configuring, monitoring, and maintaining Junos OS in FIPS mode on a device. The Security Administrator securely installs Junos OS on the device, enables FIPS mode, establishes keys and passwords for other users and software modules, and initializes the device before network connection.
We recommend that the Security Administrator administer the system in a secure manner by keeping passwords secure and checking audit files.
The permissions that distinguish the Security Administrator from other FIPS users are secret, security, maintenance, and control. For FIPS compliance, assign the Security Administrator to a login class that contains all of these permissions. A user with the Junos OS maintenance permission can read files containing critical security parameters (CSPs).
Among the tasks related to Junos OS in FIPS mode, the Security Administrator is expected to:
Set the initial root password. The length of the password should be at least 10 characters.
Reset user passwords with FIPS-approved algorithms.
Examine log and audit files for events of interest.
Erase user-generated files, keys, and data by zeroizing the device.
FIPS User Role and Responsibilities
All FIPS users, including the Security Administrator, can view the configuration. Only the user assigned as the Security Administrator can modify the configuration.
FIPS user can view status output but cannot reboot or zeroize the device.
What Is Expected of All FIPS Users
All FIPS users, including the Security Administrator, must observe security guidelines at all times.
All FIPS users must:
Keep all passwords confidential.
Store devices and documentation in a secure area.
Deploy devices in secure areas.
Check audit files periodically.
Conform to all other FIPS 140-3 security rules.
Follow these guidelines:
Users are trusted.
Users abide by all security guidelines.
Users do not deliberately compromise security.
Users behave responsibly at all times.