logo.gif VCR 2220
host: vcr.northwestern.edu

Configuring security settings

To configure security settings, go to Settings > Security.

 

Field Field description
Security settings
Advanced account security mode

Advanced account security mode causes the IP VCR to hash passwords before storing them in the configuration.xml file (see below). Note that hashing user passwords is an irreversible process.

Before you enable advanced account security mode, we recommend that you back up your configuration. The IP VCR gives you the option to do that after you have enabled advanced account security mode.

If you enable advanced account security mode, all current passwords (created when the IP VCR was not in advanced account security mode) will expire and users must change them.

Advanced account security mode is described in greater detail below.

Redirect HTTP requests to HTTPS

Enable this option to have HTTP requests to the IP VCR automatically redirected to HTTPS.

This option is unavailable if either HTTP (Web) or HTTPS (Secure web) access is disabled on the Network > Services page.

Idle web session timeout

The timeout setting for idle web sessions. The user must log in again if the web session expires. The timeout value must be between 1 and 60 minutes. Note that status web pages that auto-refresh will keep a web session active indefinitely. You can configure the IP VCR not to auto-refresh those pages; to do so, go to Settings > User interface .

Serial console settings
Hide log messages on console

The serial console interface displays log messages. If that is considered to be a security weakness in your environment, select this option to hide those messages.

Disable serial input during startup

Select this option for enhanced serial port security.

Require administrator login

Select this option to require an administrator login by anyone attempting to connect to the IP VCR via the console port. If this is not enabled, anyone with physical access to the MCU (or with access to your terminal server) can potentially enter commands on the serial console.

Idle console session timeout

If you have enabled Require administrator login , you can configure a session timeout period. The timeout setting for idle console sessions. The admin must log in again if the console session expires. The timeout value must be between 1 and 60 minutes.

Advanced account security mode

You can configure the IP VCR to use advanced account security mode. Advanced account security mode has the following features:

If you enable advanced security, all current passwords (created when the IP VCR was not in advanced account security mode) will expire and users must change them.

When using Advanced account security mode, we recommend that you rename the default administrator account. This is especially true where the IP VCR is connected to the public internet because security attacks will often use “admin” when attempting to access a device with a public IP address. Even on a secure network, if the default administrator account is “admin”, it is not inconceivable that innocent attempts to log into the IP VCR will cause you to be locked out for 30 minutes.

We recommend that you create several accounts with administrator privileges. This will mean that you will have an account through which you can access the IP VCR even if one administrator account has been locked out.

If there are API applications accessing the IP VCR, we recommend that you create dedicated administrator accounts for each application.

In advanced account security mode, if a user logs in with a correct but expired password the IP VCR asks that user to change the password. If the user chooses not to change it, that user is allowed two more login attempts to change the password before the account gets disabled.

Hashing passwords

In advanced account security mode, the IP VCR will hash passwords before storing them in the configuration.xml file. The configuration.xml file is used for backing up and restoring the configuration of the IP VCR (see Upgrading and backing up the IP VCR). If you do not select to use advanced password security, all user passwords are stored in plain text in the configuration.xml; this might be a security issue. If you select to use advanced password security, they will not be stored anywhere on the IP VCR in plain text; instead the passwords will be stored as hash sums. Note that hashing user passwords is an irreversible process.

Password format

In advanced account security mode, passwords must have:

In advanced account security mode, a new password must be different to the previous 10 passwords that have been used with an account.

Expiring passwords

In advanced account security mode, if a user logs in with a correct but expired password the IP VCR asks that user to change the password. If the user chooses not to change it, that user is allowed two more login attempts to change the password before the account gets disabled.

Related topics