Entering Common Criteria Operational Mode
When the device is in Common Criteria Administrative mode, perform the following steps
to place the device into Common Criteria Operational mode.
- Configure the local user accounts as secure and delete non-secure user accounts. A local user account is secure when it has a password with characters from three or more character classes. These character classes are uppercase, lowercase, numeric, and ASCII non-alphanumeric characters.
- Configure secure logging by setting up the encrypted syslog server. For details, refer to Encrypted syslog servers in Common Criteria mode.
- Use the
enable aaa consolecommand to ensure user authentication during the next reload. This also requires that you have enabled AAA authentication with theaaa authentication login defaultcommand. - Use
logging cli-commandto allow you to log all syntactically valid CLI commands from each user session into the system log. - Configure a motd banner using the
banner motdcommand. Refer to CLI banner configuration for more information. - Use the
write memorycommand to save the configuration. - Use the
reloadcommand to reload the device.
On successful completion of these steps, the device will be in Common Criteria Operational mode.
Note: FIPS self-tests are executed as part of device bootup. If any of the self-tests fails,
the device reloads automatically. If there are continuous reloads, please contact
Ruckus technical support.