Configuration Enhancements for Local User Accounts
Although basic local user accounts can be set up without many rules, most companies now require more security for user accounts. The following enhancements are disabled by default:
- Enhanced user password combination requirements
- User password masking
- Quarterly updates of user passwords
- Storage of up to 15 previously configured passwords for each user
- Configuration of the number of login attempts before users are locked out
- Password expiration
Password Combination Rules
When strict password enforcement is enabled on a RUCKUS device, you must enter a minimum of eight characters containing the following combinations when you create and enable a user password:
- At least two upper case characters
- At least two lower case characters
- At least two numeric characters
- At least two special characters
The following security upgrades apply to strict password enforcement feature:
- Passwords must not share four or more concurrent characters with any other password configured on the router. If the user tries to create a password with four or more concurrent characters, the following error message is returned.
Error - The substring str within the password has been used earlier, please choose a different password.
For example, the previous password was Ma!i4aYa&. The user cannot use any of the following as their new password:
- Ma!imai$D because the letters in "Mail" were used consecutively in the previous password
- &3B9aYa& because the letters in "aYa&" were used consecutively in the previous password
- i4aYEv#8 because the letters in "i4aY" were used consecutively in the previous password.
If the user tries to configure a password that was previously used, the new password configuration fails, and the following message is displayed.
This password was used earlier for same or different user, please choose a different password.
Password Masking
By default, when you use the CLI to create a user password, the password displays on the console as you type it. For enhanced security, you can configure the RUCKUS device to mask the password characters entered at the CLI. When password masking is enabled, the CLI displays asterisks (*) on the console instead of the password characters entered.
The following example shows the CLI behavior when a username and password are configured with password masking enabled.
device# configure terminal device(config)# username kelly password Enter Password: ********
Password Aging
For enhanced security, password aging enforces quarterly updates of all user passwords. After 90 days, the CLI automatically prompts users to change their passwords when they attempt to sign on.
When password aging is enabled, the software records the system time that each user
password was configured or last changed. The time displays in the output of the
show running-config command, indicated by set-time.
device# show running-config Current configuration: .... username waldo password ..... username raveen set-time 2086038248 ....
The password aging feature uses the NTP server clock to record the set-time. If the
network does not have an NTP server, the set-time appears as "set-time 0" in the output
of the
show running-config command.
A username set-time configuration is removed in the following cases:
When a username set-time configuration is removed, it no longer appears in the
show running-config output.
Password History
By default, a RUCKUS device stores the last five user passwords for each user. When changing a user password, the user cannot use any of the five previously configured passwords. For security purposes, you can configure the device to store up to 15 passwords for each user, so that users do not use the same password multiple times. The default number of stored passwords is 5. If a user attempts to use a stored password, the system prompts the user to choose a different password.
User Login Attempts
If a user fails to log in to the device after a configured number of login attempts (by default, 3 attempts), the user is locked out. You can configure the maximum number of invalid login attempts a user can make before being locked out. The maximum number of invalid login attempts can be from 1 through 10.
The user account can be configured to automatically re-enable the disabled users by specifying a recovery time (by default, 3 minutes), after which the locked-out user accounts are re-enabled automatically. The configured recovery time is applicable for all user accounts and can be configured in the range of 3 through 60 minutes.
If the login-recovery-time option is not configured, manual intervention is required to re-enable the locked user account. To manually re-enable a user account, perform one of the following actions:
Password Expiration
You can set a user password to expire. Once a password expires, the administrator must assign a new password to the user. The days before expiration can be set as a value from 1 through 365. The default is 90 days.
The expiry details of the user password can be viewed using the
show user command.
device# show user Username Password Encrypt Priv Status Expire Time ================================================================================ sandy $1$Gz...uX/$wQ44fVGtsqbKWkQknzAZ6. enabled 0 enabled 20 days