Configuration Enhancements for Local User Accounts

Advanced features are available when configuring users and their passwords.

Although basic local user accounts can be set up without many rules, most companies now require more security for user accounts. The following enhancements are disabled by default:

  • Enhanced user password combination requirements
  • User password masking
  • Quarterly updates of user passwords
  • Storage of up to 15 previously configured passwords for each user
  • Configuration of the number of login attempts before users are locked out
  • Password expiration

Password Combination Rules

When strict password enforcement is enabled on a RUCKUS device, you must enter a minimum of eight characters containing the following combinations when you create and enable a user password:

  • At least two upper case characters
  • At least two lower case characters
  • At least two numeric characters
  • At least two special characters
Note: Password minimum and combination requirements are strictly enforced.

The following security upgrades apply to strict password enforcement feature:

  • Passwords must not share four or more concurrent characters with any other password configured on the router. If the user tries to create a password with four or more concurrent characters, the following error message is returned.
Error - The substring str within the password has been used earlier, please choose a different password.

For example, the previous password was Ma!i4aYa&. The user cannot use any of the following as their new password:

  • Ma!imai$D because the letters in "Mail" were used consecutively in the previous password
  • &3B9aYa& because the letters in "aYa&" were used consecutively in the previous password
  • i4aYEv#8 because the letters in "i4aY" were used consecutively in the previous password.

If the user tries to configure a password that was previously used, the new password configuration fails, and the following message is displayed.

This password was used earlier for same or different user, please choose a different password. 

Password Masking

By default, when you use the CLI to create a user password, the password displays on the console as you type it. For enhanced security, you can configure the RUCKUS device to mask the password characters entered at the CLI. When password masking is enabled, the CLI displays asterisks (*) on the console instead of the password characters entered.

The following example shows the CLI behavior when a username and password are configured with password masking enabled.

device# configure terminal
device(config)# username kelly password
Enter Password: ********
Note: When password masking is enabled, press the Enter key before entering the password, and enter the password when prompted.

Password Aging

For enhanced security, password aging enforces quarterly updates of all user passwords. After 90 days, the CLI automatically prompts users to change their passwords when they attempt to sign on.

When password aging is enabled, the software records the system time that each user password was configured or last changed. The time displays in the output of the show running-config command, indicated by set-time.

device# show running-config
Current configuration:
....
username waldo password .....
username raveen set-time 2086038248
....

The password aging feature uses the NTP server clock to record the set-time. If the network does not have an NTP server, the set-time appears as "set-time 0" in the output of the show running-config command.

A username set-time configuration is removed in the following cases:

  • The username and password are deleted from the configuration
  • The username password expires

When a username set-time configuration is removed, it no longer appears in the show running-config output.

Note: If a username does not have an assigned password, the username does not have a set-time configuration.

Password History

By default, a RUCKUS device stores the last five user passwords for each user. When changing a user password, the user cannot use any of the five previously configured passwords. For security purposes, you can configure the device to store up to 15 passwords for each user, so that users do not use the same password multiple times. The default number of stored passwords is 5. If a user attempts to use a stored password, the system prompts the user to choose a different password.

User Login Attempts

If a user fails to log in to the device after a configured number of login attempts (by default, 3 attempts), the user is locked out. You can configure the maximum number of invalid login attempts a user can make before being locked out. The maximum number of invalid login attempts can be from 1 through 10.

The user account can be configured to automatically re-enable the disabled users by specifying a recovery time (by default, 3 minutes), after which the locked-out user accounts are re-enabled automatically. The configured recovery time is applicable for all user accounts and can be configured in the range of 3 through 60 minutes.

If the login-recovery-time option is not configured, manual intervention is required to re-enable the locked user account. To manually re-enable a user account, perform one of the following actions:

  • Reboot the device to re-enable all locked-out users.
  • Enter the usernamename-stringenable command to re-enable a specific user account.

Password Expiration

You can set a user password to expire. Once a password expires, the administrator must assign a new password to the user. The days before expiration can be set as a value from 1 through 365. The default is 90 days.

The expiry details of the user password can be viewed using the show user command.

device# show user
Username  Password                           Encrypt  Priv  Status   Expire Time
================================================================================
sandy     $1$Gz...uX/$wQ44fVGtsqbKWkQknzAZ6. enabled   0    enabled  20 days