How Korean Common Criteria Works
To configure a device to operate in Korean CC mode, download the appropriate software version onto the management station while connected to the device's console port using a serial cable.
A software build specifically supporting
Korean CC is provided, which includes the fips enable common-criteria
command and other essential requirements for Korean CC, all of which are activated
by
default upon bootup. To enable Korean CC mode of operation, you must load this specific
build at least once. There are no alternative methods to enable Korean CC on the device.
Once the software is installed, which includes the signature and the UFI images, the device will be in Korean CC mode of operation. It is important to ensure that both the signature and UFI files are loaded correctly. Failure to copy the signature file may result in image validation errors, and the device cannot be recovered. To recover the device, contact the RUCKUS Support team.
While the device is booting, the following actions are performed per the default security policy:
- Disable Telnet
- Disable TFTP (but TFTP can be
re-enabled using the
fips policy allow tftp-accesscommand) - Enable SCP access
- Disable the HTTPS server and client
- Disable HTTP server and client
- Set login recovery time to the default value of 3 minutes (180 seconds)
- Disable the user account after three invalid or wrong password attempts (the user may try again after the login recovery timer has expired [3 minutes])
- Disable SNMP access to critical security parameter (CSP) MIB objects (SNMP v2 configuration is blocked in the configuration)
- The UDP logging feature is not
enabled by default. You can enable it using the
fips policy allow udp-loggingcommand. - Non-TLS UDP RADIUS server is not enabled by default. You can enable it using the
fips policy allow udp-radius-servercommand. - Non-TLS TACACS+ feature is not enabled by default. You can enable it using the
fips policy allow common-criteria aaa-server-anycommand. - Disable the encrypted Syslog Server
While the device is booting, several tests are performed to ensure compliance with Korean CC standards:
- Firmware Integrity Tests
- Package Checksum Verification
- uboot Checksum Validation
- Power-On Self Tests (POSTs)
- Known Answer Tests (KATs)
After these tests are successfully completed, and upon loading the correct signature file and image, the device reloads and becomes operational in Korean CC mode of operation. SNMPv3 user configurations are not included in the startup configuration.