JITC Overview
The JITC mode implemented on a FastIron device enforces default behavior for some features to ensure strict JITC certification compliance.
AES-CTR Encryption Mode Support for SSH
The Advanced Encryption Standard - Cipher Block Chaining (AES-CBC) encryption mode for Secure Shell (SSH) is vulnerable to certain plain-text attacks. For enhanced security, the JITC mode uses AES-CTR (Counter) encryption mode for SSH instead of AES-CBC mode.
In the JITC mode, by default, the AES-CBC encryption mode for SSH is disabled and
the AES-CTR (Counter) encryption mode is enabled. The
ip ssh encryption disable-aes-cbc command that disables the AES-CBC mode can be seen in the running configuration.
The encryption algorithms such as aes256-ctr, aes192-ctr, or aes128-ctr are enabled
and the CBC mode ciphers are removed.
The AES-CBC mode can be re-enabled by issuing the
no ip ssh encryption disable-aes-cbc command, which will bring back the pre-existing CBC ciphers (aes256-cbc, aes192-cbc,
aes128-cbc, and 3des-cbc) along with the CTR ciphers.
SHA1 Authentication Support for NTP
In the JITC mode, the symmetric key scheme supported for cryptographic authentication
of messages uses the SHA1 keyed hash algorithm instead of the MD5 authentication scheme.
The MD5 authentication for Network Time Protocol (NTP) is disabled by default in the
JITC mode and the
disable authentication md5 command can be seen in the running configuration. Only the SHA1 authentication scheme
is available to define the authentication key for NTP in the JITC mode. SHA1 authentication
must be enabled manually using the
authentication-key key-id command. In the JITC mode, only the SHA1 option is available.
The MD5 authentication scheme can be re-enabled by issuing the
no disable authentication md5 command. By doing so, the default JITC mode behavior is overridden.
IPv6 ACL for SNMPv3 Group
As part of the JITC requirement, from 08.0.20a release onwards, the IPv6 access list is supported for the SNMPv3 group, and the incoming SNMP packets can be filtered based on the IPv6 ACL attached to the group.
For more information, refer to the "Defining an SNMP Group and Specifying which View is Notified of Traps" section in the SNMP chapter of the RUCKUS FastIron Management Configuration Guide.