Cybersecurity

The Cybersecurity feature enhances the existing password security feature, ensuring compliance with stricter password configuration and usage rules that adhere to higher security standards.

7.0 patch 2
However, the factory-provided password is exempt from these compliance requirements because it is used only once during the initial login.

Requirements

This feature has no special hardware or software requirements for feature enablement or usage.

Prerequisites

This feature has no prerequisites to feature enablement or usage.

When setting up an AP for the first time, use these default credentials:

  • User: super
  • Password: sp-admin

For a factory reset, log in through the AP UI or AP CLI using the default credentials and change the password to comply with the following requirements:

  • Blank Spaces: The password must not contain any blank spaces.
  • Character Complexity: The password must be a minimum of 8 characters in length and include at least one lowercase letter, one uppercase letter, one number, and one special character.
  • Special Characters Allowed: You can use the following special characters: ~!@#$%^&*()-=_+[]{}|;':",./<>?
      Note:
    • The password must not begin with the special character “~”
    • The password cannot contain the special characters $ and ( consecutively
    • Password for SNMP configuration must not include special characters $;&()|<>'`\
  • Device-Specific Credentials: Each device must have a unique password. Avoid using the initial factory setting credentials across all devices to prevent unauthorized access.

Remember that all passwords used to log in to an AP terminal or AP UI must comply with these requirements. Once you set a new password, use it for subsequent logins. The default password “sp-admin” is only for changing the password and cannot be used to configure or monitor the AP.

Considerations

  • Resetting Factory Settings: When an AP is reset to its initial factory settings, also reset any passwords indicated on the product label or equipment enclosure.

Limitations

The controller upgrade process does not include validation of the current passwords, for APs in existing zones, against the cybersecurity requirements.

Meaning, after controller upgrade, the current passwords for the zone and APs will be retained until further user action prompts validation:

AP Password Validation:

    • Initially set AP passwords are stored as hashes, making the actual password unretrievable from the stored value.
    • Updates to AP password validation rules will not affect existing AP passwords due to the hash storage.

After the first login using the sp-admin user name, the AP will prompt the user to change the default password. Use the new password for subsequent logins. This behavior is already present in AP solo software and is now being used in the controller profile.

Best Practices

This feature has no special recommendations for feature enablement or usage.