Chapter5SECURITYREQUIREMENTS
FDP_IFF.1.5TheTSFshallexplicitlydenyaninformationowbasedonthefollowing
rules:[none].
5.1.2.10FDP_UIT.1Dataexchangeintegrity
FDP_UIT.1.1TheTSFshallenforce
the[assignment:accesscontrolSFP(s)and/or
informationowcontrolSFP(s)]totransmitandreceiveroutingdatato/fromtrustedrouters
inamannerprotectedfrommodication,insertionandreplayerrors
ApplicationNote:inordertoprotecttheroutingdatafrommodication,insertionand
replayerror,OnlyRIPv2,OSPFv2mode2,IS-ISandBGPv4routingprotocolsareallowed
toensuretheintegrity.Thereisnoneedtoprotectthecondentialityoftheroutingdata.
5.1.2.11FIA_AFL.1Authenticationfailurehandling
FIA_AFL.1.1TheTSFshalldetectwhen[anadministratorcongurablepositive
integer(withinarangeofvalues3–16)]unsuccessfulauthenticationattemptsoccur
relatedtoanyclaimedadministratorIDattemptingtoauthenticatetotheTOE.
FIA_AFL.1.2Whenthedenednumberofunsuccessfulauthenticationattemptshas
been[met],theTSFshall[attheoptionoftheAdministratorpreventtheadministrators
excepttheadministratorfromperformingactivitiesthatrequireauthenticationuntilan
actionistakenbytheAdministrator,oruntilanAdministratordenedtimeperiod(withina
rangeofvalues1-1440minutes)haselapsed].
5.1.2.12FIA_SOS.1Verificationofsecrets
FIA_SOS.1.1TheTSFshallprovideamechanismtoverifythatsecretsmeet:
1.aminimumlength(characters)default6andwithinarangeof3-32;
2.Complexityrequirements:[numeric][special-character][mixed-case]
a.i:atleastone(1)numericcharactermustbepresentinthepassword;and
b.ii)atleastone(1)specialcharactermustbepresentinthepassword.Special
charactersinclude:~!@#$%^&*()_+|{}:”<>?`-=\[];’
c.iii)atleastone(1)upperandone(1)lowercasecharacter
3.Anadministratordenednumberofdaysanadministratorpasswordisvalidbefore
theadministratormustchangetheirpassword.Thisparametershallbeusedtoforce
theadministratortochangethepasswordattheconguredinterval.Themaximum
numberofdaysthepasswordisvalidshallbedenablewithinarangeofvaluesof15
–365.
4.Eithertheadministratormustchangehispasswordattherstlogin,orthe
administratorisnotforcedtochangehispasswordattherstlogin,asconguredby
theadministrator]
ApplicationNote:theTOEcannotenforcethisSFRwhenperformingremote
authenticationwithRADIUS/TACACS+server.
5-7
SJ-20110815105844-030|2011/08/19(R1.6)ZTECORPORATION