logo.gif MCU 4505
host: MCU

Configuring security settings

To configure security settings, go to Settings > Security.

 

Field Field description
User authentication settings
Advanced account security mode

Advanced account security mode causes the MCU to hash passwords before storing them in the configuration.xml file (see below). Note that hashing user passwords is an irreversible process.

Before you enable advanced account security mode, we recommend that you back up your configuration. The MCU gives you the option to do that after you have enabled Advanced account security mode.

If you enable advanced account security mode, all current passwords (created when the MCU was not in advanced account security mode) will expire and users must change them.

Advanced account security mode is described in greater detail below.

Redirect HTTP requests to HTTPS

Enable this option to have HTTP requests to the MCU automatically redirected to HTTPS.

This option is unavailable if either HTTP (Web) or HTTPS (Secure web) access is disabled on the Network > Services page.

Idle web session timeout

The timeout setting for idle web sessions. The user must log in again if the web sessions expires. The timeout value must be between 1 and 60 minutes. Note that status web pages that auto-refresh will keep a web session active indefinitely. You can configure the MCU not to auto-refresh those pages; to do so, go to Settings > User interface .

Serial console settings
Hide log messages on console

The serial console interface displays log messages. If that is considered to be a security weakness in your environment, select this option to hide those messages.

Disable serial input during startup

Select this option for enhanced serial port security.

Require administrator login

Select this option to require an administrator login by anyone attempting to connect to the MCU via the console port. If this is not enabled, anyone with physical access to the MCU (or with access to your terminal server) can potentially enter commands on the serial console.

Idle console session timout

If you have enabled Require administrator login , you can configure a session timeout period. The timeout setting for idle console sessions. The admin must log in again if the console sessions expires. The timeout value must be between 1 and 60 minutes.

Advanced account security mode

You can configure the MCU to use advanced account security mode. Advanced account security mode has the following features:

If you enable advanced security, all current passwords (created when the MCU was not in advanced account security mode) will expire and users must change them.

When using Advanced account security mode, we recommend that you rename the default administrator account. This is especially true where the MCU is connected to the public internet because security attacks will often use “admin” when attempting to access a device with a public IP address. Even on a secure network, if the default administrator account is “admin”, it is not inconceivable that innocent attempts to log into the MCU will cause you to be locked out for 30 minutes.

We recommend that you create several accounts with administrator privileges. This will mean that you will have an account through which you can access the MCU even if one administrator account has been locked out.

If there are applications accessing the MCU, for example TMS, Conference Director, or any other API application, we recommend that you create dedicated administrator accounts for each application.

In advanced account security mode, if a user logs in with a correct but expired password the MCU asks that user to change the password. If the user chooses not to change it, that user is allowed two more login attempts to change the password before the account gets disabled.

Hashing passwords

In advanced account security mode, the MCU will hash passwords before storing them in the configuration.xml file. The configuration.xml file is used for backing up and restoring the configuration of the MCU (see Upgrading and backing up the MCU). If you do not select to use advanced pasword security, all user passwords are stored in plain text in the configuration.xml; this might be a security issue. If you select to use advanced pasword security, they will not be stored anywhere on the MCU in plain text; instead the passwords will be stored as hash sums. Note that hashing user passwords is an irreversible process.

Password format

In advanced account security mode, passwords must have:

In advanced account security mode, a new password must be different to the previous 10 passwords that have been used with an account.

Expiring passwords

In advanced account security mode, if a user logs in with a correct but expired password the MCU asks that user to change the password. If the user chooses not to change it, that user is allowed two more login attempts to change the password before the account gets disabled.

Related topics