3e-525A–3 Wireless Access Point
Chapter 1: Introduction
29000167-001 B
11
Operator Authentication and Management
Authentication mechanisms are used to authenticate an operator ac-
cessing the device and to verify that the operator is authorized to assume
the requested role and perform services within that role. The 3e-525A-3
provides authentication services for all users of the wireless network
when they fi rst attempt to connect. While the user must log in, basic non-
user generated information is allowed to pass on the wireless network
prior to authentication, including the authentication data to and from
the authentication server and audit records passed from the client to the
server. The user is not allowed to specifi cally send any traffi c over the net-
work until successful authentication. Once successfully authenticated, all
actions taken by that user (such as accessing a connected printer) and by
processes created or started by that user, will be associated with that user,
binding the credentials from the user account to all subsequent user pro-
cesses. This ensures that all processes and network traffi c are authorized.
User accounts are defi ned with three basic attributes: username, role
and authentication credentials (i.e. password). A user account can be
defi ned as a normal user or as an administrator. Administrative users can
access the TOE management interface in addition to being able to use the
wireless network, while normal users can only access the wireless net-
work.
The TOE authentication sequence includes a counter for unsuccessful
attempts. When a user or administrator fails to enter the correct creden-
tials after a specifi ed number of attempts (the default is 3), the account
will be locked. The account must then be unlocked by a Crypto Offi cer in
the case of an administrator locking their account). This is active for ac-
cess to the management website.
Access to the management screens for the 3e–525A–3 requires knowl-
edge of the assigned operator ID and Password. The Factory defaults are:
• ID: CryptoOffi cer
• Password: CryptoFIPS
The Crypto Offi cer initially installs and confi gures the 3e–525A–3
after which the password should be changed from the default password.
The ID and Password are case sensitive.
Management
After initial setup, maintenance of the system and programming of
security functions are performed by personnel trained in the procedure
using the embedded web-based management screens.
The next chapter covers the basic procedure for setting up the hard-
ware.