Chapter 3: System planning
Security planning
Page 3-56
Security planning
This section describes how to plan for PTP 670 links to operate in secure mode.
Planning for SNTP operation
Note
PTP 670 does not have a battery-powered clock, so the set time is lost each time the
ODU is powered down. To avoid the need to manually set the time after each
reboot, use SNTP server synchronization.
Before starting to configure Simple Network Time Protocol (SNTP):
•
Identify the time zone and daylight saving requirements that apply to the system.
•
If SNTP server synchronization is required, identify the details of one or two SNTP servers:
IP address, port number and server key.
•
Decide whether or not to authenticate received NTP messages using an MD5 signature.
Using the Security Wizard
Basic wireless encryption can be configured without using the Security Wizard, by using only
the System Configuration page and optionally the Authorization Control page. For other
security features, use the Security Wizard.
Plan to use the Security Wizard for the following:
•
To install optional user-supplied device certificates for TLS-RSA. User-supplied device
certificates provide enhanced security for TLS-RSA.
•
To configure the Key of Keys. The Key of Keys is used to encrypt non-volatile Critical
Security Parameters for storage in the ODU. The Key of Keys is erased by the Zeroize CSPs
action, meaning that stored CSPs cannot later be accessed, even by an attacker with
internal access to the ODU memory.
•
To configure Entropy. Entropy is an externally-generated random number used as a seed in
many of the cryptographic methods implemented within the ODU. Generate Entropy in an
approved random number generator and install in the ODU to enhance security in wireless
encryption and HTTPS/TLS.
•
To configure an optional banner providing warnings and notices to be read by the user
before logging in to the ODU.