Security: Secure Sensitive Data Management
Menu CLI and Password Recovery
376
Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4
19
Menu CLI and Password Recovery
The Menu CLI interface is only allowed to users if their read permissions are Both or Plaintext
Only. Other users are rejected. Sensitive data in the Menu CLI is always displayed as plaintext.
Password recovery is currently activated from the boot menu and allows the user to log on to
the terminal without authentication. If SSD is supported, this option is only permitted if the
local passphrase is identical to the default passphrase. If a device is configured with a user-
defined passphrase, the user is unable to activate password recovery.
Configuring SSD
The SSD feature is configured in the following pages:
•
SSD properties are set in the
page.
•
SSD rules are defined in the
page.
SSD Properties
Only users with SSD read permission of Plaintext-only or Both are allowed to set SSD
properties.
TFTP Insecure
SCP
SCP (Secure Copy)
Secure
HTTP based file transfer
Insecure
HTTPS-based file transfer
HTTPS based file transfer
Secure
Management Channel
SSD Management
Channel Type
Parallel Secured Management
Channel