24-7
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 24 System Maintenance
Change the Default Password of the Administrator Account
Note
If you see Chinese or other unfamiliar characters in the resulting text file, please use Microsoft Internet
Explorer to view the file and verify that the Western European ISO or Western European Windows
encoding value is selected (View > Encoding). The “»” sign appears correctly as a separator when a
compatible encoding is selected.
Change the Default Password of the Administrator Account
Good security practices require that you change the default password. We recommend using strong
passwords for the MARS Appliance appliances.
Login names and passwords:
•
can be alphanumeric characters
•
are case sensitive
•
can contain special characters (!, @, #, etc.)
•
cannot
contain single or double quotes (‘or “)
Login names can contain up to 20 characters. Passwords can contain up to 64 characters.
To change the default password and setup administrator notification, follow these steps:
Step 1
Click the
Management
>
User Management
tab.
Step 2
Check the box next to Administrator, and click
Edit
.
Step 3
Enter the new Administrator password and the Administrator e-mail address.
Step 4
Click
Submit
.
Understanding Certificate and Fingerprint Validation and
Management
Many reporting devices use certificates or fingerprints to enable secure communications over SSL or
SSH respectively. Beginning in 4.2.3, MARS performs a strict check of the certificate or fingerprint of
the device or server to which it is attempting to connect.
Note
Certificate validation does not follow the convention of presenting the client with a list of certificate
authorities and using the selected one to validate individual certificates. Instead, the MARS Appliance
compares the certificate presented by the reporting device with a previously stored instance of the
certificate. If the two match, the presented certificate is considered valid. This approach allows MARS
to validate certificates without knowledge of revocation lists and to operate in a network without an
Internet connection.