Security: Secure Sensitive Data Management
Configuration Files
Cisco Small Business 200 Series Smart Switch Administration Guide
296
19
•
A text-based configuration that does not include an SSD indicator is
considered not to contain sensitive data.
•
The SSD indicator is used to enforce SSD read permissions on text-based
configuration files, but is ignored when copying the configuration files to the
Running or Startup Configuration file.
The SSD indicator in a file is set according to the user’s instruction, during copy, to
include encrypted, plaintext or exclude sensitive data from a file.
SSD Control Block
When a device creates a text-based configuration file from its Startup or Running
Configuration file, it inserts an SSD control block into the file if a user requests the
file is to include sensitive data. The SSD control block, which is protected from
tampering, contains SSD rules and SSD properties of the device creating the file.
A SSD control block starts and ends with "ssd-control-start" and "ssd-control-end"
respectively.
Startup Configuration File
The device currently supports copying from the Running, Backup, Mirror, and
Remote Configuration files to a Startup Configuration file. The configurations in the
Startup Configuration are effective and become the Running Configuration after
reboot. A user can retrieve the sensitive data encrypted or in plaintext from a
startup configuration file, subject to the SSD read permission and the current SSD
read mode of the management session.
Read access of sensitive data in the startup configuration in any forms is excluded
if the passphrase in the Startup Configuration file and the local passphrase are
different.
SSD adds the following rules when copying the Backup, Mirror, and Remote
Configuration files to the Startup Configuration file:
•
After a device is reset to factory default, all of its configurations, including
the SSD rules and properties are reset to default.
•
If a source configuration file contains encrypted sensitive data, but is
missing an SSD control block, the device rejects the source file and the
copy fails.
•
If there is no SSD control block in the source configuration file, the SSD
configuration in the Startup Configuration file is reset to default.
Содержание Small Business 200
Страница 1: ...Cisco Small Business 200 Series Smart Switch Administration Guide Release 1 3 ADMINISTRATION GUIDE ...
Страница 13: ...Cisco Small Business 200 Series Smart Switch Administration Guide 13 Contents ...
Страница 24: ...Getting Started Window Navigation 11 Cisco Small Business 200 Series Smart Switch Administration Guide 1 ...
Страница 38: ...Status and Statistics Managing RMON 25 Cisco Small Business 200 Series Smart Switch Administration Guide 2 ...
Страница 124: ...Administration Discovery Configuring CDP 111 Cisco Small Business 200 Series Smart Switch Administration Guide 8 ...
Страница 144: ...Port Management Configuring Green Ethernet 131 Cisco Small Business 200 Series Smart Switch Administration Guide 9 ...
Страница 182: ...Port Management PoE Configuring PoE Settings 169 Cisco Small Business 200 Series Smart Switch Administration Guide 11 ...
Страница 206: ...VLAN Management Voice VLAN 193 Cisco Small Business 200 Series Smart Switch Administration Guide 12 ...
Страница 288: ...Security Denial of Service Prevention 275 Cisco Small Business 200 Series Smart Switch Administration Guide 17 ...