Admin Security APC License
The Admin Security and Admin Security ACP licenses both work to increase the security of the Oracle Communications Session Border Controller (SBC). If a device already has an Admin Security license installed, you can add an Admin Security ACP license later if you need to reopen access to ACP ports. Both licenses may co-exist on a single device, or either license may be on the device alone. An Admin Security ACP license performs the same functions as an Admin Security license, but also enhances password strength requirements and allows access to the ACP (Acme Control Protocol) ports blocked by an Admin Security license.
As with any other license, an activate-config command must be executed after license installation for all changes to take effect. Certain ACLI aspects, such as login and password change prompts, change immediately after installation of the Admin Security license.
Note:
Once the Admin Security or the Admin Security with ACP entitlement is provisioned, it can not be removed from the system in the field; your chassis must be returned to Oracle for replacement.
Note:
The Admin Security or the Admin Security ACP feature sets are not intended for all customer use. Consult your Oracle representative to understand the ramifications of enabling these features.License Requirements
Support for enhanced password strength requires two licenses: the previously existing Admin Security license and the newly available Admin Security ACP license.
Password Policy
The Admin Security feature set supports the creation of password policies that enhance the authentication process by imposing requirements for:
- password length
- password strength
- password history and re-use
- password expiration and
grace period
The Admin Security feature set restricts access to the ACP ports and mandates the following password length/strength requirements.
- user password must contain at least 9 characters (Admin Security only)
- admin password must contain at least 15 characters
- passwords must contain at least 2 lower case alphabetic characters
- passwords must contain at least 2 upper case alphabetic characters
- passwords must contain at least 2 numeric characters
- passwords must contain at least 2 special characters
- passwords must differ from the prior password by at least 4 characters
- passwords cannot contain, repeat, or reverse the user name
- passwords cannot contain three consecutive identical characters
The Admin Security ACP add-on feature imposes the same password length/strength requirements as above except for the minimum length requirement, and also provides access to the ACP ports.
- passwords cannot contain two or more characters from the user ID
- passwords cannot contain a sequence of three or more characters from any password contained in the password history cache
- passwords cannot contain a sequence of two or more characters more than once
- passwords cannot contain either sequential numbers or characters, or repeated characters more than once.
In the absence of the Admin Security ACP feature, you may safely ignore the password-policy-strength config property and retain the default value (disabled). For more information, see Configuring the Admin Security with ACP Password Rules.
Some specific password policy properties, specifically those regarding password lifetime and expiration procedures, are also applicable to SSH public keys used to authenticate client users.