Configuring a Common Criteria Authorized Administrator
An account for root
is always present in a configuration and is not intended
for use in normal operation. In the evaluated configuration, the root
account
is restricted to the initial installation and configuration of the evaluated device.
A Common Criteria authorized administrator must have all permissions, including the ability to change the router configuration.
To configure an authorized administrator:
The root password should be reset following the change to sha256 for the password storage
format. This ensures the new password is protected using a sha256 hash, rather than the
default password hashing algorithm. To reset the root password, use the set system
login user root password password
command, and confirm the new
password when prompted.