Security - Panduit VeriSafe VS2-NET User Manual

Network module
Hide thumbs Also See for VeriSafe VS2-NET:
Table of Contents

Advertisement

Security

The Network Module contains software that stores user entered data . All data entered by the user is stored in
non-volatile storage on the system running the software .
NON-VOLATILE STORAGE
AUTHENTICATION DATA
NETWORK TRANSPORT SECURITY
NETWORK CONFIGURATION DATA
1006819, B21176_EN_rev3
The Network Module uses non-volatile storage to store all configuration information .
Passwords used for managing the software are stored as a one way bcrpyt hash .
Passwords that the user enters are not returned to the customer .
(They are 'write only' from a user perspective)
The product generates a random SSH RSA 2048-bit private host key the first time the product starts up .
The product has a randomly generated RSA 2048-bit private key configured by the factory . This key is
used to generate a HTTPS certificate the first time the product boots up .
The user may upload a custom HTTPS certificate and private key .
The HTTPS certificate should use a SHA-256 signature .
The private key should be RSA 2048-bit or prime256v1 (SECP256R1) .
Other private key types may work, but performance may be negatively impacted if greater
private key sizes are used: RSA 3072-bit, RSA 4096-bit; ECC curves: SECP192R1, SECP224R1,
SECP256R1, SECP384R1, SECP521R1, SECP192K1, SECP224K1, SECP256K1, BP256R1,
BP384R1, BP512R1, CURVE25519 .
The product uses TLS 1 .2 to communicate with HTTPS browser clients .
Secure communication cipher negotiation with HTTPS clients uses these Cipher Suites:
Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02b)
Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)
Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (0xc02c)
Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)
Cipher Suite: TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca9)
Cipher Suite: TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca8)
Cipher Suite: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (0x009e)
Cipher Suite: TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (0x009f)
Network Configuration, including Static IP addresses and addresses obtained by DHCP are exposed on a
"Settings" page, to aid in network management of the product .
26
06/19/2023

Advertisement

Table of Contents
loading

Table of Contents