SV-101261r1_rule
V-91161
SRG-APP-000378-NDM-000302
JUNI-ND-001060
CAT II
10
Configure one or more classes as shown in the example below whose users will not be permitted to add or change software installed on the router.
[edit system]
set login class JR_ENGINEER permissions all
set login class JR_ENGINEER deny-commands “(request system software)”
Note: The predefined classes operator and Read-only do not have permissions to install software.
Review the router configuration to verify that it is compliant with this requirement. The configuration example below depicts a class JR_ENGINEER that is not permitted to add or change software installed on the router.
login {
class JR_ENGINEER {
permissions all;
deny-commands "request system software";
}
Note: The following are the options under request system software:
abort -Abort software upgrade
add -Add extension or upgrade package
delete -Remove extension or upgrade package
rollback -Roll back to previous set of packages
validate -Verify package compatibility with current configuration
If the router is not configured to prohibit installation of software without explicit privileged status, this is a finding.
V-91161
False
JUNI-ND-001060
Review the router configuration to verify that it is compliant with this requirement. The configuration example below depicts a class JR_ENGINEER that is not permitted to add or change software installed on the router.
login {
class JR_ENGINEER {
permissions all;
deny-commands "request system software";
}
Note: The following are the options under request system software:
abort -Abort software upgrade
add -Add extension or upgrade package
delete -Remove extension or upgrade package
rollback -Roll back to previous set of packages
validate -Verify package compatibility with current configuration
If the router is not configured to prohibit installation of software without explicit privileged status, this is a finding.
M
3381