JUSX-DM-000136 - The Juniper SRX Services Gateway must use the SHA256 or later protocol for password authentication for local accounts using password authentication (i.e., the root account and the account of last resort) - i.e., the root account and the account of last resort the Juniper SRX Services Gateway must use the SHA1 or later protocol for password authentication.

Information

Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised.

Solution

Enter the following example command from the configuration mode.

[edit]
set system login password format sha256

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Juniper_SRX_SG_Y25M01_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CAT|I, CCI|CCI-000197, Rule-ID|SV-223223r1056174_rule, STIG-ID|JUSX-DM-000136, STIG-Legacy|SV-81017, STIG-Legacy|V-66527, Vuln-ID|V-223223

Plugin: Juniper

Control ID: fe0a6612a0148566cd104c677bd5d9d60791d0fcc8618a4455cf7032f584297a