6 Security User Guide / Security Advisories
The current firmware version LTOS V7 of Meinberg’s TSU boards no longer offers the ability to establish an
SSH connection via network. Access is only allowed via the CPU module of the LANTIME. It is still possible
to completely disable the SSH service of a TSU card as shown in
Figure 6.3: Disable SSH on TSU
Services
Confidentiality
Integ.
Avail.
Auth.
Account.
https
x
x
0
x
(x)
ssh
x
x
0
x
(x)
ntp
-
x
0
x
(x)
Table: Security targets
The table shows the security goals of the protocols in short. The accountability is given through a detailed
syslog of the actions performed by every user or process. However, the log files can be changed later by root
or super users. For this reason, the system cannot guarantee the non-repudiation.
The most, possible availability of the services is realized through current updates and IP banning. For more
protection, implement web application firewalls and traditional firewalls in the network, that are able to identify
and prevent DOS/DDOS attacks.
With all changes to the configuration keep in mind, that they are lost after a reboot or could be discarded
by other admins or super users , if they are not saved in the startup configuration.
LANTIME CPU Expansion Shelf
Date: 2nd July 2020
19
Summary of Contents for LCES
Page 2: ......