SV3800, SV3800B, and SV3800B-20 Security Policy
2016 Symantec Corporation This document may be freely reproduced & distributed whole & intact including this copyright
notice.
24
•
symbols (32 characters)
•
space (one character)
The total valid character set is 95 characters. The password is further limited in
that it must contain at least one non-alphabetic character, one uppercase letter,
one lowercase letter, and one digit. Further, it cannot be in the dictionary of
common passwords. Login attempts are rate limited to 10 per second.
Table A.1 in NIST Special Publication 800-63-1 shows that with 94 characters there
are 30 bits of entropy. 2
30
is much greater than 1 million, as is 2
30
/ 10. As the total
valid character set of 95 characters is larger than 94 characters, there is
approximately 30.32 bits of entropy present.
The PIN configured during initial setup and entered at each subsequent boot
must be at least one character, and at most 16 characters. The characters permitted
are all uppercase characters, all lowercase characters, and space. Symantec
recommends using a PIN of at least eight characters.
Table 2
–7 Authentication Mechanisms
Role
Authentication
Type
Single Attempt Strength
Multiple Attempt Strength
Crypto
Officer
Username/
password
Passwords must be a minimum of 8
characters. The probability of a false
positive for a random password
guess is less than 1 in 1,000,000.
Actual value 2
30
.
Passwords must be a minimum
of 8 characters. The probability
of a false positive for a
maximum of 600 attempts per
minute is less than 1 in 1,000,000
over a one minute period.
Actual value 2
30
/10.
User
Username/
password
Passwords must be a minimum of 8
characters. The probability of a false
positive for a random password
guess is less than 1 in 1,000,000.
Actual value 2
30
.
Passwords must be a minimum
of 8 characters. The probability
of a false positive for a
maximum of 600 attempts per
minute is less than 1 in 1,000,000
over a one minute period.
Actual value 2
30
/10.
Manage
Appliance
Username/
password
Passwords must be a minimum of 8
characters. The probability of a false
positive for a random password
guess is less than 1 in 1,000,000.
Actual value 2
30
.
Passwords must be a minimum
of 8 characters. The probability
of a false positive for a
maximum of 600 attempts per
minute is less than 1 in 1,000,000
over a one minute period.
Actual value 2
30
/10.
Manage
Policy
Username/
password
Passwords must be a minimum of 8
characters. The probability of a false
positive for a random password
guess is less than 1 in 1,000,000.
Actual value 2
30
.
Passwords must be a minimum
of 8 characters. The probability
of a false positive for a
maximum of 600 attempts per
minute is less than 1 in 1,000,000
over a one minute period.
Actual value 2
30
/10.