Security: Secure Sensitive Data Management
Configuring SSD
Cisco Small Business 200, 300 and 500 Series Managed Switch Administration Guide (Internal Version) 453
21
Password recovery is currently activated from the boot menu and allows the user
to log on to the terminal without authentication. If SSD is supported, this option is
only permitted if the local passphrase is identical to the default passphrase. If a
device is configured with a user-defined passphrase, the user is unable to activate
password recove ry.
Configuring SSD
The SSD feature is configured in the following pages:
SSD properties are set in the Properties page.
SSD rules are defined in the SSD Rules page.

SSD Properties

Only users with SSD read permission of Plaintext-only or Both are allowed to set
SSD properties.
To configure global SSD properties:
STEP 1 Click Security > Secure Sensitive Data Management > Properties. The
following field appears:
Current Local Passphrase Type—Displays whether the default
passphrase or a user-defined passphrase is currently being used.
STEP 2 Enter the following Persistent Settings fields:
Configuration File Passphrase Control—Select an option as described in
Configuration File Passphrase Control.
Configuration File Integrity Control—Select to enable this feature. See
Configuration File Integrity Control.
STEP 3 Select a Read mode for the current session (see Elements of an SSD Rule).
To change the local passphrase:
STEP 1 Click Change Local Passphrase, and enter a new Local Pass phrase:
Default—Use the devices default passphrase.