C H A P T E R
18
Configuring Password Encryption
This chapter describes how to configure password encryption on Cisco NX-OS devices.
This chapter includes the following sections:
•
About AES Password Encryption and Master Encryption Keys, on page 413
•
Licensing Requirements for Password Encryption, on page 413
•
Guidelines and Limitations for Password Encryption, on page 414
•
Default Settings for Password Encryption, on page 414
•
Configuring Password Encryption, on page 414
•
Verifying the Password Encryption Configuration, on page 417
•
Configuration Examples for Password Encryption, on page 417
About AES Password Encryption and Master Encryption Keys
You can enable strong, reversible 128-bit Advanced Encryption Standard (AES) password encryption, also
known as type-6 encryption. To start using type-6 encryption, you must enable the AES password encryption
feature and configure a master encryption key, which is used to encrypt and decrypt passwords.
After you enable AES password encryption and configure a master key, all existing and newly created clear-text
passwords for supported applications (currently RADIUS and ) are stored in type-6 encrypted
format, unless you disable type-6 password encryption. You can also configure Cisco NX-OS to convert all
existing weakly encrypted passwords to type-6 encrypted passwords.
Related Topics
Configuring a Master Key and Enabling the AES Password Encryption Feature
, on page 414
Configuring Global RADIUS Keys
, on page 46
Configuring a Key for a Specific RADIUS Server
, on page 47
, on page 75
Configuring a Key for a Specific Server
, on page 76
Configuring a Master Key and Enabling the AES Password Encryption Feature
, on page 414
Licensing Requirements for Password Encryption
The following table shows the licensing requirements for this feature:
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
413