2-29
Configuring Username and Password Security
Encrypting Credentials in the Configuration File
the username and password used as 802.1X authentication credentials for
access to the switch. You can store the
password port-access
values in the
running configuration file by using the
include-credentials
command.
Note that the
password port-access
values are configured separately from
local operator username and passwords configured with the
password
operator
command and used for management access to the switch. For
more information about how to use the
password port-access
command
to configure operator passwords and usernames for 802.1X authentica-
tion, see “Do These Steps Before You Configure 802.1X Operation” on page
13-13 in this guide.
Encrypting Credentials in the
Configuration File
Overview
A security risk is present when credentials used for authentication to remote
devices such as RADIUS or servers are displayed in the configura-
tion file in plain text. The
encrypt-credentials
command allows the storing,
displaying, and transferring of credentials in encrypted form.
When the encrypt-credentials feature is enabled, the affected credentials will
be encrypted using aes-256-cbc encryption. By default, a fixed, hard-coded
256-bit key that is common to all HP networking devices is used. This allows
transfer of configurations with all relevant credentials and provides much
more security than plaintext passwords in the configuration.
Additionally, you can set a separate, 256-bit pre-shared key, however, you must
now set the pre-shared key on the destination device before transferring the
configuration. The pre-shared key on the destination device must be identical
to the pre-shared key on the source device or the affected security credentials
will not be usable. This key is only accessible using the CLI, and is not visible
in any file transfers.
N o t e
It is expected that plaintext passwords will continue to be used for configuring
the switch. The encrypted credentials option is available primarily for the
backup and restore of configurations.
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......