
ISR654601-00 D
3-1
3
Configuring CHAP
In
challenge handshake authentication protocol
(CHAP), the authentication agent
sends the client program an ID value and a random value that is used only once.
Both the sender and peer share a predefined secret. The peer concatenates the
random value, the ID, and the secret. Then it calculates a one-way hash using
message-digest algorithm 5 (MD5). The peer sends the hash value to the
authenticator, which in turn builds that same string on its side, calculates the MD5
checksum, and compares the result with the value received from the peer. If the
values match, the peer is authenticated.
By transmitting only the hash, the secret cannot be reverse-engineered. The
algorithm increases the ID value with each CHAP dialog to protect against replay
attacks.
This chapter provides the procedures for configuring CHAP from the command
line interface (CLI), including:
“Discovery Session—Bi-directional CHAP” on page 3-2
“Discovery Session—Uni-directional CHAP” on page 3-3
“Normal Session— Bi-directional CHAP” on page 3-4
“Normal Session—Uni-directional CHAP” on page 3-5
Summary of Contents for StorageWorks MPX200
Page 1: ...ISR654601 00 D iSR6200 Command Line Interface CLI User s Guide...
Page 10: ...x ISR654601 00 D iSR6200 Command Line Interface CLI User s Guide...
Page 16: ...xvi ISR654601 00 D...
Page 138: ...3 Configuring CHAP Normal Session Uni directional CHAP 3 6 ISR654601 00 D...
Page 146: ...4 Virtual Port Groups Enabling Virtual Port Groups 4 8 ISR654601 00 D...
Page 182: ...A Simple Network Management Protocol Notifications A 26 ISR654601 00 D...
Page 239: ......