Encrypting Passwords Using the service passwordencryption Command
router(config) #
service password-encryption
• Encrypts all clear text passwords in the router configuration file router(config) #
Boston(config)# service password-encryption
• Encrypts all clear text passwords in the router configuration file router(config) #
Boston(config)# service password-encryption
|
Boston# show running-config |
||
|
enable password 7 06020026144A061E |
||
|
line con |
0 |
|
|
password |
7 |
0956F57A109A |
|
line vty |
0 |
4 |
|
password |
7 |
034A18F366A0 |
|
line aux |
0 |
|
|
password |
7 |
7A4F5192306A |
Just like console and vty passwords, auxiliary passwords are not encrypted in the router configuration. This is why it is important to use the service password-encryption command.
With the exception of the enable secret password, all Cisco router passwords are, by default, stored in clear text form within the router configuration. View these passwords with the show running-config command. Sniffers can also see these passwords if your TFTP server configuration files traverse an unsecured intranet or Internet connection. If an intruder gains access to the TFTP server where the router configuration files are stored, the intruder will be able to obtain these passwords.
A proprietary Cisco algorithm based on a Vigenere cipher (indicated by the number 7 when viewing the configuration) allows the service password-encryption command to encrypt all passwords (except the previously encrypted enable secret password) in the router configuration file. This method is not as safe as MD5, which is used with the enable secret command, but prevents casual discovery of the router line-level passwords.
Note The encryption algorithm in the service password-encryption command is considered relatively weak by most cryptographers, and several Internet sites post mechanisms for cracking this cipher. This posting only proves that relying on the encrypted passwords alone is not sufficient security for your Cisco routers. You need to ensure that the communications link between the console and the routers, or between the TFTP or management server and the routers, is a secured connection. Securing this connection is discussed in the "Configuring Enhanced Support for Virtual Logins" topic.
After all of your passwords have been configured for the router, you should run the service password-encryption command in global configuration mode, as shown in the figure.
2-36 Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.
Continue reading here: Setting a Login Failure Rate
Was this article helpful?