Require Password Encryption

Information

Passwords should not be displayed in plain text format in configuration files or when viewed via the CLI. This prevents casual observers and unauthorized individuals gaining knowledge of other users passwords. The 'hash-control' command is used to enforce encryption of passwords in the configuration. Version 2 must be specified.

Solution

Run the following command on the device to enable password encryption: configure system security hash-control read-version all write-version 2

See Also

https://infoproducts.alcatel-lucent.com/aces/cgi-bin/dbaccessfilename.cgi/9305050101_V1_SR-OS Security Best Practices v2.0.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c)

Plugin: Alcatel

Control ID: 4322ee269747b85769e00a34140112b6c8ae02ebb746feb8e19baffc7fd07ed6