One-Time Password Support; Recovering The Administrator Password - Cisco MDS 9000 Series Configuration Manual

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Security Features on an External AAA Server
Authentication Statistics
Accounting Statistics
You can clear RADIUS server statistics using the clear radius-server statistics 10.1.3.2 command.

One-Time Password Support

A one-time password (OTP) is a password that is valid for a single login session or transaction. OTPs avoid
a number of disadvantages that are associated with usual (static) passwords. The most vital disadvantage that
is addressed by OTPs is that, they are not at risk to replay attacks. If an intruder manages to record an OTP
that was already used to log into a service or to conduct an operation, it will not be misused as it will no longer
be valid.
One Time Password is applicable only to RADIUS and TACACS protocol daemons. With a RADIUS protocol
daemon, there is no configuration required from the switch side. With a TACACS protocol, ascii authentication
mode needs to be enabled, which can be done by the following command:
aaa authentication login ascii-authentication

Recovering the Administrator Password

You can recover the administrator password using one of two methods:
• From the CLI with a user name that has network-admin privileges.
• Power cycling the switch.
The following topics included in this section:
Using the CLI with Network-Admin Privileges
If you are logged in to, or can log into, switch with a user name that has network-admin privileges and then
recover the administrator password, follow these steps:
Procedure
Step 1
Use the show user-accounts command to verify that your user name has network-admin privileges.
failed transactions: 0
sucessful transactions: 0
requests sent: 0
requests timed out: 0
responses with no matching requests: 0
responses not processed: 0
responses containing errors: 0
failed transactions: 0
successful transactions: 0
requests sent: 0
requests timed out: 0
responses with no matching requests: 0
responses not processed: 0
responses containing errors:
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
One-Time Password Support
65

Advertisement

Table of Contents
loading

Table of Contents