Dhchap Hash Algorithm Configuration; Dhchap Group Configuration - Cisco DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor Configuration Manual

Mds 9000 family
Table of Contents

Advertisement

DHCHAP Hash Algorithm Configuration

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .
DHCHAP Hash Algorithm Configuration
Cisco MDS switches support a default hash algorithm priority list of MD5 followed by SHA-1 for
DHCHAP authentication.
If you change the hash algorithm configuration, then change it globally for all switches in the fabric.
Tip
RADIUS and TACACS+ protocols always use MD5 for CHAP authentication. Using SHA-1 as the hash
Caution
algorithm may prevent RADIUS and TACACS+ usage—even if these AAA protocols are enabled for
DHCHAP authentication.
To change the hash algorithm, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# fcsp dhchap hash sha1
switch(config)# fcsp dhchap hash MD5
switch(config)# fcsp dhchap hash md5
sha1
switch(config)# no fcsp dhchap hash
sha1

DHCHAP Group Configuration

All switches in the Cisco MDS Family support all DHCHAP groups specified in the standard: 0 (null
DH group, which does not perform the Diffie-Hellman exchange), 1, 2, 3, or 4.
Tip
If you change the DH group configuration, change it globally for all switches in the fabric.
To change the DH group settings, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# fcsp dhchap
group 2 3 4
switch(config)# no fcsp dhchap
group 0
Cisco MDS 9000 Family Configuration Guide
31-6
Purpose
Enters configuration mode.
Configures the use of only the SHA-1 hash algorithm.
Configures the use of only the MD5 hash algorithm.
Defines the use of the default hash algorithm priority list
of MD5 followed by SHA-1 for DHCHAP authentication.
Reverts to the factory default priority list of the MD5
hash algorithm followed by the SHA-1 hash algorithm.
Purpose
Enters configuration mode.
Prioritizes the use of DH group 2, 3, and 4 in the configured order.
Reverts to the DHCHAP factory default order of 0, 4, 1, 2, and 3.
Chapter 31
Configuring FC-SP and DHCHAP
OL-6973-03, Cisco MDS SAN-OS Release 2.x

Advertisement

Table of Contents
loading

Table of Contents