Restrictions for Configuring Security with Passwords, Privileges, and Logins
Your networking device must not be configured to use any local or remote authentication, authorization, and accounting (AAA) security features. This document describes only the non-AAA security features that can be configured locally on the networking device.
For information how to configure AAA security features that can be run locally on a networking device, or for information on how to configure remote AAA security using TACACS+ or RADIUS servers, see the Securing User Services Configuration Guide Library.
Restrictions and Guidelines for Reversible Password Types
-
Password type 0 and type 7 are deprecated. So password type 0 and type 7, used for administrator login to Console, Telnet, SSH, webUI, and NETCONF, must be migrated to password type 8 or type 9.
-
No action is required if username and password are type 0 and type 7 for local authentication such as CHAP, EAP and so on for ISG and Dot1x.
-
Enable password type 0 and type 7 must be migrated to password type 8 or type 9.
Restrictions and Guidelines for Irreversible Password Types
-
Password type 5 is deprecated. Password type 5 must be migrated to stronger password type 8 or type 9.
-
For username secret password type 5 and for enable secret password type 5, migrate to type 8 or type 9.
-
Secret password type 4 is not supported.