About The Dhchap Hash Algorithm; Configuring The Dhchap Hash Algorithm - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

DHCHAP
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Command
Step 3
switch(config-if)# fcsp on
switch(config-if)# no fcsp on
Step 4
switch(config-if)# fcsp
auto-active 0
switch(config-if)# fcsp
auto-active 120
switch(config-if)# fcsp
auto-active

About the DHCHAP Hash Algorithm

Cisco MDS switches support a default hash algorithm priority list of MD5 followed by SHA-1 for
DHCHAP authentication.
Tip
If you change the hash algorithm configuration, then change it globally for all switches in the fabric.
RADIUS and TACACS+ protocols always use MD5 for CHAP authentication. Using SHA-1 as the hash
Caution
algorithm may prevent RADIUS and TACACS+ usage—even if these AAA protocols are enabled for
DHCHAP authentication.

Configuring the DHCHAP Hash Algorithm

To configure the hash algorithm, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# fcsp dhchap hash sha1
switch(config)# fcsp dhchap hash MD5
switch(config)# fcsp dhchap hash md5
sha1
switch(config)# no fcsp dhchap hash
sha1
Cisco MDS 9000 Family CLI Configuration Guide
38-6
Chapter 38
Purpose
Sets the DHCHAP mode for the selected interfaces to be in the
on state.
Reverts to the factory default of auto-passive for these three
interfaces.
Changes the DHCHAP authentication mode for the selected
interfaces to auto-active. Zero (0) indicates that the port does
not perform reauthentication.
The reauthorization interval configuration is the same
Note
as the default behavior.
Changes the DHCHAP authentication mode to auto-active for
the selected interfaces and enables reauthentication every two
hours (120 minutes) after the initial authentication.
Changes the DHCHAP authentication mode to auto-active for
the selected interfaces. Reauthentication is disabled (default).
The reauthorization interval configuration is the same
Note
as setting it to zero (0).
Purpose
Enters configuration mode.
Configures the use of only the SHA-1 hash algorithm.
Configures the use of only the MD5 hash algorithm.
Defines the use of the default hash algorithm priority list
of MD5 followed by SHA-1 for DHCHAP authentication.
Reverts to the factory default priority list of the MD5
hash algorithm followed by the SHA-1 hash algorithm.
Configuring FC-SP and DHCHAP
OL-18084-01, Cisco MDS NX-OS Release 4.x

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents