<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE and Oracle DB with Hash Passwords in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794243#M485727</link>
    <description>Ok,  Thanks for the clarification.&lt;BR /&gt;</description>
    <pubDate>Mon, 04 Feb 2019 14:00:44 GMT</pubDate>
    <dc:creator>gugonza2</dc:creator>
    <dc:date>2019-02-04T14:00:44Z</dc:date>
    <item>
      <title>ISE and Oracle DB with Hash Passwords</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794130#M485639</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have an Oracle DB with Usernames and Password Hashes stored.&lt;/P&gt;
&lt;P&gt;I would like to configure ISE using ODBC to authenticate users using Oracle DB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Is ISE able to check credentials if Oracle has password hashes only ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- ISE would calculate the password hash and will compare with Oracle DB ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 11:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794130#M485639</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2019-02-04T11:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Oracle DB with Hash Passwords</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794211#M485642</link>
      <description>&lt;P&gt;It can be hashed in the table, but stored procedure for retrieving the password has to be able to reverse it to plain text password. IOW, ISE will not do the calculation, rather you have to make the stored procedure call in the DB to do that for ISE.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 13:11:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794211#M485642</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-02-04T13:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Oracle DB with Hash Passwords</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794235#M485647</link>
      <description>&lt;P&gt;Thx,&amp;nbsp; but it´s not easy revert hash to plain text.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Checking the ISE documentation I found;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Plain Text Password fetching from ODBC database Credential Check:&amp;nbsp;&amp;nbsp;If the username is found, its password and relevant user information is returned by the stored procedure. Cisco ISE calculates the password hash based on the authentication method and compares it with the one received from the client."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any comment ?&lt;/P&gt;
&lt;TABLE id="id_10025__table_1FA9CAC4C09845119461AB366E7C5566" class="table" border="1" width="100%"&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 04 Feb 2019 13:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794235#M485647</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2019-02-04T13:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Oracle DB with Hash Passwords</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794242#M485726</link>
      <description>&lt;P&gt;Yes, exactly. ISE needs to see the password for it to process the authentication. ISE can't simply compare hash from the client to the DB directly ATM. So the answer is still no it can't be done unless password is presented to ISE in clear text.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 13:51:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794242#M485726</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-02-04T13:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and Oracle DB with Hash Passwords</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794243#M485727</link>
      <description>Ok,  Thanks for the clarification.&lt;BR /&gt;</description>
      <pubDate>Mon, 04 Feb 2019 14:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-oracle-db-with-hash-passwords/m-p/3794243#M485727</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2019-02-04T14:00:44Z</dc:date>
    </item>
  </channel>
</rss>

