<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Encryption for TACACS+ user passwords inside ISE2.2's Internal Identity Store in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593112#M527050</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for response. Appreciate if you could also point me in the right direction to the PM for such matters?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Sep 2017 16:30:01 GMT</pubDate>
    <dc:creator>Jimi</dc:creator>
    <dc:date>2017-09-27T16:30:01Z</dc:date>
    <item>
      <title>Encryption for TACACS+ user passwords inside ISE2.2's Internal Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593109#M527047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll just like to confirm that my understanding of how encryption is currently done for TACACS+ users in ISE 2.2 Internal Identity Store:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With reference to this link: &lt;A href="http://pmbuwiki.cisco.com/Products/ISE/Technical/Security#How_is_information_encrypted_in_ISE_for_local_Identity_Storage.3f" title="http://pmbuwiki.cisco.com/Products/ISE/Technical/Security#How_is_information_encrypted_in_ISE_for_local_Identity_Storage.3f"&gt;http://pmbuwiki.cisco.com/Products/ISE/Technical/Security#How_is_information_encrypted_in_ISE_for_local_Identity_Storage…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As mentioned in the document above, only the users' passwords (and not the rest of the fields/columns) in the database are hashed using SHA256 and stored without any cryptography "salt" component? May I know what is the recommended approach if customer has an audit compliance requirement that users' passwords have to be hashed and "salted" before kept on any DB?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jimmy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Sep 2017 09:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593109#M527047</guid>
      <dc:creator>Jimi</dc:creator>
      <dc:date>2017-09-03T09:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption for TACACS+ user passwords inside ISE2.2's Internal Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593110#M527048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to add on, I've also found this thread: &lt;A href="https://cisco.jiveon.com/thread/134207" title="https://cisco.jiveon.com/thread/134207"&gt;https://cisco.jiveon.com/thread/134207&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This kind of adds on additional information to the previous document.&lt;/P&gt;&lt;P&gt;However, it still says that non ISE-admin users' passwords are not salted prior to hashing with the AES128.&lt;/P&gt;&lt;P&gt;May I know is this considered acceptable for TACACS+ users' passwords?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Sep 2017 15:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593110#M527048</guid>
      <dc:creator>Jimi</dc:creator>
      <dc:date>2017-09-03T15:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption for TACACS+ user passwords inside ISE2.2's Internal Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593111#M527049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Enable passwords are stored the same as regular passwords. Please contact our PM if you have additional requirements.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 18:20:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593111#M527049</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-11T18:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption for TACACS+ user passwords inside ISE2.2's Internal Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593112#M527050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for response. Appreciate if you could also point me in the right direction to the PM for such matters?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 16:30:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593112#M527050</guid>
      <dc:creator>Jimi</dc:creator>
      <dc:date>2017-09-27T16:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption for TACACS+ user passwords inside ISE2.2's Internal Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593113#M527051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just emailed you separately on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 19:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/encryption-for-tacacs-user-passwords-inside-ise2-2-s-internal/m-p/3593113#M527051</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-27T19:51:37Z</dc:date>
    </item>
  </channel>
</rss>

