<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE2.3 username with blank password in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3325170#M555198</link>
    <description>&lt;P&gt;I was the one tested on version 2.3. i found same the return message is "Enter Old Password:" and i try put known users in ISE with blank password. i found return message is "% Authentication failed. " &lt;BR /&gt;I think that is a vulnerability for those who do not hope to find a real user.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Feb 2018 10:55:20 GMT</pubDate>
    <dc:creator>Jakapan</dc:creator>
    <dc:date>2018-02-05T10:55:20Z</dc:date>
    <item>
      <title>why do I get this prompt even though the user does not exist.(ISE2.3)</title>
      <link>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3313618#M555138</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have Cisco ISE 2.3&amp;nbsp;and the router has IOS&amp;nbsp;. I am using TACACS+ function on ISE&amp;nbsp;&lt;BR /&gt;Am try put unknown&amp;nbsp;users in ISE(&lt;/SPAN&gt;Network Access Users) with blank password(by enter)&lt;/P&gt;
&lt;P&gt;we found the return message is "Enter Old Password:" on the router.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;what &amp;nbsp;I doing wrong?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;router configuration&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local group tacacs+&lt;BR /&gt;aaa authorization exec default local group tacacs+ if-authenticated&lt;BR /&gt;aaa authorization commands 3 default local group tacacs+ if-authenticated&lt;BR /&gt;aaa authorization commands 5 default local group tacacs+ if-authenticated&lt;BR /&gt;aaa authorization commands 15 default local group tacacs+ if-authenticated&lt;BR /&gt;aaa accounting exec default&lt;BR /&gt; action-type start-stop&lt;BR /&gt; group tacacs+&lt;BR /&gt;!&lt;BR /&gt;aaa accounting commands 3 default&lt;BR /&gt; action-type start-stop&lt;BR /&gt; group tacacs+&lt;BR /&gt;!&lt;BR /&gt;aaa accounting commands 5 default&lt;BR /&gt; action-type start-stop&lt;BR /&gt; group tacacs+&lt;BR /&gt;!&lt;BR /&gt;aaa accounting commands 15 default&lt;BR /&gt; action-type start-stop&lt;BR /&gt; group tacacs+&lt;BR /&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pb-1.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/6492i3AD50620FB4BBDA3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pb-1.png" alt="pb-1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pb-2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/6493i891A5E361E72C4D4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pb-2.png" alt="pb-2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pb-3.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/6491i9571945AEB63215F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pb-3.png" alt="pb-3.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3313618#M555138</guid>
      <dc:creator>hatman</dc:creator>
      <dc:date>2020-02-21T18:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE2.3 username with blank password</title>
      <link>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3317222#M555140</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you enter a TACACS+ username a blank password is a 'change password' action.&lt;/P&gt;
&lt;P&gt;I think the question would be "why do I get this prompt even though the user does not exist".&lt;/P&gt;
&lt;P&gt;In this case you can easily see that in a capture done on ISE. Unfortunately, now I don't have any ISE or ACS to test, but it would be nice if someone can confirm that ACS is behaving the same way or not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 22:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3317222#M555140</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2018-01-23T22:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE2.3 username with blank password</title>
      <link>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3317463#M555161</link>
      <description>&lt;P&gt;Thank you for your advice i have changed the subject.&lt;BR /&gt;and i experimented on ACS version 5.8 i found the same thing.&lt;BR /&gt;I wonder if this is normal process.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 02:10:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3317463#M555161</guid>
      <dc:creator>hatman</dc:creator>
      <dc:date>2018-01-25T02:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE2.3 username with blank password</title>
      <link>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3318027#M555176</link>
      <description>&lt;P&gt;If ACS behaves the same exact way, I would say it's a feature :).&lt;/P&gt;
&lt;P&gt;I'm just imagining that the whole authentication process (even though this is interactive/message by message) is done only after one has succesfully sent both his username and password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I mean, give me user (X) and password (Y) in a total of&amp;nbsp; 4 messages (request/response) and after that and only after that I'll tell you if you're authenticated or not (doesn't matter if the user exists or not; I must have user's password to check)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the above logic is correct, then the password change functionality would behave the same way.&lt;/P&gt;
&lt;P&gt;Enter any user and press enter. AAA system will initiate the password change functionality and request your old password + your new password. Only after you've provided all this info, the AAA server is able to tell you that it can't do anything about it because actually the first authentication phase was not succesful (because there's no such username)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 22:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3318027#M555176</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2018-01-24T22:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE2.3 username with blank password</title>
      <link>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3325170#M555198</link>
      <description>&lt;P&gt;I was the one tested on version 2.3. i found same the return message is "Enter Old Password:" and i try put known users in ISE with blank password. i found return message is "% Authentication failed. " &lt;BR /&gt;I think that is a vulnerability for those who do not hope to find a real user.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2018 10:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-do-i-get-this-prompt-even-though-the-user-does-not-exist/m-p/3325170#M555198</guid>
      <dc:creator>Jakapan</dc:creator>
      <dc:date>2018-02-05T10:55:20Z</dc:date>
    </item>
  </channel>
</rss>

