<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 9800 encrypt PSK in config file in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4517584#M236467</link>
    <description>&lt;P&gt;Cisco IOS XE allows you to encrypt all the passwords used on the box. This includes user passwords but also SSID passwords, for example. To use encryption, first define an encryption key:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;c9800-1(config)#key config-key password-encrypt &amp;lt;key&amp;gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;and then use the following command:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;c9800-1(config)#password encryption aes&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This is recommended for protecting your password information.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;Note:&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;On the C9800, once the passwords are encrypted there is no mechanism to decrypt them, as a security best practice. The only way to recover would be to reconfigure the passwords.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Dec 2021 02:46:35 GMT</pubDate>
    <dc:creator>Haydn Andrews</dc:creator>
    <dc:date>2021-12-13T02:46:35Z</dc:date>
    <item>
      <title>9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4516830#M236432</link>
      <description>&lt;P&gt;is there a way to encrypt the PSK in the config file?&lt;/P&gt;&lt;P&gt;I tried password enryption aes in config mode and saved, as well as service password-encryption but no success with the PSK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;wlan Test 1 Test&lt;BR /&gt;security wpa psk set-key ascii 0 &lt;STRONG&gt;&lt;FONT color="#000000"&gt;Test1234&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;no security wpa akm dot1x&lt;BR /&gt;security wpa akm psk&lt;BR /&gt;no shutdown&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2021 16:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4516830#M236432</guid>
      <dc:creator>merilcerpos</dc:creator>
      <dc:date>2021-12-10T16:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4517174#M236446</link>
      <description>&lt;P&gt;All working fine for us - PSKs are type 8 encrypted.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;service password-encryption&lt;BR /&gt;password encryption aes&lt;/P&gt;&lt;P&gt;What model of WLC and what version of IOS-XE are you doing this on?&lt;/P&gt;&lt;P&gt;Have you actually set the AES encryption key using "&lt;!--  StartFragment   --&gt;&lt;SPAN class=""&gt;key config-key password-encrypt &amp;lt;key&amp;gt;"&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;Have you tried re-entering the PSK?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2021 14:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4517174#M236446</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2021-12-11T14:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4517584#M236467</link>
      <description>&lt;P&gt;Cisco IOS XE allows you to encrypt all the passwords used on the box. This includes user passwords but also SSID passwords, for example. To use encryption, first define an encryption key:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;c9800-1(config)#key config-key password-encrypt &amp;lt;key&amp;gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;and then use the following command:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;c9800-1(config)#password encryption aes&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This is recommended for protecting your password information.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;Note:&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;On the C9800, once the passwords are encrypted there is no mechanism to decrypt them, as a security best practice. The only way to recover would be to reconfigure the passwords.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 02:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4517584#M236467</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2021-12-13T02:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4522034#M236652</link>
      <description>&lt;P&gt;hello, thank you for your replies. Unfortunately it is still not working:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried that on 9800-CL WLC with software version 17.3.3 in dcloud.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;applied those commands in that order:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;service password-encryption&lt;BR /&gt;key config-key password-encrypt Test5678&lt;BR /&gt;password encryption aes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;wlan Test 1 Test&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;security wpa psk set-key ascii 0&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Test1234&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;no security wpa akm dot1x&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;security wpa akm psk&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;no shutdown&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;tried to reapply wlan profile configuration another time and save, but still the psk appears unencrypted in the config.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 08:47:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4522034#M236652</guid>
      <dc:creator>merilcerpos</dc:creator>
      <dc:date>2021-12-21T08:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4522063#M236653</link>
      <description>&lt;P&gt;It's working fine for us on&amp;nbsp;C9800-CL Software (C9800-CL-K9_IOSXE), Version 17.6.1 running on VMware ESX.&lt;/P&gt;&lt;P&gt;I can't see any reason why the same code shouldn't work fine in dcloud but that is a Cisco demo environment so they might have disabled some features.&amp;nbsp; You should be testing on a production release - not dcloud.&lt;/P&gt;&lt;P&gt;Did you try&amp;nbsp;password encryption aes&lt;BR /&gt;*before*&lt;BR /&gt;key config-key password-encrypt Test5678&lt;/P&gt;&lt;P&gt;Did you watch for error messages or other prompts?&lt;/P&gt;&lt;P&gt;Did you check the logs?&lt;/P&gt;&lt;P&gt;For example if there's already a key set you'll be prompted to enter the old key before it will allow you to set a new one.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 10:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4522063#M236653</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2021-12-21T10:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4522114#M236659</link>
      <description>&lt;P&gt;thank you it is working now. My mistake was to apply the cli commands via the gui command line interface instead via ssh/console&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 13:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4522114#M236659</guid>
      <dc:creator>merilcerpos</dc:creator>
      <dc:date>2021-12-21T13:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4522121#M236660</link>
      <description>&lt;P&gt;Lesson learned: do not use the GUI for CLI config, just use the CLI!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 13:21:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4522121#M236660</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2021-12-21T13:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4531891#M237121</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you are using "ascii 0", and not "ascii 8" ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the difference between this password&lt;/P&gt;&lt;PRE&gt;key config-key password-encrypt Test5678&lt;/PRE&gt;&lt;P&gt;and this one&lt;/P&gt;&lt;PRE&gt;security wpa psk set-key ascii 0&amp;nbsp;Test1234&lt;/PRE&gt;&lt;P&gt;Is the first one the Master? how is it used?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jan 2022 00:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4531891#M237121</guid>
      <dc:creator>shadowplay101</dc:creator>
      <dc:date>2022-01-15T00:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4531967#M237137</link>
      <description>&lt;P&gt;0 is plain text, unencrypted&lt;/P&gt;&lt;P&gt;8 is encrypted&lt;/P&gt;&lt;P&gt;ascii refers to the PSK format in this instance which is either ascii or hex.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;key config-key password-encrypt Test5678 is setting the AES encryption master key which the device keeps stored in private NVRAM (hidden) which is used to strongly (but reversibly) AES encrypt various keys/passwords in the config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security wpa psk set-key ascii 0 Test1234 is simply defining a WPA key for an SSID and ascii refers to the PSK format not the encryption or otherwise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Corrected to clarify ascii keyword.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 00:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4531967#M237137</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-01-16T00:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4531994#M237142</link>
      <description>&lt;P&gt;Thank you. I've been banging my head about how to "restore" a config file into a new WLC that includes the encrypted pre-shared keys&lt;/P&gt;&lt;P&gt;My wlan is configured like this (all good: preshared key encrypted, clients associated)&lt;/P&gt;&lt;PRE&gt; no broadcast-ssid
 security wpa psk set-key ascii 8 gKMSb[fBS^_ffUSI_MXZa`CWDUX[OeKHFAAB
 no security wpa akm dot1x
 security wpa akm psk
 no shutdown&lt;/PRE&gt;&lt;P&gt;Let's say my WLC fails and gets replaced, so I upload my config file&lt;/P&gt;&lt;P&gt;After the upload my wlan looks like this ( client cannot associate because there is no PSK)&lt;/P&gt;&lt;PRE&gt; no broadcast-ssid
 no security wpa akm dot1x
 no shutdown&lt;/PRE&gt;&lt;P&gt;At this point, it seems that I have to re-enable PSK, re-enter my pre-shared key, and re-send this command again&lt;/P&gt;&lt;PRE&gt;key config-key password-encrypt &amp;lt;key&amp;gt;&lt;/PRE&gt;&lt;P&gt;Is there a way for my pre-shared key to "transfer" by uploading my config file?&lt;/P&gt;&lt;P&gt;Thanks so much for the help!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jan 2022 13:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4531994#M237142</guid>
      <dc:creator>shadowplay101</dc:creator>
      <dc:date>2022-01-15T13:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4532109#M237146</link>
      <description>&lt;P&gt;Can't say I've tried it myself but a few pointers:&lt;/P&gt;&lt;P&gt;- make sure you're on latest version of IOS-XE that you can be.&lt;/P&gt;&lt;P&gt;- make sure AES encryption is configured with the same master key &lt;STRONG&gt;before&lt;/STRONG&gt; restoring any of the backup config otherwise IOS cannot decrypt those keys.&lt;/P&gt;&lt;P&gt;- you can enable AES, configure the master key (must be identical to what was used to encrypt initially) and then copy the backup config to running-config or to startup-config then reload.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 00:13:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/4532109#M237146</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-01-16T00:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 encrypt PSK in config file</title>
      <link>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/5199800#M276053</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Error&lt;/STRONG&gt;: Failed to decrypt password in &lt;STRONG&gt;WLC 9800-40&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;GUI&lt;/STRONG&gt;: Go to Configuration &amp;gt; WLC &amp;gt; Select WLAN ''name'' &amp;gt; Security &amp;gt; Change ''&lt;STRONG&gt;PSK Type&lt;/STRONG&gt;'' to unencrypted from dropdown &amp;gt; save the password and PSK Type will auto switch to AES.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 08:01:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-encrypt-psk-in-config-file/m-p/5199800#M276053</guid>
      <dc:creator>shubhamverma</dc:creator>
      <dc:date>2024-09-27T08:01:35Z</dc:date>
    </item>
  </channel>
</rss>

