cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3130
Views
0
Helpful
3
Replies

Authentication failure for switch username on CAT6K when service password-encryption is enabled

umahar
Cisco Employee
Cisco Employee

Hello,

We have encountered an issue on Cat6K SUP720 running 12.2(33)SXI9 with the following command.

radius-server host <ip address –PSN1> test username <radius-test> idle-time X key <key>

If service password-encryption is enabled on the switch the PAP_ASCII authentication is failing on ISE.

If there is no service password-encryption enabled on the switch the authentication is passing.

The logs on ISE are as follows.

Root Cause :- Wrong password or invalid shared secret

DetailInfo   :- UserPassword is corrupted.

Is this a known issue ?

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

I've seen this and it's a IOS bug. Please work with our IOS platform team to resolve it.

View solution in original post

3 Replies 3

hslai
Cisco Employee
Cisco Employee

I've seen this and it's a IOS bug. Please work with our IOS platform team to resolve it.

umahar
Cisco Employee
Cisco Employee

Thank You Hsing-Tsu Lai.

Can you direct me to the IOS platform team which can address this.

hslai
Cisco Employee
Cisco Employee

If you are a Cisco customer/partner, please open a TAC case to address your concerns. Otherwise, I believe I already responded offline.