cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1945
Views
0
Helpful
3
Replies

ASA 9.3(2) wants "password encryption key"

ericx
Level 1
Level 1

 

The following now appears in my ASA config file:

(obfuscated hash)

! The following entry is deferred until the password encryption key is specified.
snmp-server community 8 jX1ZpJ8wlsJWIYJFHHnXF4htTLcjPvQPHGM=

The snmp V2c works. 

 

Google search for the string "The following entry is deferred until the password encryption key is specified." returns nothing useful.

So what does "deferred" mean?

What is a "password encryption key?"

3 Replies 3

The ASA can encrypt local passwords (and a community-string is also a password) in the config. For that password-encryption has to be configured:

key config-key password-encryption SUPER-SECRET-KEY
password encryption aes

The key will not be visible in the config and the ASA can't use the encrypted keys until you configure the line with the config-key. That is meant with "deferred".


@Karsten Iwen wrote:

The ASA can encrypt local passwords (and a community-string is also a password) in the config. For that password-encryption has to be configured:

key config-key password-encryption SUPER-SECRET-KEY
password encryption aes

The key will not be visible in the config and the ASA can't use the encrypted keys until you configure the line with the config-key. That is meant with "deferred".


That's pretty clear; but it begs a few more questions..

- How is it that the community string is hashed if no config-key has been supplied?

- More to the point, the snmp v2c community string works fine from remote machines; so presumably it's not "deferred?"

 

Actually, you should just see the encrypted string and not a hash.

If it works, it could be because of the rest of the config/setup that you didn't show. Hard to tell.

Review Cisco Networking products for a $25 gift card