Hi Trying to setup c9800 as normal procedure. We can login the WLC via cli but not gui with saying "Wrong Credential .." The below link is bug on it.
Is this issue resolved? Thank you
Symptom: "Wrong Credentials. Please Login again." error when accessing the switch via GUI. Conditions: SHIVA#show run | i username username ww password 0 ww username cisco password 0 cisco username test password 0 test SHIVA#show run | i aaa aaa new-model aaa session-id common Problem is not always seen right after reboot, after day or two problem appears consistently. With above configuration try to access the GUI of the switch. Workaround: Power cycle of the switch. Further Problem Description:
Solved! Go to Solution.
You should not be using type 7 password encryption or md5 hash secret anymore - both very insecure and unsafe.
You should be using type 9 (scrypt) which is now the most secure option available (type 8 also acceptable but consensus that 9 is better):
username test privilege 15 algorithm-type scrypt secret plaintextsecret
That will appear in the config as:
username test privilege 15 secret 9 $9$XDxtW9Ixseuak.$kMOej8hDPlSueAY6NsEMvwSCa51qmm11JBvdPjrF8Ec
FYI: you can't just 'change the number from "0" to "7".' - what follows 7 is the reversibly encrypted version of your plaintext password. It's very easy to decrypt using numerous websites and tools because the encryption algorithm is very basic and well known.
If you enable "service password-encryption" then IOS will encrypt plaintext passwords by default and which encryption type it uses depends on whether you have also enabled aes encryption with master key:
password encryption aes
key config-key password-encrypt <masterencryptionkey>
The master key is stored in secure NVRAM and can never be viewed. If you lose the master key then the passwords can never be decrypted.