cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
786
Views
0
Helpful
9
Replies

Bug is resolved on login issue?

zshowip
Enthusiast
Enthusiast

Hi Trying to setup c9800 as normal procedure. We can login the WLC via cli but not gui with saying "Wrong Credential .." The below link is bug on it.

Is this issue resolved? Thank you

 

 

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvd82988

 

Symptom: "Wrong Credentials. Please Login again." error when accessing the switch via GUI. Conditions: SHIVA#show run | i username username ww password 0 ww username cisco password 0 cisco username test password 0 test SHIVA#show run | i aaa aaa new-model aaa session-id common Problem is not always seen right after reboot, after day or two problem appears consistently. With above configuration try to access the GUI of the switch. Workaround: Power cycle of the switch. Further Problem Description:

3 Accepted Solutions

Accepted Solutions

 

 - Wouldn't do that , apparently the bug report is already two years old ,avoid using usernames as being mentioned in the Conditions of the bug report.

 M.

View solution in original post

 

     - Yes , don't use those usernames or passwords.

 M.

View solution in original post

 

 - Issue (CLI) command "show tech wireless" : have the output analyzed by , https://cway.cisco.com/tools/WirelessAnalyzer/ , look for critical advisories (red) , and correct accordingly.

 M.

View solution in original post

9 Replies 9

marce1000
VIP Mentor VIP Mentor
VIP Mentor

 

       - Use one of the Known Fixed Releases , as mentioned in the bug report.

 M.

Thank you for your reply! now its version is 17.3.4c. The options are about 16.-- Do you mean we need to downgrade its ios? 

 

 - Wouldn't do that , apparently the bug report is already two years old ,avoid using usernames as being mentioned in the Conditions of the bug report.

 M.

zshowip
Enthusiast
Enthusiast

It means that username and password are too simple?

 

 

     - Yes , don't use those usernames or passwords.

 M.

zshowip
Enthusiast
Enthusiast

We have changed to complicated username and password. but the issue is still there. 

and i also want to change the number from "0" to "7" . but it does not work. Do you think we need to change it?

 

V(config)#username asqwert privilege 15 password 7 ?
WORD The HIDDEN user password string

 

 

 - Issue (CLI) command "show tech wireless" : have the output analyzed by , https://cway.cisco.com/tools/WirelessAnalyzer/ , look for critical advisories (red) , and correct accordingly.

 M.

You should not be using type 7 password encryption or md5 hash secret anymore - both very insecure and unsafe.

You should be using type 9 (scrypt) which is now the most secure option available (type 8 also acceptable but consensus that 9 is better):

username test privilege 15 algorithm-type scrypt secret plaintextsecret

That will appear in the config as:

username test privilege 15 secret 9 $9$XDxtW9Ixseuak.$kMOej8hDPlSueAY6NsEMvwSCa51qmm11JBvdPjrF8Ec

 

FYI: you can't just 'change the number from "0" to "7".' - what follows 7 is the reversibly encrypted version of your plaintext password. It's very easy to decrypt using numerous websites and tools because the encryption algorithm is very basic and well known.

If you enable "service password-encryption" then IOS will encrypt plaintext passwords by default and which encryption type it uses depends on whether you have also enabled aes encryption with master key:

password encryption aes

key config-key password-encrypt <masterencryptionkey>

The master key is stored in secure NVRAM and can never be viewed.  If you lose the master key then the passwords can never be decrypted.

 

___________________________________________
TAC recommended codes for AireOS WLC's
Best Practices for AireOS WLC's
TAC recommended codes for 9800 WLC's
Best Practices for 9800 WLC's
Cisco Wireless compatibility matrix
Field Notice: FN-72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Recommended
WARNING - see CSCwd37092 Throughput degraded after upgrading to code 8.10.181.0/17.3.6 - 2800/3800/4800 series
- The fix for CSCwd37092 is now released in 8.10.183.0 and
- For IOS-XE 17.3.6 select controller model, go to IOS XE Software AP Service Pack, select CSCwd40096 17.3.6 APSP2
Field Notice: FN-63942 Lightweight APs and WLCs Fail to Create CAPWAP Connections Due to Certificate
                      Expiration - Software Upgrade Recommended
Field Notice: FN-72524 - During Software Upgrade/Downgrade IOS APs Might Remain in Downloading State
                     After 4 Dec 2022 Due to Certificate Expiration - Fixed in 8.10.183.0 and 17.3.6 APSP5 (APSP_CSCwd83653)
                     Also fixed in 8.5.182.7 (8.5 mainline) and 8.5.182.105 (8.5 IRCM) if you can't upgrade to 8.10
                     Note that 8.10.181.0 and 8.10.182.0 have been deferred (withdrawn) and are effectively unsupported by Cisco
___________________________________________
Richard R

zshowip
Enthusiast
Enthusiast

Resolved, Thank you!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers