Technical Tip: Only super_admin accounts can view WiFi SSID passphrase after upgrade to FortiOS v7.4.10 or v7.6.5
| Description | This article describes an expected GUI behavior change that prevents administrator accounts other than a super_admin from viewing managed SSID passphrases in cleartext after upgrade to an affected version. |
| Scope | FortiOS v7.4.10 and later, v7.6.5 and later. |
| Solution | Starting in FortiOS v7.4.10 and v7.6.5, only super_admin accounts are able to view reversible secrets in cleartext.
Before the upgrade, a profile administrator account can view reversible secrets. For an SSID in tunnel mode, this requires an administrator with read-write access permission to 'WiFi & Switch' and read-only access permission to 'Network', see Administrator profiles.
To view the WPA2 Passphrase, go to WiFi & Switch Controller -> SSIDs -> WiFi Settings -> Select the 'eye' icon next to the Passphrase field. The existing passphrase displays in cleartext.
After the upgrade, a profile administrator account is only able to change the WPA2 passphrase and cannot view the existing passphrase after configuration. This is expected.
An administrator with super_admin permissions is still able to view the SSID passphrase in cleartext.
Notes:
Related articles: |


