Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sw408b
New Contributor

System admin password encrypt

Please tell us how to encrypt the system admin password.

set strong-crypto disable

admin password Encryption is AES 128? AES 256?

Is it possible to change the encryption algorithm?

Please help me

3 REPLIES 3
Alexis_G
Contributor II

https://cookbook.fortinet.com/increasing-the-encryption-level/

 

--------------------------------------------

If all else fails, use the force !

-------------------------------------------- If all else fails, use the force !
ede_pfau

That cookbook article refers to HTTPS and SSH admin access. It's not about the stored passwords, PSKs, certs...

 

You cannot influence how passwords are stored in the config or in memory. If we knew the algorithm we could possibly re-engineer the cleartext password from the stored ENC string which would be detrimental in most cases.

I know of no other vendor who would allow this freedom, or document these details, in a security device.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

[I know of no other vendor who would allow this freedom, or document these details, in a security device.]

 

Cisco and Juniper password some types can be backwards engineer. Forcepoint NGFW password are store in a  posgresql.db with a salt, and hashed_password.

 

So I would be " loose to say";    'no other vendor offers this freedom'  ;)

 

Ken Felix

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors