New password is seen in clear text format

Unanswered Question
Aug 21st, 2008
User Badges:

When users are changing their password from a given default, ACS 3.3 is asking for a new password. When they type in the password it echos in clear text.

The users are using the ACS to access a PIX 535 pair using IOS 7.2 to access a Telnet proxy.

This doesn't look like a normal operation to allow the password characters to be seen in clear text.


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Farrukh Haroon Fri, 08/22/2008 - 06:12
User Badges:
  • Red, 2250 points or more

You can use SSH if you are worried about clear text passwords being sent on the wire.


Regards


Farrukh

rlortiz Fri, 08/22/2008 - 07:46
User Badges:

Farrukh,


Thanks for the input, but the issue is the visual echo that is seen when typing in the new password on screen. This isn't about the actual password being sent on the wire.

Farrukh Haroon Fri, 08/22/2008 - 21:21
User Badges:
  • Red, 2250 points or more

The local echo depends on your client. You can turn it off if you want.


Regards


Farrukh

Actions

This Discussion