Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
2-106
Configuring the ProCurve Wireless Edge Services xl Module
System Maintenance
By default, only two types of passwords are encrypted when you view the
configuration:
SNMP v3 user passwords
Web-User passwords (encrypted by SHA)
Other types display in plaintext, by default:
passwords for users in the local RADIUS database
shared secrets for the RADIUS servers specified in WLAN settings
shared secret for globally configured RADIUS servers (used for authenti-
cation, authorization, and accounting [AAA])
WEP keys
WPA/WPA2 preshared keys (PSK)
However, you can configure SHA256-AES256 encryption for these five types
of passwords. In addition to obscuring the passwords in the configuration file,
encryption protects passwords that the module might send over the wire to
facilitate seamless Layer 2 roaming for Web-Auth.
To enable password encryption, configure the encryption secret. The Wireless
Edge Services xl Module uses this secret to encrypt:
all previously configured passwords of the five types listed above
The SNMP v3 and Web-User passwords (by default, encrypted) are unaf-
fected by the password encryption configuration.
all new passwords of the five types listed above
all Web-Auth passwords that the module sends to other modules in order
to facilitate roaming
Make sure to configure the same password on all modules.
To configure the encryption key, follow these steps:
1. Select Management.