Users Guide

Table Of Contents
sha256password: Uses sha256based encryption method for password.
encryption-type: Enter the encryption type for securing an user password. There are four encryption types.
0 input the password in clear text.
5 input the password that is already encrypted using MD5 encryption method.
7 input the password that is already encrypted using DES encryption method.
8 input the password that is already encrypted using sha256based encryption method.
password: Enter the password string for the user.
dynamic-salt: Generates an additional random input to password encryption process whenever the password is
configured.
privilege level: Assign a privilege levels to the user. The range is from 0 to 15.
role role-name: Assign a role name for the user.
Dell EMC Networking OS encrypts type 5 secret and type 7 password based on dynamic-salt option such that the
encrypted password is different when an user is configured with the same password.
NOTE:
dynamic-salt option is shown only with secret and password options.
In dynamic-salt configuration, the length of type 5 secret and type 7 password is 32 and 16 characters more compared
to the secret and password length without dynamic-salt configuration. An error message appears if the username
command reaches the maximum length, which is 256 characters.
The dynamic-salt support for the user configuration is added in REST API. For more information on REST support, see
Dell EMC Networking Open Automation guide.
Configuring the Enable Password
Access EXEC Privilege mode using the enable command. EXEC Privilege mode is unrestricted by default. Configure a
password as a basic security measure.
There are three types of enable passwords:
enable password is stored in the running/startup configuration using a DES encryption method.
enable secret is stored in the running/startup configuration using MD5 encryption method.
enable sha256-password is stored in the running/startup configuration using sha256-based encryption method
(PBKDF2).
Dell EMC Networking recommends using the enable sha256-password password.
To configure an enable password, use the following command.
Create a password to access EXEC Privilege mode.
CONFIGURATION mode
enable [password | secret | sha256-password] [level level] [encryption-type] password
level: is the privilege level, is 15 by default, and is not required.
encryption-type: specifies how you input the password, is 0 by default, and is not required.
0 is to input the password in clear text.
5 is to input a password that is already encrypted using MD5 encryption method. Obtain the encrypted password
from the configuration file of another device.
7 is to input a password that is already encrypted using DES encryption method. Obtain the encrypted password from
the configuration file of another device.
8 is to input a password that is already encrypted using sha256-based encryption method. Obtain the encrypted
password from the configuration file of another device.
Getting Started
47