WESM zl Management and Configuration Guide WT.01.28 and greater

2-106
Configuring the ProCurve Wireless Edge Services zl Module
System Maintenance
Other types display in plaintext, by default:
passwords for users in the local RADIUS database
shared secrets for the RADIUS servers specified in WLAN settings
shared secret for globally configured RADIUS servers (used for authentication,
authorization, and accounting [AAA])
WEP keys
WPA/WPA2 preshared keys (PSK)
However, you can configure SHA256-AES256 encryption for these five types of
passwords. In addition to obscuring the passwords in the configuration file, encryp-
tion protects passwords that the module might send over the wire to facilitate seamless
Layer 2 roaming for Web-Auth.
To enable password encryption, configure the encryption secret. The Wireless Edge
Services zl Module uses this secret to encrypt:
all previously configured passwords of the five types listed above
The SNMP v3 and Web-User passwords (by default, encrypted) are unaffected
by the password encryption configuration.
all new passwords of the five types listed above
all Web-Auth passwords that the module sends to other modules in order to
facilitate roaming
Make sure to configure the same password on all modules.
To configure the encryption key, follow these steps:
1. Select Management.